How CellCog decides what an agent may do on your behalf: the three threat levels, your auto-approve thresholds per surface, pending approvals in chat, and standing approvals for AI employees.
Every action an agent takes on your computer (Cowork), in a browser (Browse my Chrome or a cloud browser), or through a connected app (Tools) is classified by the agent as safe, moderate, or dangerous, with a plain-language summary and, for elevated levels, a one-sentence reason. You set an auto-approve threshold per surface. Actions at or below your threshold run immediately; actions above it appear as a pending approval in chat and wait for you. AI employees work on the same model with two additions: their level is at least Moderate, and you can grant standing approvals for classes of dangerous work they need repeatedly.
Threat tracks data, not the kind of command. The same click or command can be safe, moderate, or dangerous depending on what it touches. The agent answers two questions in order; the first yes wins:
When in doubt the agent is expected to pick the higher level.
| Level | Cowork (your computer) | Browsers | Tools (connected apps) |
|---|---|---|---|
| Safe | Listing files, running tests or builds, reading and editing files inside a version-controlled working directory | Opening a public page, searching a public site, expanding a menu | Listing files, reading public profiles, reading your own calendar or project data |
| Moderate | Reading files outside the working directory, environment variables, shell history; editing files in a project with no version control and no backup | Snapshotting a logged-in page (inbox, private repo, banking), reading cookies, listing or adopting your personal tabs | Reading highly private data: full email content, payment history, private messages |
| Dangerous | Installing packages, deleting files, editing shell profiles or system files, pushing to a remote, anything touching production | Submitting forms, sending email, paying, deleting, writing cookies, downloading files | Any write or externally visible action: sending email, posting, creating invoices, changing CRM records |
Two special cases:
You choose how much runs without a click, separately for each surface:
| Threshold | What runs automatically |
|---|---|
| None | Nothing. Every action requires your approval. |
| Safe | Safe actions only. Private reads and anything that changes data still ask. This is the default for every surface. |
| Moderate | Also actions that read your private data. Anything that changes data or acts on your behalf still asks. |
| Dangerous | Everything the agent declares, including actions that change data or act on your behalf. Use only when you fully trust the task. |
| Surface | Page | Setting |
|---|---|---|
| Cowork | cellcog.ai/cowork | Auto-approve threshold |
| Browse my Chrome (and cloud browsers) | cellcog.ai/cowork/browse | Auto-approve threshold |
| Tools | cellcog.ai/connectors/tools | Auto-approve tool calls up to |
Your profile page shows all three side by side under Auto-approve up to (Terminal on my computer, Browser control, Connected app actions), with a link to change each.
Each surface chip in the chat editor (Cowork, Browse, Tools) carries a colored dot showing the effective level for that chat. Hover the chip and click the dot to set a level for this chat only; Reset returns the chat to your account default. New chats always start at the account default. You can also change the account default from the same panel.
When an agent sends an action above your threshold, an approval panel opens on the right side of the chat. Each command card shows:
Your choices:
A batch runs in the order the agent sent it, and starts only after every command in it has been decided. Commands at or below your threshold in the same batch are marked Auto-approved and run without waiting. In a regular chat the agent waits for your decision as long as it takes.
If an agent forgets to classify an action, or declares an elevated level without a reason, the action does not run at all. The card shows Will retry and the agent re-issues it with proper metadata on its next turn; nothing is needed from you.
AI employees work autonomously, often while you are away, so their approval model has three additions.
An employee's level per surface is Moderate (the default) or Dangerous. None and Safe are not available, because an employee cannot stop and wait for every read. You set the level when you hire the employee and can change it later from the chips in the employee's chat.
When an employee wants to do something above its level, the platform checks, in order:
A standing approval is your yes to a class of dangerous work, described in one sentence, for example "Send up to 5 cold outreach emails per day" or "Post the weekly update to the team channel". How it works:
AP-7Q2K4M. Approvals have no expiry by default; a temporary grant can carry a number of days.You can see every active approval in the Approvals app on the employee's computer, with its description, grant date, and expiry. That view is read-only: approvals are granted and revoked in conversation. To revoke one, tell the employee and it removes the approval; expired approvals stop working on their own.
The platform checks that a quoted approval exists, is active, and has not expired. The wording of the approval is the contract the employee is expected to honor; if it oversteps, tell it and revoke.
Hiring is never covered by an approval. An AI employee (or a chat) can only propose a hire: the New AI Employee form appears filled in for you, and your Hire click is the hire. No standing approval, id, or setting lets an agent create an employee on its own.
~/.ssh, cloud CLI configs, .env files in your home directory, and shell profiles. These are blocked regardless of threshold.When an agent drives your Chrome through Browse my Chrome, Chrome shows a yellow banner on the controlled tabs: "CellCog Browse started debugging this browser." with a Cancel button. This is Chrome's own safety indicator; CellCog cannot hide it. It appears while the agent is executing a batch and clears shortly after. Click Cancel to revoke control of that tab immediately. Cloud browsers show no banner, because they are the employee's own Chrome on CellCog's servers.
Only the agent knows what a command is about to touch. Its declaration is what your threshold gates, and the card shows you both the level and the reason so you can judge it. Underclassification shows up on the card; when in doubt the agent is expected to escalate.
Threshold None on every surface: every action waits for your click. Most people settle on Safe or Moderate and keep Dangerous for chats they fully trust.
No. Overrides apply only to that chat and are never copied to new chats. Changing the default from a chip does update the account-wide default.
No. The threshold is enforced by CellCog, not by the agent: an action above it stops and waits for you no matter how the agent describes it. The card shows you the level the agent declared and its reason, so an underclassified action is visible when you review it.
After 15 minutes without a decision, the action fails, the employee is told to get a standing approval or retry while you are present, and its shift continues with other work.
Tell the employee in chat. It revokes the approval, and the Approvals app on its computer stops listing it. Timed approvals expire on their own.
Employee email works differently: there is no approval button on outgoing mail. Your dangerous-operation policy for the role, set during onboarding, decides what the employee sends on its own and what it brings to you first. See the AI Employees Guide.