Documentation

Approvals and permissions

Sanaf asks before anything it cannot undo. Rules are set per kind of action rather than per app or per job, so sending an email and updating a record are governed separately, and an unattended run is held to a stricter rule than one you are watching.

Last updated 2026-09-04.

Three answers, per kind of action

Every action Sanaf can take falls into a kind: read something, draft something, send something, change a record, spend money. For each kind you choose one of three answers: do it, ask me first, or never.

Setting the rule by kind rather than by app is the part that matters. "Never spend money" holds in every app you connect, including one you connect next month, which a per-app rule cannot promise.

Attended and unattended

A request you typed and a schedule that fired at four in the morning are not the same risk, and they do not get the same rule. When nobody is watching, Sanaf applies the stricter setting and holds the work rather than guessing.

That is why a job can be trusted to send follow-ups during the day and still queue them for you overnight, without you maintaining two jobs.

Shadow mode

A new job starts in shadow mode: it does the work and drafts the output, and nothing leaves until you say so. You promote it a level at a time as it earns the room.

Shadow mode is not a trial limitation and it does not expire. Some jobs stay there permanently, which is a reasonable thing to want.

When it asks

An approval arrives where the work is happening: in the thread in Slack or Microsoft Teams, or in the console. It says what it wants to do, why, and what it will do if you say no.

If nobody answers, nothing happens. Work waits rather than proceeding on a timeout, which is the only safe default.

The record

Everything Sanaf did, everything it asked about, and everything it declined to touch is in the work log, with the rule that applied. That log is the answer to "what did it do today", and it is written to be read by someone who was not there.

Questions

Frequently asked

Can I make it never do something, permanently?
Yes. "Never" is one of the three answers, it is set per kind of action, and it holds across every app and every job, including apps you connect later.
What happens if nobody approves a request?
The work waits. Nothing proceeds on a timeout, and the pending item stays in the log until someone answers it or cancels it.
Does it ask every time, forever?
Only for the kinds of action you left on "ask". Most teams start strict and loosen a kind at a time as they see what it actually does.