Safety and control

Keep control of actions Otto takes

Approvals let Otto pause before it takes an action that could affect another app, person, or system. Use them while you are learning a workflow, then choose a narrower level of supervision only after you understand what the agent does.

What an approval protects

Otto can answer questions and inspect information without changing anything. An approval may be required when it is about to do something consequential, such as:

  • send a message or other communication;
  • publish or share something;
  • create, edit, or delete a record in a connected app; or
  • make a purchase or another external change.

The exact request depends on the tool, connection, agent, and current safety settings. Approval does not give an agent access it does not already have: the agent still needs the connected app and the appropriate access level.

Choose how much supervision you want

Open the agent or automation's Approvals & safety settings and choose the mode that fits the work:

  • Always ask — ask before every action that crosses the approval boundary. Choose this when you are testing a new agent or workflow.
  • Ask to change — allow reading to proceed, but ask before actions that make changes. This is a useful default for a reviewed workflow.
  • Off — do not ask before actions. Use this only for a workflow you have watched and are comfortable allowing to run without an approval at each change.

These controls apply to the work that the agent or automation is allowed to do. They do not expand a connection's permissions or turn read-only access into write access.

For an automation, review its saved app access as well as Approvals & safety. A scheduled run can pause when it reaches an approval boundary; that is expected. If you need the automation to complete unattended, first make sure the workflow is appropriate for that, then review whether its access and approval settings support it.

Respond to an approval request

When Otto asks for approval:

  1. Read the requested action, target, and reason. Check that the account, recipient, record, amount, or other details are expected.
  2. Choose Approve if the action is correct and within the task you gave Otto.
  3. Choose Deny if it is not correct or you do not want it to happen.
  4. If the plan is close but needs to change, return to the conversation and tell Otto what to do differently before approving a later request.

If you choose Always allow for a request, you are approving that specific repeatable action for future work without being asked each time. Use it only when you understand the action and expect it to remain safe; it does not approve unrelated actions.

If you are away, enable Otto notifications so you can learn when an agent is waiting for a decision. Until you respond, Otto waits rather than taking the action on its own.

A safe way to introduce an agent

  1. Start with the narrowest connected app access the task needs. Use read-only access for research, monitoring, and drafts.
  2. Set Ask to change or Always ask.
  3. Run a realistic example and inspect the activity in the conversation.
  4. Confirm that the agent used the expected source, stopped at the right point, and produced the result in the right place.
  5. If the workflow is reliable, reduce supervision only as far as the task requires. Separate agents keep instructions apart but share the Otto's connected apps; for work that needs a different set of accounts, use a separate Otto.

Do not respond to an unexpected result by turning approvals off. First check whether the agent had unclear instructions, too much context, or more app access than it needed.

If an approval is unexpected or the agent is blocked

  • The request is not what you asked for: deny it, then explain the correct boundary in the conversation. Review the agent's instructions and connected-app access before trying again.
  • The agent cannot perform a read or change: check that the required app is connected and that the agent or automation has the needed access level. An approval cannot fix missing access.
  • An automation is waiting for approval: open its run history, review the requested action, and approve or deny it. If it must finish while you are away, revisit whether the task should make that change automatically.
  • You approved the wrong action: check the target app immediately and undo the change there if that app supports undo. Then tighten the workflow before running it again.
  • You are not receiving requests: check that Otto notifications are enabled in Otto and in your operating system, and confirm that the device is online. You can also review the conversation or automation run history for a waiting or failed run.