Asking ends the agent’s run
When an agent requests an approval or asks a question itself, its run ends. The run trace marks it Succeeded, because asking is a normal ending. The task shows “Blocked · needs your approval” or “Blocked · needs your answer”. While the agent waits on your decision, nothing else wakes it on that task. A new comment gets the note “this task is waiting on a human decision”. Your response wakes the agent in a new run. The run receives your decision and any note you wrote. A rejection wakes the agent too, so it can change its plan. Some asks pause inside the run instead of ending it. A permission ask is one. The agent waits up to 15 minutes on a device and 5 minutes in the cloud. If you answer in time, the same run continues. If you allow it later, a new run picks up the work.Actions outside an agent’s permissions ask first
Each agent has a Permissions section on its Configure tab. It lists actions under Allow, Ask and Deny. The Anything else setting decides what happens with an action no row names:
With no setting anywhere, an agent uses Default. Only workspace owners and admins can change an agent’s permissions.
A permission ask offers three choices. Allow approves this one use, and the agent asks again next time. Always allow adds a rule, so the agent can repeat that action without asking. Deny refuses it.
Harnesses differ. In Default, Cursor applies file edits without asking, but shell and MCP actions still ask. Codex has no per-action rule list. It asks through its own approval prompts, and in Strict it runs read-only.