Home/Platform/Apps, actions & approvals
Scope & approvals

AI can use app actions —
only inside the scope you approve.

Hubson shows exactly what it can read, draft, update, or ask to do in each connected app. Risk controls and approval policy decide where it can act on its own and where it must pause for a human to approve, edit, or decline.

hubson · Approvals
Pending 3 Approved today Declined All receipts
Approval requiredworkflow · refund-approval
Issue refund: $2,840 to Acme
SOP finance.refunds.v3 requires approval above $2,000. Paused at step 4 of 6.
Run · R-1284Paused 2m ago
Approval requiredworkflow · crm-hygiene
Update CRM stage for 14 deals
Bulk CRM mutations above 10 records require sign-off per sales.crm-hygiene.v2.
Run · R-1279Paused 34m ago
Approval requiredworkflow · vendor-invoices
Approve $48 vendor invoice — Linear
Routine, but policy requires a human stamp on all financial outflows.
Run · R-1275Paused 1h ago
What "scope" means

Every action has a clear level

No vague "connect your account and let AI handle it." Each app action carries a default control — allowed, approval optional, approval required, or restricted — and you see it before any live use.

ALLOWED

Read & draft

Read context and draft outputs — low-risk reads and drafts AI can do on its own, like pulling context or preparing a reply.

auto
APPROVAL OPTIONAL

Internal writes

Internal writes that a workflow owner may allow without a pause — like adding a CRM note or an internal comment.

owner sets
APPROVAL REQUIRED

Act with a yes

Customer-facing, financial, code, or external actions pause for the owner to approve, edit, or decline — with the context attached.

pauses
RESTRICTED

Restricted

Actions marked restricted are blocked by the workflow policy unless an authorized owner changes the policy.

blocked
Action typeDefault controlExample
Read contextallowedread ticket, read customer record
Draft outputalloweddraft reply, draft note
Internal writeapproval optionaladd CRM note
Customer-facing writeapproval requiredsend customer email
Financial actionapproval requiredissue refund
Destructive actionrestricteddelete record
Approvals

Authority stays with humans

When risk, uncertainty, or external impact requires judgment, Hubson pauses with a clear, specific approval card linked to the work — not a vague "AI wants to do something."

PREPAREDAction stagedHubson prepares the action with full context — but does not send it.
PAUSEDApproval cardThe right person sees what, why, and how much — then approves, edits, or declines.
RESOLVEDActed & recordedOn approve, Hubson acts and writes the receipt. On decline, nothing changes.
hubson · approval card · try it
Approval requiredworkflow · refund-approval
Issue refund: $2,840 to Acme
SOP finance.refunds.v3 requires approval above $2,000. Paused at step 4 of 6.
Context · Zendesk ticket · Stripe payment · HubSpot plan
If approved · issue refund + draft customer updateIf declined · nothing changes
  • Per-workflow budgets and pre-run approval for Heavy runs
  • Owner-defined approval policy decides who can authorize what
  • Approve from Hubson, with notifications for refunds, deployments, CRM updates, and other approval-required actions
  • Only workflow owners or authorized admins can change risk controls
  • Every approval is captured in Activity and the Action Receipt
Nervous about app access?

Start on sample data. Connect only when it's trusted.

Review the scope, restrict the risky actions, and require approval before any live impact. Then connect the apps this one workflow needs.