I need the go-ahead before I act.

Here is exactly what I would doWho it reaches, and what it says
ApproveAlways allowEditDeny

You see the real details

The card shows a short summary of what will run: the key details, with long values cut short. If a message goes to someone, their address is on the card in bold.

What needs a yes

By default Bob reads on his own and asks before he writes. Writing means changing something in an app: sending an email, adding a calendar invite, updating a record. Slack messages are the exception. When you start a job by mentioning Bob or messaging him, he posts his Slack messages without a card, in the channel where you asked or in another one. An admin can change that.

One extra rule covers jobs a person starts. If a message would go to an address nobody typed, Bob asks first, even if approvals are off for that app and even if someone pressed Always allow before. Schedules and other automations work differently, as explained below.

What the four buttons do

To see what Bob no longer asks about, and any standing access you gave him to your own apps, type /bob grants. It numbers them, and /bob grants revoke 1 takes the first one back.

Who can press the buttons

By default, anyone in your workspace can answer an approval card. Admins can narrow that for cards that send something outward, such as an email. They name the people who may approve, and Bob mentions those people on the card. Anyone else who tries is told who can.

A card about someone’s own account, such as their mailbox, can only be answered by that person. More on acting for a teammate.

The receipt under the finished job says who approved what, so the trail stays next to the work.

When nobody answers

Bob nudges halfway through the wait. If nobody decides in time, the card closes with “This approval timed out”, and Bob carries on without that step and says so in the thread.

Schedules do not stop to ask

Nobody is there at 3am to press a button. So when you set up a schedule, Bob tells you which apps it may use and whether it may change things in them. Inside that list it acts. Outside it, it refuses and says so. The extra rule about addresses nobody typed does not apply here, because nobody is there to answer. The list is the limit. One exception: if an admin set an action to always ask, a schedule still asks, even though the card may time out. How scheduled jobs work.

Change the defaults

Admins can tell Bob in Slack, in plain words, to stop asking about an app, or to always ask before one. They can also set a rule for a whole app or a single action on the Policies page: run without asking, ask, or always refuse. The most specific rule wins. Anyone who can answer a card can also press Always allow, where it is offered, and that stops Bob asking the whole workspace about that one thing.