Approvals & the safety gate
Turn on Nebula's safety gate to pause agents before risky actions — then approve, deny, or always-allow each write and delete from the prompt bar.
The safety gate pauses an agent before it runs an action that looks risky — an irreversible delete, a message to someone outside your team, or anything that doesn't match what you asked — and asks you to approve it first. It's off by default, so agents act without interruption until you switch it on.
Turning the safety gate on
The gate is a single on/off switch — there's nothing to configure beyond turning it on. You can flip it from two places.
From the prompt bar — click the shield icon to the right of the message input. Its tooltip reads Safety gate: on (pauses risky actions) or Safety gate: off (runs everything).
From settings — open Account → Profile and find the Write approval section. Toggle Safety gate on. The same switch drives both surfaces.
Off by default. When on, the gate applies to your actions in the current workspace — each person sets their own.
What the gate catches
When it's on, Nebula reviews each write or delete an agent is about to run and pauses the ones that look dangerous or unexpected: irreversible deletes, sending to people outside your team, or anything that doesn't match what you asked for. Everything else runs without a prompt.
Approving an action
When the gate fires, the agent stops and shows an approval card. The card names the action, explains why it was flagged, and lays out exactly what the action will do, so you can decide with full context.
| Approve | Deny | Always allow | |
|---|---|---|---|
| What it does | Runs this one action | Blocks it; the agent moves on | Runs it and stops asking for this tool |
| Add a note? | No | Optional reason sent to the agent | No |
| Best when | The action is right | It's wrong or you've changed your mind | You trust this tool and don't want to be re-asked |
If several actions are waiting, the card steps through them one at a time — "This agent wants to run a write/delete action (1 of N pending)."
A waiting card holds the thread
A card waits until it's dealt with — there's no countdown, and nothing expires out from under you while you go and check something. In exchange, an open card holds its thread: new messages don't send until the card is answered or dismissed, so the conversation can't run ahead of a decision nobody has made.
Only the person whose request paused the agent can answer. Everyone else sees Waiting on name to respond in place of the buttons, which keeps two people from answering the same card different ways. The composer says the same thing, so it's clear why typing isn't going anywhere.
Don't want to answer it? Dismiss it with the X in the card's header. The agent is told the input isn't coming, and it moves on with whatever it can still do rather than asking again. A dismissed write approval counts as a denial. Dismissing also clears any sibling cards still waiting in the same batch — answers you already gave stand and still run — so the thread unblocks in one go.
Not every card holds the thread:
The safety gate card above — approve, deny, or always-allow a write or delete. Holds the thread.
The agent needs you to pick between options before it continues. Holds the thread.
An agent needs you to connect an app, or hand it a key it doesn't have yet. These don't pause anything — the agent carries on with what it can do, and the card waits. Close it with its X and it stays gone.
A card left alone doesn't strand the thread forever — after a couple of days the thread starts accepting messages again, and the card is still there to answer.
Always-allowed tools
Choosing Always allow adds that tool to a per-workspace skip list, so future actions from it run without a prompt. Review and revoke the list anytime under Always allowed (skip the safety check) in the Write approval section — removing a tool puts it back under the gate.
Prefer the gate's reason over blanket trust. Approve case by case while you're learning what an agent does, then reach for Always allow only for the tools you've seen behave.
Related
Your profile
Set your Nebula display name, avatar, timezone, and appearance. Your profile follows you across every workspace you belong to — personal or team.
Connected accounts
Connect your own accounts — Gmail, Calendar, GitHub, and more — so your agents can act on your behalf. Connections stay private to you, per workspace.