Automations

Set automation permissions and limits

An automation can run while you are away, so its access should match the work—not the maximum your connected apps allow. Give a recurring report read access, for example, and reserve change access and automatic execution for workflows you have already reviewed.

What each control does

Automation controls answer different questions:

  • App access — one level for the whole automation: no app access, read-only, or read and write. The level applies to every app connected to your Otto; it does not select individual apps.
  • Approvals & safety — when Otto must stop and ask before the agent acts.
  • Limits — how much model usage or other configured run capacity the automation may consume.
  • Schedule — how often the automation can start. A shorter interval can increase usage even when every run is successful.

Because the level covers every connected app, Read & write lets the automation change records in any app connected to that Otto, not only the one the task is about. Review the automation's saved settings whenever you change its task, schedule, or agent, and whenever you connect another app.

Choose app access

In the automation's access settings, choose the lowest level that can finish the job:

AccessUse it forIt cannot do
NoneWork based only on the instructions and context already suppliedUse any connected app
Read-onlyMonitoring, research, summaries, and finding information in any connected appSend, publish, purchase, or change records in any app
Read & writeA reviewed workflow that must create or change somethingNothing beyond the permissions each connection grants and your approval rules — in every connected app, not just one

Read-only is the right starting point for a new scheduled check. If the run needs to send a message, publish a result, purchase something, or update a record, first confirm that the change is genuinely part of the task. Then grant Read & write only if the automation needs it, and check which other apps are connected to that Otto first: the automation will be able to change those too. Keep Approvals & safety asking before changes, or disconnect apps the device does not need.

App access is not the same as connecting an app. If the required account is not connected, open Integrations, connect the app, and return to the automation's access settings. The automation still needs the appropriate access level after the connection is available.

Choose approval behavior

Use Approvals & safety to decide how much supervision the automation needs:

  • Always ask — Otto asks before every action.
  • Ask to change — reading can proceed; actions that make changes ask for approval.
  • Off — Otto does not ask before actions.

For a new automation, start with Ask to change or Always ask. A scheduled run can pause for approval instead of completing; that is expected when its next step crosses the approval boundary. Use Off only after you have reviewed real runs and are comfortable with the workflow's scope.

Approval behavior does not expand app access. An approval cannot make a read-only automation send or edit something; increase the saved app access first if that change is intentional.

Set a useful limit

Choose a limit you would be comfortable reaching without watching every run. Consider both the work in one run and how often the automation repeats:

  • A short, focused instruction usually needs less usage than a broad research request.
  • A frequent schedule can consume more over a day or month even if each run is small.
  • A workflow that reads many files or app records may need more capacity than a simple reminder.

If the settings include a model-usage or run limit, set it conservatively at first. If a run stops because it reached a limit, shorten or narrow the task, reduce the schedule frequency, or raise the limit deliberately. Do not treat a limit failure as a reason to grant broader app access.

Change an automation's controls

  1. Open Automations and select the automation.
  2. Choose Edit.
  3. Review the task and schedule so the access still matches what the automation is meant to do.
  4. Open the access settings and choose None, Read-only, or Read & write for the connected-app work it needs.
  5. Review Approvals & safety and choose Always ask, Ask to change, or Off.
  6. Review the available usage or run Limits and set a conservative value that fits the schedule.
  7. Select Save.
  8. Choose Run now to test the changed boundary when you want to verify it immediately.

After the test, open the run history. Confirm that the automation used the expected connection, stopped for approval when it should, and completed within its limit. If the task also has a result destination or notification, verify those separately; changing access does not change where results appear.

If a run is blocked

Use the exact run status or error to decide which setting needs attention:

  • Needs approval — review the requested action and approve it if expected, or return to the session with a narrower instruction.
  • Insufficient access — the automation is trying to perform a read or change that its saved app-access level does not allow. Grant only the missing level if the task requires it.
  • Connection unavailable — reconnect or authorize the required app in Integrations, then check the automation's access again.
  • Limit reached — narrow the request, reduce how often it runs, or adjust the limit intentionally.
  • Device offline or unavailable — bring Otto back online and retry after confirming the schedule and connection are still current.

Read the failed run before changing settings. If you change one control at a time and use Run now, it is easier to tell which fix worked. See Read and recover failed runs.

Review after a change

Revisit permissions and limits when you:

  • add or remove a connected app;
  • change the automation's instructions, agent, or schedule;
  • change a workflow from drafting or reporting to sending or editing; or
  • see an unexpected approval, access error, or usage spike.

Pause the automation while you review it if it should not start another scheduled run. Pausing does not cancel a run already in progress.