Approvals#
An approval is a decision a person makes while an agent waits. The call is held on the run's machine; a person the policy names opens it in the console, sees what the call would do, and approves or denies it. This page explains what asks for one, who decides, and how long things wait.

What asks for an approval#
| Kind | Asked when | While waiting |
|---|---|---|
Tool call (tool_call) |
A call is permitted only by permit rules marked @approval. |
The machine holds the call; the agent waits for its answer. |
Budget (budget) |
A run reaches its own limit with Ask for approval, or an agent or workspace budget with on_exceed: approval. |
The model call is held. Approved, the limit is raised and the run goes on. |
Flow step (flow_step) |
A flow reaches an approval step. |
The flow's execution waits; no machine holds anything. |
Who decides#
The approvers come from the policy, never from the machine:
| Approver | Who |
|---|---|
@approval alone |
The workspace's editors and admins (role:editor). |
role:admin |
The workspace's admins. |
role:editor |
Its editors and admins. |
role:viewer |
Anyone of the workspace who may decide — in practice editors and admins, since deciding needs the editor role. |
user:<id> |
That person, if they are an editor or admin. |
group:<name> |
Accepted, but there are no groups yet: it matches nobody. |
Several are separated by commas: @approval("user:0192…, role:admin").
A flow's approval step names its approvers in approvers, editors when
empty. The workspace's members who may decide are told by email when an
approval is asked.
What the approver sees#
The approval's page shows the call (the server, the tool or method and URL), the policy that asked, the run, the agent and version, who decides, and when it expires. The call's arguments are read from the run's machine when the page is opened — shortened, and values that look like keys hidden — and are not kept anywhere else. Astralyx stores only a target, digests and the decision.
How it ends#
| State | Meaning |
|---|---|
Pending |
Waiting for a person. |
Approved |
Allowed: the held call goes ahead, once. |
Used |
Approved, and the call went ahead. |
Denied |
Refused. The agent is told who denied it and the reason they gave (at most 500 characters). |
Expired |
Nobody decided in time. |
Timing. A held tool call waits 10 minutes by default; the rule may say
more with @approval_wait("1h") (or wait=1h among the approvers), at
most a day. If nobody decides in that time, the call is refused with the
approval's name — but the approval stays Pending for 24 hours from when
it was asked, and the same call made again (same server, tool or method,
URL and arguments) waits on it rather than asking again, and goes ahead
once approved. A flow step waits wait_seconds (a day by default, up to 7
days). A run may have at most 16 calls waiting at once on its machine.
Finished approvals are kept 7 days by default (workspace Retention), and every decision is an event in the workspace's history.