Approvals
Email approval cards, secure inputs, held routine actions and the limits of approval prompts.
Work that runs immediately
OpenTag can read, draft, work with files and carry out supported operations without asking for permission on every tool call. A write-capable integration can make changes during a request. Do not assume that every write produces an approval card.
Use Read only on a connection when you need to prevent writes. Say “draft only” when you want to review the result before taking it further. Connection permissions and approval are separate controls.
Email approval
Sending Gmail messages, replies and saved drafts requires explicit approval. OpenTag prepares the email and shows Approve & send and Don't send with the subject, To, Cc, Bcc and body.
For a request made in a channel, the full email approval goes to the requester's DM. The original thread receives a notice. Check your DM if the channel says the email is waiting for review.
The approval is bound to the prepared message. Changing a draft cannot silently substitute different content for the email you reviewed. If OpenTag cannot prepare or validate the message, it refuses the send and may need fresh approval.
Review recipients, content and attachments before approving. Slack may truncate a long preview; a truncation notice means the preview is not the full email.
Other requests for a decision
OpenTag can ask you to confirm an external commitment, choose between approaches, or complete a step yourself. Secure credential entry and skill scripts that explicitly require human approval also wait for a person.
Enter secrets only in the secure field or provider sign-in page, never in the conversation. Answer the control attached to the current request; an old card from a cancelled or replaced run may no longer be usable.
Scheduled routines
Routines post their results to Slack without waiting for an approval click. Some other actions are held, including Gmail sends, phone calls and calendar writes that can invite attendees.
A held action does not block the rest of the routine. OpenTag can finish its report, state what it held, and notify the owner. The owner can then ask for that action in an interactive conversation; an email still needs its send approval.
See Managing routines for ownership and execution access.
Use permissions for a firm boundary
There is no customer setting that makes every operation require approval. A request to ask first helps direct the work; a read-only connection limits what the tool can actually change. Review both before giving OpenTag access to an account where a mistaken change would matter.
If you decline
The declined action is not authorised. Explain what should change in the thread and ask OpenTag to prepare it again. Approving one email does not approve later emails.