AI can use app actions —
only inside the scope you approve.
Hubson shows exactly what it can read, draft, update, or ask to do in each connected app. Risk controls and approval policy decide where it can act on its own and where it must pause for a human to approve, edit, or decline.
Every action has a clear level
No vague "connect your account and let AI handle it." Each app action carries a default control — allowed, approval optional, approval required, or restricted — and you see it before any live use.
Read & draft
Read context and draft outputs — low-risk reads and drafts AI can do on its own, like pulling context or preparing a reply.
Internal writes
Internal writes that a workflow owner may allow without a pause — like adding a CRM note or an internal comment.
Act with a yes
Customer-facing, financial, code, or external actions pause for the owner to approve, edit, or decline — with the context attached.
Restricted
Actions marked restricted are blocked by the workflow policy unless an authorized owner changes the policy.
Authority stays with humans
When risk, uncertainty, or external impact requires judgment, Hubson pauses with a clear, specific approval card linked to the work — not a vague "AI wants to do something."
- Per-workflow budgets and pre-run approval for Heavy runs
- Owner-defined approval policy decides who can authorize what
- Approve from Hubson, with notifications for refunds, deployments, CRM updates, and other approval-required actions
- Only workflow owners or authorized admins can change risk controls
- Every approval is captured in Activity and the Action Receipt
Start on sample data. Connect only when it's trusted.
Review the scope, restrict the risky actions, and require approval before any live impact. Then connect the apps this one workflow needs.