Approvals tab
The Approvals tab in the browser extension lists tool requests that wait for an Administrator's decision, and lets you approve or deny each one.
Written By Chris Scaminaci
Last updated About 1 hour ago
The Approvals tab in the QuantumOps browser extension lists the tool requests that are waiting for an Administrator. Each request is an action that your governance rules say must be approved by a person before it runs. You read it, then approve or deny it.
Before you start: Install the browser extension and sign in to it. Only people with the Administrator role can see requests and decide them. The tab is listed in the More menu for everyone, but anyone else sees Tool approvals need the Administrator role. Approvals for your own chat actions appear inline in Chat. instead of the list.
What lands here
The tab holds requests that do not belong to a person's own chat:
- Steps of an Agent Runner that must be approved before they run.
- Write requests from an external AI client, for example a request to add a note to a HaloPSA ticket or to change its fields.
This is the only place to decide those two kinds of request.
Approvals for your own chat stay in your chat: you decide them on the card, as described in Approving Qubit's actions. Approvals in Slack and Teams are decided on the card in that conversation; see Approvals and files in Slack and Teams. Which tools ask for approval at all is set in Tool Governance.
Open the tab
- Select More in the tab strip.
- Select Approvals.
For an Administrator, the More tab shows the number of requests waiting, and the same number appears beside Approvals in the menu. The count is not shown to anyone else.
When nothing is waiting, the tab says Nothing is waiting for approval.
Decide a request
Each request is a card. Its title is the tool, and a chip beside it names where the request came from: AgentRunner for a step of an Agent Runner, Copilot for a write request from an external AI client (the Copilot surface in Tool Governance, not the Copilot card on the Ticket Dashboard).
- Read the line under the title: Requested with how long ago, and who asked. Where the request has an expiry, the line ends with expires in and the time left. A request that nobody decides expires after 24 hours and can no longer be approved.
- Read the reason, when there is one, and the arguments in the block below it. The arguments are exactly what will run.
- Select Approve to run the stored action once, or Deny to refuse it. The tab confirms with a message such as Approved followed by the tool name, and the request leaves the list.
What Approve does depends on where the request came from. For an Agent Runner step, the paused run continues from that step. For an external AI client, the change is made in HaloPSA and the client sees the result the next time it checks.
If another Administrator already decided the request, or it has expired, the tab shows an error message instead.
Your decision is recorded against your account.
Review a request before you approve it
Approving runs the action for real, with no way to edit it first. Before you select Approve on a change to HaloPSA:
- Check that the ticket number is the one you expect.
- Read the new values in full. For a note, read the whole text and check whether it is hidden from the end user. For an update, check each field against what you expect.
- Check who asked and why. If the reason does not match the change, deny it.
- When you are not sure, deny it. The requester can ask again.
Related pages
- Approving Qubit's actions: the approvals that belong to a chat.
- Agent Runners: the runs that can wait for approval.
- Connecting external AI clients over MCP: the clients whose write requests land here.
- Tool Governance: how administrators decide which tools ask for approval.
Was this helpful?
Still need help? Ask the team