Agent Desktop/Work with your agent/Approve what your agent can do
Approve what your agent can do
Choose ask, allow or deny for connector actions and see the details before an action is sent.
Agent Desktop does not treat every capability as equally safe. Each action has an execution policy, and the app uses that policy before sending a request.

Ask
Ask is the default policy for newly connected capabilities. When the agent wants to run an action, the Canvas shows a confirmation card with the action and the arguments that can be shown safely.
Choose the action when you are ready. Decline it when the request is not what you intended. Declining does not execute the action.
Allow
Allow lets an action run without asking every time. Use it for a capability you trust and expect to repeat. The app can remember an allowed policy when the action supports persistent approval.
Some sensitive or browser actions continue to ask even when another action is allowed. The app keeps those decisions separate.
Deny
Deny blocks an action. A denied policy cannot be bypassed by clicking through a confirmation. The agent receives a refusal instead of a request being sent.
Use deny for actions you never want this desktop installation to run.
What the confirmation shows
The confirmation view is designed to help you make a decision quickly. It can show the connector, capability, action arguments and the available choices. Secret-like values such as tokens, passwords, cookies and authorization values are redacted from the presentation.
Credentials are different
A missing credential is not an approval request. The app sends you to credential setup instead of treating a secret as something the agent may ask permission to reveal.
Browser actions
Browser actions use a stricter approval path. The app-owned browser can navigate, click, fill and capture pages, but the agent does not silently receive permission to act on your behalf. Review the action shown in the Canvas.