Skip to content

Inbox and passkeys#

Inbox lists everything that waits on you, soonest to expire first:

Kind Comes from You see it when
Repairs on machines Self-healing: a reboot, a drain, a GPU reset, a power cycle waiting for approval You may read repairs (remediation-actions:read); you decide them with remediation-actions:approve
Agents waiting for you An agent's or a model's held tool call You may read approvals in the workspace; you decide with approvals:approve and when the approval names you
Your AI assistants An action an assistant you connected asks you to confirm Always: they are yours
Invitations An invitation to an organisation, a workspace or an environment Always: they are yours

What expires within the hour is listed first, under Soon. Tap an item for its details — what it would do, the machine, the policy that held it, who asked — and Open in the console for its full page.

Decide#

Each item has its two buttons: Approve and Reject (a repair), Approve and Deny (a held call), Confirm and Decline (an assistant's action), Accept and Decline (an invitation). A decision is yours, made as you, through the same rules as in the console: your permission is checked again, and a cluster checks once more. An item you may see but not decide says so.

Dangerous decisions take a passkey#

Approving something that disrupts machines or work, or cannot be undone, asks for your passkey — your fingerprint, your face, or the phone's PIN — so that an unlocked phone in the wrong hands, or a slip of the thumb, approves nothing. The item says so (Approving takes your passkey) and why. Dangerous are:

  • repairs that reboot, power-cycle, drain, reset a GPU, reinstall or return a machine for replacement;
  • an assistant's action that deletes a deployment, cancels a run, stops an environment, drains a machine or approves a repair;
  • a held call that deletes, removes, drops, revokes, merges, deploys, transfers, pays or spends (a budget), powers off or reboots something, or uses a DELETE request.

Rejecting is never dangerous. Astralyx decides what is dangerous from the item itself, not from what the app shows, and refuses a dangerous approval without a passkey confirmation made for that very item — once, within 5 minutes.

Add a passkey#

  1. Settings → Passkeys → Add a passkey on this device.
  2. Confirm with your fingerprint, face or PIN.

The passkey stays on the phone (or in your password manager, synced to your other devices); Astralyx keeps only its public key. Add one on each phone you approve from, and remove one there under Settings → Passkeys. You may have 10.

When a confirmation is refused#

Message What to do
Dangerous decisions in the app are confirmed with a passkey Add one (above), or decide this one in the console.
Your device did not verify you Try again; the phone must check your fingerprint, face or PIN, not only a tap.
The confirmation expired Try again: a confirmation lasts 5 minutes and is used once.
This passkey may have been copied Its counter went back. Remove it in Settings → Passkeys and add it again.
It no longer waits Someone decided it, or it expired.
You may not decide this one Your role does not include it, or the approval names other people.

From a notification#

A notification of something waiting on you opens it in the inbox. On Android and computers, one that is not dangerous also has Approve on the notification itself; a dangerous one only opens the app, where approving takes your passkey. If approving from the notification is refused (signed out, decided already), a second notification says why.