The three answers
Every rule gives one action one of three answers.
Anything you haven’t written a rule for keeps the default:
Actions no rule matches keep the default: sends, changes, and deletions pause for your approval.So you’re not starting from nothing. Rules are adjustments to a sensible baseline, in either direction.
When you’d write one
To stop being asked about something routine that’s obviously fine. Your coworker posting to the team channel it always posts to. To be asked about something the default lets through. A coworker allowed to update records, where you’d rather see the ones touching pricing. To rule something out entirely. Deleting. Emailing outside the company. A specific app you attached for reading only.Where they live
On the coworker’s Files tab, in the file labelled Permissions. Rules take effect from your coworker’s next step — you don’t need to restart the task.A rule can take power away, and it can remove a prompt for something your coworker was already allowed to do. It cannot grant a capability that’s switched off. If Talking to people is off, no rule makes it possible.
The strictest rule always wins
When more than one rule matches the same action, the strictest of them applies:
Never beats ask, and ask beats allow — whatever order the rules are in.
- Order doesn’t matter. Moving rules around can never weaken your policy, so you can’t accidentally undo a “never” by adding something below it.
- A narrow rule can’t loosen a broad one. If you’ve said never delete anything, adding “always allow deleting drafts” does not create an exception — the never still wins. To carve out an exception, narrow the original rule instead of layering another on top.
A sensible starting set
For a coworker with real access to your systems:- Never delete anything
- Never email outside the company
- Always ask before anything touching pricing or contracts
- Always allow posting to its own team channel
- Always allow reading from any connected app
Rules, connections, or capabilities?
Three levels of control, from broadest to finest.
Reach for the finest one that solves your problem. Switching a capability off to avoid a prompt is a blunt fix that costs you the capability.
Common questions
Do I need rules to be safe?
Do I need rules to be safe?
No. The default already pauses for sends, changes and deletions. Rules are for tuning, not for basic safety.
Can a coworker change its own rules?
Can a coworker change its own rules?
It can propose a change, and it lands on the Improvements tab for your approval like anything else. It can’t quietly widen its own permissions.
Do rules apply to every task?
Do rules apply to every task?
Yes — they belong to the coworker, so every task it runs uses them.
What if two rules could both apply?
What if two rules could both apply?
The strictest one wins — never, and never asks, both beat allow. Being more specific doesn’t override it, and neither does being further down the list. See “The strictest rule always wins” above.
Can different coworkers have different rules?
Can different coworkers have different rules?
Yes, and they should. A research coworker and one with access to your CRM warrant very different rules.
Next steps
Approvals
What asking looks like.
Connecting your apps
Control at the action level.
Capabilities overview
The broadest control.
Automatic checks
Rules that act rather than ask.
