Approvals and permissions
Sanaf asks before anything it cannot undo. Rules are set per kind of action rather than per app or per job, so sending an email and updating a record are governed separately, and an unattended run is held to a stricter rule than one you are watching.
Last updated 2026-09-04.
Three answers, per kind of action
Every action Sanaf can take falls into a kind: read something, draft something, send something, change a record, spend money. For each kind you choose one of three answers: do it, ask me first, or never.
Setting the rule by kind rather than by app is the part that matters. "Never spend money" holds in every app you connect, including one you connect next month, which a per-app rule cannot promise.
Attended and unattended
A request you typed and a schedule that fired at four in the morning are not the same risk, and they do not get the same rule. When nobody is watching, Sanaf applies the stricter setting and holds the work rather than guessing.
That is why a job can be trusted to send follow-ups during the day and still queue them for you overnight, without you maintaining two jobs.
Shadow mode
A new job starts in shadow mode: it does the work and drafts the output, and nothing leaves until you say so. You promote it a level at a time as it earns the room.
Shadow mode is not a trial limitation and it does not expire. Some jobs stay there permanently, which is a reasonable thing to want.
When it asks
An approval arrives where the work is happening: in the thread in Slack or Microsoft Teams, or in the console. It says what it wants to do, why, and what it will do if you say no.
If nobody answers, nothing happens. Work waits rather than proceeding on a timeout, which is the only safe default.
The record
Everything Sanaf did, everything it asked about, and everything it declined to touch is in the work log, with the rule that applied. That log is the answer to "what did it do today", and it is written to be read by someone who was not there.