Appearance
Approvals and veto
Two rules, and neither is a per-agent setting.
No agent acts outward. Nothing an agent does reaches a third party. No email, no post, no CRM write, no published page. Every result is inward: a note you read.
Nothing an agent wrote counts until a person says so, unless the agent could show where it came from.
Inward and outward
| Inward, which agents do | Outward, which agents do not |
|---|---|
| Write a note for you | Send an email |
| Produce a shortlist with sources | Add a contact to your CRM |
| Answer a question from your data | Publish a page |
| Summarise what needs a decision | Post to a channel |
| Read back its own earlier notes | Message a customer |
A lead finder produces a shortlist. It does not contact anybody on it. What happens next is a decision you make, with a tool you chose, at a time you picked.
This is a property of the whole feature rather than of each agent, so there is no configuration screen where it can be relaxed by accident.
Why output is held back
An agent that states a figure it cannot source is worse than an agent that says nothing, because the figure is confidently wrong somewhere nobody thinks to check. A note is only useful if you can trust the numbers in it without re-deriving them, which is the entire point of having the agent.
So when an agent writes a note, Studio checks whether its content is grounded in something the agent actually read during that run. If it is not, the note is quarantined: written, kept, and unreadable by anything until a person accepts it.
Quarantined is literal. No widget can retrieve it, no assistant can cite it, no other agent can read it, no search returns it. It is not "flagged" and still in circulation.
Waiting for you
Agents → Waiting for you lists everything held. Each entry says which agent produced it and why it is being held:
Pricing changes, week of 8 September From Competitor watch The agent could not point to a source for this, so it was held back.
You have two buttons.
Accept makes it readable, immediately and everywhere. Accepting means exactly one thing: this may now be used to answer questions.
Reject leaves it unreadable, permanently, and asks you why.
The reason is required
Rejecting without a reason is refused, and this is deliberate rather than an oversight in the form design.
The reason is the only thing in the whole loop that makes the next agent better. "It made up the figure, there was no source for it" is a test case. A rejection with no reason is a deleted file and nothing learned. So the button stays disabled until you write a sentence.
One sentence is enough. It is stored with who rejected it and when, in the same approval record the rest of Studio uses, so there is no second place to look for what was decided.
Doing it from a knowledge file
The same accept and reject buttons appear on the knowledge file itself. They act on exactly the same state: the inbox is for triaging a batch, the file page for when you are already looking at one thing. Neither is the real mechanism and the other a shortcut.
What happens to a rejected note
It stays unreadable and it stays stored. Deleting it would remove the evidence of what the agent did, which is the opposite of what you want after finding out it got something wrong.
Deleting an agent
Deleting an agent stops its schedule and removes the agent. Everything it already produced is kept, including what you accepted and what you rejected. Removing the thing that made a claim does not retract the claim.
Next
- Testing an agent: reading a run before deciding
- What agents can see: the read side of the same boundary