---
title: "Human approval"
canonical: "https://canmyagentuse.com/features/human-approval"
contentKind: "feature"
locale: "en"
description: "Pause before a tool action or file change until a person confirms."
llmSummary: "Human approval pauses an action until a person confirms or denies it. Action scope, remembered decisions, and policy behavior are qualifiers."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["runtime"]
---

# Human approval

Human approval pauses an action until a person confirms or denies it. Action scope, remembered decisions, and policy behavior are qualifiers.

- HTML: https://canmyagentuse.com/features/human-approval
- JSON: https://canmyagentuse.com/api/v1/features/human-approval.json
- Markdown: https://canmyagentuse.com/features/human-approval.md

Terminology basis: **Common product term** — https://github.com/different-ai/openwork.

## Current support at a glance

Human approval: 12 supported, 1 partial, 0 unsupported, 18 unreviewed across 31 cataloged products.

- Reviewed current products: 13 of 31
- Supported: 12
- Partial: 1
- Unsupported: 0
- Unreviewed: 18
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

Pause before a tool action or file change until a person confirms.

The matrix below lists published **web**, **desktop**, and **CLI** surfaces. Unreviewed cells remain **unknown** until a dated note and public source support a more specific status.

Use the Markdown and JSON twins if you are an agent reading this site.

## Catalog context

- Category: [runtime](/categories/runtime.md)
- Terminology basis: Common product term
- Aliases: None

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Grok Bot desktop documentation observation; observed 2026-08-28
  - Environment: hosted-default
  - Constraint (policy): Auto Review is model-based and complements rather than replaces explicit approval boundaries and least privilege
  - Constraint (runtime): local-computer execution defaults to asking every time and is configured separately from cloud-computer actions
  - Evidence: [xAI — Grok Bot approvals, security, and privacy](https://docs.x.ai/grok-bot/approvals-security-and-privacy) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Grok Bot shows a proposed operation and inputs before approval; desktop controls include Allow once, Deny, and matching Always allow rules, while Require Approval rules take precedence.

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Replit Agent documentation observation; observed 2026-08-28
  - Environment: hosted-default
  - Constraint (plan): the documented gate applies when Plan mode is selected and approves the plan before file changes, not each tool call
  - Evidence: [Replit — Build with Agent](https://docs.replit.com/learn/build-with-agent) — documented; observed 2026-08-28
  - Qualification note 13: Evidence checked 2026-08-28: Replit Plan mode waits for plan approval before Agent changes project files, but this is an opt-in plan-level gate rather than a documented per-tool approval system.
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Supported**
  - Target: dated-documentation — current Cursor documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): ordinary workspace-file edits do not prompt; terminal, MCP, configuration-file, and sensitive actions do unless pre-approved or another run mode applies
  - Evidence: [Cursor — Agent security](https://prod.cursor.com/docs/agent/security) — documented; observed 2026-08-28
  - Qualification note 4: Evidence checked 2026-08-28: Cursor requires manual approval for sensitive actions by default, including terminal commands, MCP connections and calls, and configuration-file edits; ordinary workspace-file edits are saved immediately without approval.
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Supported**
  - Target: dated-documentation — current OpenWork repository documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): effective prompts depend on workspace and server approval configuration
  - Evidence: [OpenWork — Publisher repository](https://github.com/different-ai/openwork) — documented; observed 2026-08-28
  - Qualification note 1: Evidence checked 2026-08-28: OpenWork Desktop surfaces permission requests and documents allow-once, always-allow, and deny responses.

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Supported**
  - Target: dated-documentation — current VS Code documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): permission level, tool settings, saved approvals, and organization-managed rules determine which calls prompt
  - Evidence: [Microsoft — Manage approvals and permissions in VS Code](https://code.visualstudio.com/docs/agents/run/approvals) — documented; observed 2026-08-28
  - Qualification note 6: Evidence checked 2026-08-28: VS Code can show a confirmation dialog for tool calls, with approval scopes ranging from one use through future invocations and managed rules that can continue to require approval.
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Supported**
  - Target: dated-documentation — current Zed documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): per-tool defaults and matching allow, deny, and confirm patterns determine prompts
  - Evidence: [Zed — Tool permissions](https://zed.dev/docs/ai/tool-permissions) — documented; observed 2026-08-28
  - Qualification note 11: Evidence checked 2026-08-28: Zed Agent tool permissions support confirm, always-allow, and always-deny rules for terminal, edit, write, delete, fetch, MCP, and other tools.
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Supported**
  - Target: dated-documentation — current Continue documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): a tool whose policy is Automatic skips the human permission step
  - Evidence: [Continue — How Agent mode works](https://docs.continue.dev/features/agent/how-it-works) — documented; observed 2026-08-28
  - Qualification note 9: Evidence checked 2026-08-28: Continue Agent mode asks the user for permission between a model tool call and tool execution unless that tool's policy is set to Automatic.
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Supported**
  - Target: dated-documentation — current Cline documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): settings and policy can require approval, auto-approve, or disable specific tools
  - Evidence: [Cline — Tools and approval controls](https://docs.cline.bot/tools-reference/all-cline-tools) — documented; observed 2026-08-28
  - Qualification note 8: Evidence checked 2026-08-28: Cline documents approval or auto-approval policies, including requiring approval for risky Bash and write/edit operations.
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Supported**
  - Target: dated-documentation — current Warp documentation; observed 2026-08-28
  - Environment: local-default
  - Evidence: [Warp — Getting started with Warp](https://docs.warp.dev/) — documented; observed 2026-08-28
  - Qualification note 12: Evidence checked 2026-08-28: Warp says local Agent users can review changes and approve actions before they execute.
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Supported**
  - Target: dated-documentation — current Claude Code documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): prompts depend on permission mode and rules; acceptEdits, auto, dontAsk, and bypassPermissions reduce or remove routine prompts
  - Evidence: [Anthropic — Claude Code permission modes](https://code.claude.com/docs/en/permission-modes) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Claude Code Manual mode stops before most file edits, shell commands, or network access, and its plan flow can keep edits blocked until the person approves the plan.
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Unknown**
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Supported**
  - Target: dated-documentation — current OpenCode documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): approval requires an ask rule; tools are enabled without prompts by default
  - Evidence: [OpenCode — Permissions](https://opencode.ai/docs/permissions/) — documented; observed 2026-08-28
  - Qualification note 10: Evidence checked 2026-08-28: OpenCode permission rules can resolve a tool call to ask, and an ask prompt offers once, session-scoped always, or reject outcomes.
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Supported**
  - Target: dated-documentation — current Gemini CLI documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): security policy and sandbox configuration still determine the effective execution boundary
  - Evidence: [Google — Gemini CLI tools reference](https://geminicli.com/docs/reference/tools/) — documented; observed 2026-08-28
  - Qualification note 5: Evidence checked 2026-08-28: Gemini CLI requires manual confirmation for file-modifying tools and shell commands and shows the proposed diff or exact command before execution.
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Supported**
  - Target: dated-documentation — current GitHub Copilot CLI documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (policy): command-line and saved permissions can pre-authorize calls; deny rules take precedence
  - Evidence: [GitHub — Allowing and denying tool use in Copilot CLI](https://docs.github.com/en/copilot/how-tos/copilot-cli/use-copilot-cli/allowing-tools) — documented; observed 2026-08-28
  - Qualification note 7: Evidence checked 2026-08-28: GitHub Copilot CLI prompts before destructive shell commands, file edits, or URL access unless the relevant permission has already been granted.
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
