Skip to content

Command approvals

A deep agent can run shell commands, and a command can change files or reach other systems. So before it runs one, the agent stops and asks the person it is talking to. Nothing runs until that person answers.

Command approval is on for every agent by default.

In web chat and the VirtuAI CLI, the conversation shows The agent wants to run a command, the exact command, and a countdown. Choose one of:

Option What it allows
Allow once This command, this time only.
Allow for this chat Every command this agent runs in the current conversation.
Allow 60 min Every command this agent runs for you in the next 60 minutes, in any conversation.
Always allow Every command this agent runs for you, from now on.
Deny The command does not run. The agent is told it was denied and can continue another way.

If nobody answers within 5 minutes, the command is denied.

Standing permissions (Allow for this chat, Allow 60 min and Always allow) belong to you and to this one agent. They don’t carry over to other users or other agents.

Google Chat, Telegram, Slack and A2A have no way to show the prompt. On those channels, when a sandbox is available to the workspace, a deep agent’s commands run without asking.

If an agent that serves one of those channels should never run commands, keep it on the Classic harness, and use a separate deep agent in web chat or the CLI for work that needs commands.

Publishing an agent can also require a second person’s approval. That is a separate setting, described in Drafts and publishing.