Skip to Content
ConceptsApprovals

Approvals

Some tool calls need a person before they run: every call to a tool with an approval guard, and calls where an action or egress rule decides to ask. This page explains what an answer means and how long it lasts. To answer requests in the dashboard, see the Approvals guide.

Waiting

The call pauses until someone answers. Then the tool runs with exactly the approved arguments, or the agent gets a refusal. This works in any agent loop.

  • No time limit. A request waits until someone answers, and an approval never expires.
  • Identical calls. While a request is open, a new identical call, from the same agent to the same tool with the same arguments, waits on the same request instead of opening another.
  • Stopped processes. If the waiting process stops, for example after a crash, its heartbeats stop and the dashboard shows the request as no longer waiting. The request stays open, and an Approve once given then is used by the next identical call.
  • Hosts that stop long calls. Some hosts end a call that waits too long. Set a timeout, in seconds, on the approval guard to give up sooner with a refusal. The request stays open.

The three answers

AnswerWhat runsWhat it is tied to
Approve onceThis call, one timeThe run, agent, step and tool, and the exact arguments
Always approveLater calls with exactly the same arguments, without asking, in any runThe agent, the tool and the exact arguments, until revoked
DenyNothing. The agent gets a refusalThis request

An approval is void as soon as any argument changes: a call with a different argument asks again. Arguments are compared after normalizing, by a hash.

Checks after an approval

The block checks run again right after an approval. An approval never overrides a block that came up while the call waited, such as a daily cap being reached.

What the approver sees

The approver sees the real arguments, where each value came from, and the influence path from the entry point to the call. Everywhere else the dashboard shows sensitive values masked, but an approver must see exactly what they approve. After the answer, only a hash of the arguments is kept.

Anyone signed in to the dashboard can answer. Every answer records who gave it.

If Quard’s backend can’t be reached

A call that needs an answer is blocked after retrying for up to 30 seconds, with the reason backend_unavailable.

Last updated on