Tool approval

Risky tool calls can pause until you approve or deny in a desktop dialog (default timeout ~120s).

What triggers approval

Depends on your approval policy, typically:

Policy levels (runtime)

Level Behavior
on-request Ask before risky operations
untrusted Ask before writes
never Auto-approve (use with caution)
auto Runtime auto-decides per rules (used with on-request)

Configure under Settings → System alongside execution policy (read-only, workspace-write, …).

Session memory

Approvals can be remembered for the session so repeated safe commands do not nag.

Tips

Related: Streaming · Embedded terminal