Skip to content
πŸͺΆPivra Desk

Approvals, rules and Touch ID

What runs on its own, what waits on a card, what needs Touch ID or a typed phrase, and how to write rules in plain words.

Updated 4 Oct 2026

Pivra Desk sorts every action by what it could do. The more it could change, the more it asks of you. The model proposes; your rules and approvals decide.

Three tiers

TierExamplesWhat happens
AutomaticReading a file, searching the web, looking at your calendarRuns on its own. Looking things up never needs a click.
Needs approvalSending an email, publishing a post, opening a pull request, running a command, changing a file outside its work folderWaits for you on an approval card that shows exactly what will happen: the recipient, the text, the file, the command.
CriticalMoving money, deleting, deploying, email to anyone outside your trusted domains, changing a saved passwordNeeds Touch ID on a Mac that has it, or a phrase you type. No agent moves money on its own; the money tool has no payment rail connected.

The approval card

A card appears in the chat and under Needs you on Home. It has:

  • Allow: do exactly what the card says. If a draft still has a gap in it (for example "[Your Name]"), the button reads Allow as written so you know it will go as it is.
  • Decline: do not do it. The agent is told, and carries on without it.
  • Always allow: every action of this kind from now on runs without asking. Pivra Desk never offers it for commands (one approved command must not allow every other) or for a draft-only email (once a mailbox is connected, mail would go out unasked).

If you move on without answering, the card settles itself: "You moved on without answering, so this did not run."

Critical cards

On a Mac with Touch ID the card shows Approve with Touch ID and Decline. Touch ID happens in the desktop app itself, which signs and sends the approval. Elsewhere the card shows a short confirmation phrase; type it exactly (Type: …), then press Approve.

In Settings β†’ Safety β†’ Critical actions you choose whether critical actions can be approved In the app only or In the app or by typed phrase (the phrase is what lets you answer from Slack or Teams). Trusted email domains lists your own domains; email to anyone else becomes critical.

Rules, in plain words

Open Rules for an agent. The page says: "Say when your agent may act alone, when it acts only on your word, when it asks, what you do yourself, and what it never does. A built-in review still checks every action, and password changes always come to you."

Write each rule as a sentence under When it wants to…, for example:

  • "Never email anyone at example.com."
  • "Ask before posting anything on LinkedIn."
  • "You may read any file in ~/Projects without asking."
  • "I send invoices myself."

A never rule stops the action at once, with no card. An ask rule turns an automatic step into a card. Rules are yours to read back at any time.

Approvals from your phone

If you connect your own Slack or Microsoft Teams bot (Settings β†’ Channels), approval cards are sent there with Allow and Decline buttons, so you can answer from your phone. Only the channel's owner can press a button, a card can be decided once, and sign-ins and blocked actions never get buttons: they need the desk. Critical cards there need the typed phrase, or In the app only keeps them on your computer.

Every decision is recorded

Activity shows every run on your computer: the steps, the tools called, what was read, and what you decided. Nothing of this leaves the machine.

Related

Was this helpful?

If you have questions or suggestions, email us at support@pivra.ai .