Review approvals
Approve, reject, or revert the changes the copilot proposes — the human decision point for money-moving writes.
Approvals is where you decide on the changes the copilot proposes but the policy won't auto-apply. Everything money-moving that isn't bounded and low-risk lands here with its risk tier, the reason it queued, and the exact before/after — so a decision takes seconds, not investigation.
The queue
Open the Approvals page (or asa_list_pending_actions over MCP). Each item shows:
- What — the entity and the exact change (e.g. budget €40 → €52).
- Risk tier —
safe(would auto-apply) orreview(queued). - Policy reasons — why it queued: outside the CPA band, above a step limit, a strategy change, a daily auto-apply cap hit, and so on.
Decide
Approve
Applying runs the change through Apple. The apply worker re-checks the policy and re-validates first, and hard-caps any budget change at 3× the current value — defense in depth even for changes you approved.
Revert
A change that was applied — and whose prior state was snapshotted — can be reverted. Every write
stores its prior* values precisely because Apple has no change history to reconstruct from.
Over MCP, approvals are operator-only: asa_approve_action, asa_reject_action, and
asa_revert_action exist only in the MCP bridge, where a human drives. The in-app copilot
cannot approve its own proposals.
The kill switch
If you want to stop all auto-apply immediately, the org kill switch (asaAutoApply) is checked at
both propose and apply time. With it off, every write queues here regardless of tier. See the
safe-apply policy for the full gate list.