Approvals and questions
Before an agent writes or sends something, lowcloud asks for your approval by default. Reading runs without asking. In a workflow run, an agent can also ask you a question and wait for your answer.
Find open approvals
Open approvals and questions are listed in three places. You can answer them in all of them.
- Approvals in the sidebar: all open approvals and questions across all workflows, oldest first. There are no filters, no search and no bulk actions.
- The timeline of the run, at the point where it stopped.
- The answer field in the tab Run, as long as you have the run open there.
Who sees and can answer an approval or a question, and how long it stays open, is described under Runs.
Notifications
lowcloud points you to open approvals and questions in these ways:
- a badge with the count on the menu item Approvals
- an entry under Notifications in the page header
- a banner on the workflow overview
- on request, a browser notification. You switch it on with Activate in the prompt, or under My account in the section Notifications.
- an email, if nobody is following the run on screen
The email comes for runs of a personal setup. It goes to the person who set the workflow up for themselves. It is sent for an approval, a question or an interrupted run that waits for a person. Test runs and runs that were started through a form do not trigger an email. This also applies to the public form. There is no setting for this email.
Approve an action
- Open Approvals in the sidebar.
- On the approval, click Review. The card expands.
- Check the values on the card.
- Click Approve.
lowcloud executes the call with exactly the values that are on the card. Seconds to minutes later, a message of its own reports how the run continued. To the run opens it.
One approval can cover several calls at once. One decision then covers all of them.
Change values
Via the pencil icon you correct individual values before approving. You can change only text values that the model wrote itself. Values fixed in the step are locked.
As soon as you have changed something, the button is called Approve with changes. The timeline then notes Approval granted, with your changes.
| Limit | Value |
|---|---|
| Calls | at most 10 |
| Fields per call | 40 |
| Characters per field | 20,000 |
Approval card
The card shows the concrete call with the real values, for example the email with recipient, subject and text.
| Part | Content |
|---|---|
| Header | Workflow, step, number and start time of the run, waiting time of the approval |
| Consequence | one sentence in everyday language saying what approving triggers |
| Target | the object that is written to, with its title instead of a raw ID, partly as a link |
| Account | a note if the action runs through a predefined account and not through yours |
| Content | Email preview, message, Markdown or a table of fields. Show all values reveals the remaining technical values. |
| Trigger | the short form of the event that triggered the run |
Under Approvals, the collapsed card shows only the consequence and the preview. Expanded, it adds Received message, Context and History so far. In the timeline of the run the card is always expanded.
Values from external sources
If the agent read text from outside while composing the call, the card shows a warning. Text from outside comes, for example, from an email, a web page, a custom HTTP interface or an MCP server.
Each affected field then shows which source the value comes from, according to the agent. If the agent names no source, the field shows "Entered without a source." in warning colour.
Pure read calls such as calendar or tables do not trigger this warning.
Reject an action
Click Reject. A field for an optional reason opens. In no case is the action executed.
- With a reason: write the reason and click Reject with feedback. The reason goes back to the agent as the result of the rejected call. It revises and asks again, or finishes. The reason can be up to 5,000 characters long.
- Without a reason: click Reject and end run. The run ends immediately at this point with the status Cancelled. No second message follows.
Answer a question
You answer a question with text, not with yes or no. The agent gets your answer as the result, and the run continues at the same point.
Write your answer in the answer field of the question. The agent can send along two to six answers to click. A click sends exactly that text.
Limits
| Limit | Value |
|---|---|
| Length of an answer | 1 to 10,000 characters |
| Questions per run | 50, after that the run aborts |
Requirements
An agent step may ask only if both are true:
- The switch Questions is on at the agent step.
- A person started the run and can answer. This is the case only with the trigger Form, the manual start in the app.
With Public form, email and schedule, the agent cannot ask questions. This also applies if you submit the public form yourself. For triggers that nobody is watching, the builder does not show the switch Questions at all.
If the agent asks a question together with a write call, the question is deferred and you answer the approval first. If it asks together with completing the step, the question is discarded. Both appear as a line in the timeline.
Turn approval for a tool on or off
At the agent step, every tool has the switch Approval. With it you reverse the default for one tool: a write tool then runs without asking, and a read tool asks anyway.
To let a write tool run without asking:
- Open the agent step in the builder.
- In the row of the tool, switch Approval off.
- Confirm with Yes, without asking.
The row of the tool then carries the badge Without approval.
Actions that need approval
Whether an operation from the catalog asks depends on whether it counts as reading or writing. For MCP servers and custom integrations:
- MCP servers (external tool servers): their tools count as writing and ask. Tools for which the switch Read-only is on, on the detail page of the server, are the exception. The server's own statement on whether a tool only reads merely pre-fills this switch.
- Custom integrations: Fetch data (GET) counts as reading, Send data (POST/PUT/PATCH/DELETE) as writing. For a named tool you created yourself, your classification applies.
A run stops only before a write call and at a question. There is no approval between two steps.
Approvals in the chat
The chat also asks before writing. If the model calls a writing action, the answer stops and shows a card. Confirm and execute carries out the action. After Reject, the model keeps answering but does not carry out the action. What the switch Auto mode does is described under Chat.
Approvals in Microsoft Teams
If an agent wants to write something in the Teams chat, a card appears there with the call, its values and the buttons Approve and Reject. In Teams every write asks, even if the approval for the tool is switched off on the agent. You cannot change values or write a reason on this card. Approvals from workflow runs do not appear in Teams.
For whom the agent writes in Teams and how long a card is valid is described under Microsoft Teams.