Approvals playbook
How to choose Ask, Auto or Full access for each bot, and cautious starting setups for inbox, sales, finance and research teams.
Every bot has an approval level. It decides how often the bot stops to check with you. Getting it right is the difference between a team that saves you hours and one that pings you every minute, or one that does something you'd never have allowed.
The mechanics are in Permissions and the stop line. This page is about choosing.
The short version
- New bots start on Ask. Leave them there until you've watched them work.
- Move a bot to Auto once you've approved the same kinds of actions a few times and they were right every time.
- Use Full access for bots that work mostly inside their own folder, where the stop line still catches what matters.
- Avoid No limits unless you have a specific reason. It turns the stop line off for your own conversations.
What each level really means day to day
Ask is for new bots, new jobs and anything touching customers or money. You'll see a card for each action that needs permission. Answer from the chat, the Inbox, the menu bar or Telegram.
Auto is for bots you trust with routine work. The bot keeps going on its own, and destructive or sensitive actions still ask.
Full access is for bots doing a lot of steps in their own space: research, drafting, analyzing files, building. It doesn't ask, except at the stop line and before reading your keys and passwords. On Full access, a bot stops before messaging anyone new, posting publicly, paying, or deleting outside its folder, unless you have allowed it for that task. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: shell commands and file edits. Replies in a conversation that's already going count as ordinary work and go ahead.
No limits does anything without asking, except reading your keys and passwords. It's desktop only and asks you to confirm a warning.
Things that ask whatever the level
- A turn started by a webhook or someone other than you is judged as Auto, because nobody is watching it live.
- A routine runs at its own level. One you haven't set follows the bot's level.
- Making pictures asks before it spends, even on Full access.
- A bot asks once before it first uses your screen.
- Connecting an app always needs you, because you sign in to it yourself.
Using the approval buttons well
- Allow once when you're not sure yet.
- Allow for this task on a stop-line card when a job needs several similar steps, such as replying to five people in one thread.
- Always allow only for something you'd approve every time. On a stop-line card it's tied to that folder, recipient or payee. On an ordinary connected-app card it covers the whole tool, so think before you use it there.
- Deny tells the bot no, and it can try another way. Per the default House Rules, a no is final and it won't reach the same result by another route.
Bot-to-bot contact
In Bot settings → Permissions, Ask me before contacting other bots makes a bot stop before it hands work to, or asks, another bot. Turn it on for a bot whose teammates have more access than it does, so it can't get work done indirectly that you wouldn't approve directly. On Full access and No limits the switch is skipped in conversations you start, but webhook and routine turns still stop and ask.
Starting setups by team
These are starting points. Adjust after a week of watching real work.
Inbox team
- The bot that reads and sorts mail: Auto. Reading and labeling is low risk.
- The bot that drafts replies: Auto, with House Rules that say "drafts, not sends".
- Sending: leave it to the stop line. Replies to people already in the thread go ahead on Auto; first contact with someone new stops and asks. On a Hermes bot, sends through MCP or connected-app tools don't reach the stop line, so keep a Hermes bot on drafts.
- Don't use Always allow on the email app's send tool. It covers the whole tool.
Sales team
- Research and lead lists: Full access. It's mostly reading the web and writing files.
- Outreach writer: Ask at first, then Auto. First messages to new prospects always stop at the stop line, which is exactly what you want.
- CRM updates: Auto once you've checked a few.
- Turn on Ask me before contacting other bots for the research bot if the outreach bot can send.
Finance and bookkeeping
- Keep finance bots on Ask. Reading statements and preparing reports is fine; anything that moves money should be yours.
- Paying stops at the stop line on Ask, Auto and Full access. Never put a finance bot on No limits.
- Give finance bots read access to the apps they need, and add a House Rule: "Never pay, transfer, refund or approve an invoice."
Research and writing
- Full access works well. The work lives in the bot's folder, and publishing or sending still stops.
- Put a reviewer bot on the team if you want a second pair of eyes before work reaches you. It's optional.
Routines and webhooks
Webhook runs are judged as Auto even if the bot is on Full access. Each routine runs at its own level, set under Advanced → Approvals for this routine, and one you haven't set follows the bot's level. Keep a routine on Ask or Auto while it's new, and design it to produce a report or a draft that you send. A morning brief that reports in the app is ideal. Once you trust it, Always allow for this routine stops it asking about the same command or place again.
When to raise a bot's level
Raise it when the cards you're approving are boring. If you approve the same kind of card ten times without changing anything, the bot is ready for Auto. Lower it again the moment a card surprises you.
Messages from your phone
On Full access or No limits, Also skip approvals for my messages from Telegram, Slack and Discord lets your own messages from those apps run without cards. Messages from anyone else, webhooks and routines still ask. Leave it off if you'd rather see a card before your phone messages turn into actions.
The honest limit
The stop line is a careful check on every action Murage is asked about, not a sandbox. On Claude Code and Codex, the stop line also covers tools from MCP servers you add. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: Hermes asks before shell commands and file edits, but not before MCP or connected-app tools. An engine with shell access runs with your user account's permissions. For anything where one mistake would really hurt, keep the bot on Ask, and keep the bot's access to what the job needs.