Where the Approval Gate Is Armed, and Where It Isn't

The tool-approval card is a guardrail on one surface, not a workspace-wide guarantee. Knowing which surface is the difference between a control and a belief.

Sophia Faria
Sophia Faria
Sep 13, 2026

A human-in-the-loop control you have not located precisely is not a control. It is a belief about a control.


Insulin can pause before a sensitive tool call and ask. A Tool Approval Required card appears in the thread, naming the tool, showing the arguments it would be called with, and explaining why it stopped. Allow runs it; Deny does not. Afterwards the card keeps a badge recording what you chose.

Leave it alone and the request times out after about three minutes, the card is marked Expired, and nothing is sent. That default matters: an unanswered approval fails closed.

The part that decides how you design around it

The card is offered in an interactive solo chat in the web workspace, on the main thread. It is not offered — and the action is not held back — in:

  • a channel,
  • a Slack or Microsoft Teams DM,
  • a reply written inside a sub-thread.

Those surfaces cannot render the card or send your decision back, so the turn proceeds without pausing.

This is worth reading twice, because the intuitive assumption is the opposite. Most people assume an approval requirement is a property of the tool — arm it once, and it holds everywhere the tool can be called. Here it is a property of the surface: the same agent calling the same tool pauses in one place and proceeds in another.

What to do with that

Scope the agent, not the prompt. If an action genuinely must not happen without a human, the control is the agent’s integration allowlist — what it can reach at all — rather than an approval card that only one surface can show. An agent that cannot call the tool cannot call it in a Slack DM either.

Decide deliberately which agents belong in channels and chat apps. A channel is a collaboration surface, and an agent that only ever reads and drafts is a good fit for one. An agent that writes to a business system is a different proposition there, because the pause you would rely on in the web workspace is not available.

Treat the card as a guardrail on the surface that can show it, which is exactly how the documentation frames it — not as a workspace-wide guarantee that every sensitive action will wait for you.

Plan approvals are a different gate

Worth separating, because they are easy to conflate. For a multi-step task an agent may present a plan before executing — the steps it intends to take — and you approve, reject, or modify it before anything runs.

That is a gate on intent, before the work starts. Tool approval is a gate on one action, mid-turn. A plan you approved does not pre-approve every tool call inside it, and a tool approval says nothing about the overall shape of what the agent is doing. Use both, and know which question each one is asking you.

Frequently asked questions

Does the tool approval card appear everywhere?

No. It is offered in an interactive solo chat in the web workspace, on the main thread. In a channel, a Slack or Teams DM, or a sub-thread, the card is not shown and the action is not held back.

What happens if I ignore an approval request?

It times out after about three minutes, the card is marked Expired, and nothing is sent. An unanswered approval fails closed.

How is a plan approval different from a tool approval?

A plan approval gates intent before a multi-step task begins. A tool approval gates a single action mid-turn. Approving a plan does not pre-approve the tool calls inside it.

How do I stop an agent acting without approval in a channel?

Scope the agent rather than relying on the card. Restrict which integrations it can reach, so the action is impossible rather than merely gated on a surface that cannot show the gate.

Does the card record what I decided?

Yes. After you answer, the card keeps a badge showing Approved or Rejected, and an unanswered one is marked Expired.

Takeaways

  • The approval card lives on one surface: interactive solo chat, main thread, web workspace.
  • Channels, Slack/Teams DMs and sub-threads do not pause — they proceed.
  • Approval is a property of the surface, not of the tool. That is the counterintuitive part.
  • An unanswered request expires after ~3 minutes and nothing is sent.
  • If an action must never happen unapproved, restrict the integration instead.

More on the practice in human approval for AI agents, on scoping in agents, and on shared threads in how channels work.

Sources

Primary sources for the platform rules cited above. Last verified September 13, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

Browse every post on the Insulin Blog

Stay Updated

Get the latest Cloud GTM insights, product updates, and marketplace strategies delivered to your inbox.