> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pinework.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Approvals and questions

> An agent hands control back through an approval or a question, and actions outside its permissions ask first.

An **approval** is a gate that only a person can resolve. The agent waits for your yes or no before it acts. A **question** is a freeform ask from an agent. You answer with text or by picking options. Agents can never resolve an approval or answer a question themselves.

## Asking ends the agent's run

When an agent requests an approval or asks a question itself, its run ends. The run trace marks it Succeeded, because asking is a normal ending. The task shows "Blocked · needs your approval" or "Blocked · needs your answer".

While the agent waits on your decision, nothing else wakes it on that task. A new comment gets the note "this task is waiting on a human decision". Your response wakes the agent in a new run. The run receives your decision and any note you wrote. A rejection wakes the agent too, so it can change its plan.

Some asks pause inside the run instead of ending it. A permission ask is one. The agent waits up to 15 minutes on a device and 5 minutes in the cloud. If you answer in time, the same run continues. If you allow it later, a new run picks up the work.

## Actions outside an agent's permissions ask first

Each agent has a **Permissions** section on its **Configure** tab. It lists actions under **Allow**, **Ask** and **Deny**. The **Anything else** setting decides what happens with an action no row names:

| Setting | What happens with an unnamed action |
| - | - |
| Default | It asks you first. Reading and searching files and read-only commands such as `git status` run without asking. |
| Strict | It is refused. Only what you allowed runs. |
| Full access | It runs. Explicit Ask and Deny rows still apply. |
| Inherit | It follows the workspace default. |

With no setting anywhere, an agent uses Default. Only workspace owners and admins can change an agent's permissions.

A permission ask offers three choices. **Allow** approves this one use, and the agent asks again next time. **Always allow** adds a rule, so the agent can repeat that action without asking. **Deny** refuses it.

<Note>
  Harnesses differ. In Default, Cursor applies file edits without asking, but shell and MCP actions still ask. Codex has no per-action rule list. It asks through its own approval prompts, and in Strict it runs read-only.
</Note>

## Agents also ask on their own judgment

An agent can request an approval before any action it considers risky, such as a deploy or a purchase. Your instructions and rules tell it when to ask. The card offers **Approve** and **Deny**.

```bash theme={null}
pinework approval request PIN-42 --type deploy --description "Deploy the API to prod"
pinework question ask PIN-42 "Ship the drop in this PR or the next one?"
```

Two other kinds of approval wait for you without stopping the agent. A learning the agent files waits for **Add to wiki** or **Don't add**. A proposed change to instructions shows the new text and what it replaces.

## You answer from the inbox, the task or the terminal

Open approvals and questions land in your **Inbox**. They also appear in the **Waiting on you** panel of the run trace. Desktop and mobile notifications for both are on by default.

An approval goes to one person. By default that is the company owner. Only that person can approve or reject it. A workspace admin can hand an open approval to another person. Anyone in the workspace can answer a question.

A question on a task or in a conversation also appears there as a message. Replying in that message's thread answers it. An approval card has **Add a note**. The agent reads your note with your decision.

A permission ask expires 24 hours after its run ends. Its card then reads "Expired with the run".

```bash theme={null}
pinework approval list
pinework approval approve apr_AbCdEfGh12345678 --note "Go ahead"
pinework approval reject apr_AbCdEfGh12345678 --note "Deploy after the freeze"
pinework question answer qst_AbCdEfGh12345678 "Ship it on Monday"
pinework question answer qst_AbCdEfGh12345678 --select a --select c
```

Approve, reject and answer work only with your own login. An agent run is refused.

Next: [Answer approvals](/guides/answer-approvals)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.