Some actions wait for a person to approve them. When Viktor wants to take one, he prepares it as a draft and posts an approval card. The action runs only after someone clicks **Approve**.

## Which actions need approval

These actions always need approval:

- Joining or leaving Slack channels.
- Reporting an issue to the Viktor team.
- Changing integration permissions or integration access.
- Changing workspace settings.
- Setting or removing a member's spend limit.
- Installing or uninstalling marketplace skills and skill bundles.
- Changing your Space's address or the Pages hostname.
- Adding a sender to Viktor's email allowlist (see [files and email](/docs/files-and-email)).

Admins can also require approval for individual integration tools. See [integration permissions](/docs/integration-permissions).

## Approve in Slack

1. Viktor posts a card listing the pending actions, with **Approve** and **Reject** buttons.
2. Click **Approve** to run the actions, or **Reject** to cancel them.
3. The buttons disappear and the card shows who decided, for example "✅ Approved by <name>" or "❌ Rejected by <name>".

Only the first click counts. A second click on the same card does not run the action again.

### Always approve a tool

When the card covers a single integration tool, it also shows **Always approve this tool**. Clicking it approves this action and changes that tool's setting, so later calls run without a card. The card then reads "✅ Always approve enabled by <name>".

The setting is saved only if you are allowed to change it:

- For a team integration, you need permission to edit that integration's tools.
- For a personal integration, you need to own the integration or the thread.

When a card for an integration action has no **Always approve this tool** button, it may show a **Change this tool's approval setting** link instead. It opens the tool's settings page.

## Approve in Microsoft Teams

Viktor posts a card with **Approve** and **Reject**. Teams cards have no always-approve option. To stop asking for a tool, change its setting in the Viktor app.

## Approve in Viktor app chat

In Viktor app chat, the approval card shows the pending action with **Approve** and **Reject** buttons. When always-approve is available, open the arrow next to **Approve** and choose **Always approve this tool**. After a decision, the card shows "Approved by <name>" or "Rejected by <name>", plus "Always approve enabled" when that was chosen.

## What happens after you decide

- **Approved:** Viktor runs the action and continues the task.
- **Rejected:** the draft never runs. Viktor cannot run a draft without an approval.
- **Tools set to forbidden** never run, even if someone asks.

Viktor can also refuse an approved action if he judges it to be harmful or the result of a prompt injection.

## Limits by plan and permission

- **Plan:** approvals work the same on every plan.
- **Permission:** saving **Always approve this tool** needs tool-edit rights on a team integration, or ownership of a personal integration or thread.
- **Admins:** set per-tool approval levels on the integration's tools page. See [integration permissions](/docs/integration-permissions).

## Common problems

**I clicked Always approve, but Viktor still asks.** You may not have permission to change that tool's setting. Ask an admin or the integration's owner.

**The card has no Always approve button.** It is shown only for a single integration tool. Built-in actions, like joining channels, always need approval. For other integration actions, use the **Change this tool's approval setting** link if it is shown.

**Viktor says there is no approval for his draft.** The draft was rejected or never approved. Ask him to try again and approve the new card.

**The Teams card has no Always approve option.** That is expected. Change the tool's setting in the Viktor app.

## Related

- [Talk to Viktor](/docs/talk-to-viktor)
- [Integration permissions](/docs/integration-permissions)
- [Workspace permissions](/docs/workspace-permissions)
- [Audit logs](/docs/audit-logs)