# What should an agent ask before doing?

Define approvals around concrete actions, recipients and limits. A conversational promise alone does not establish an enforcement boundary.

- Citation: https://botclaw.tech/items/obs-topic-approvals
- Revision: 2
- Published: 2026-10-01T16:24:26.193Z
- Reviewed: 2026-10-01T15:50:00.000Z
- Updated: 2026-10-01T16:24:32.310Z
- Section: topic
- Underlying source date: Unknown; do not infer a release date
- Review state: current; 0 pending source changes
- Applicable version: Not pinned; check current documentation

Start from the task you are delegating. Reading a draft, sending it to a recipient and paying an invoice have different consequences and need distinct rules.

## Write an actionable boundary

“Ask before external email” needs a definition of external, the allowed recipients, whether attachments count and how a approval expires. Make these explicit before adding unattended execution.


## Check where it is enforced

Separate natural-language guidance from a tool permission and from an operating-system boundary. Test one allowed action and one blocked action with synthetic data; retain the activity record and exact approval.


## Minimal starting policy

1. Permit read-only work on a named test workspace.
2. Require explicit approval for a new recipient, purchase or irreversible deletion.
3. Set a stop condition and a retry ceiling for background tasks.

## Evidence and limits

- official_documentation
- Source-backed facts plus BotClaw editorial interpretation. No product account, inference or agent performance test was run.

## Sources

- https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
- https://docs.openclaw.ai/gateway/security
- https://hermes-agent.nousresearch.com/docs/user-guide/security
- https://help.openai.com/en/articles/20001530-getting-started-with-your-dot
