Approvals, undo and your data
What pauses for your yes, what can be reversed, how outside content is handled, and who owns what.
On this page
This is the part of the design that matters most, so it is worth reading even if you skip the rest.
Approval for designated actions
Designated sensitive actions stop and ask you first, including:
- Deleting a task, a certification, a register or a saved import
- Submitting or saving a form on a web page through the browser extension
- Creating a scheduled job or a standing watch
- Running an approved external connector that changes external data
You see the proposed action before you decide. Declining prevents that action; earlier completed steps are not automatically undone. Ordinary authorised saves and updates can proceed without a separate approval. Approval permits the tool action; professional acceptance of the result remains a separate decision.
Metis cannot approve itself. Approval requirements are enforced before tool execution across the supported assistant surfaces, including the app, browser extension and messaging channels.
You can allow it to remember approval for allowlisted read-only external lookups. Read-only requests can still disclose their query to the connected service, so check the data and destination. Remembered approval cannot grant standing permission for sending, deleting or submitting.
Undo
Ask Metis to undo and it reverses its most recent change to your data in that conversation. "Change the due date… no, undo that."
Be clear about what this is: a convenience, not an audit trail. It covers the last change in the current conversation, for about fifteen minutes, and restores the fields you could normally edit yourself — not deeper artefacts like the original file attached to a certificate. For anything you need to be able to prove later, use the module's own history.
Memory changes work the same way: every update appears as a chip you can undo, and Brain notes keep a version history with one-click restore.
Outside content is marked as untrusted
Document and external-tool content is marked as untrusted, instructing Metis to analyse it without following embedded commands. This helps resist malicious instructions but does not guarantee that they can never influence a response. Inspect proposed actions, recipients and destinations before approving them.
Your saved working instructions can guide later conversations. Read material before adding it to memory; do not turn unreviewed outside text into trusted instructions.
Access and working context
Account and workspace access is checked by the service. Selected agent reads also use a database-constrained read path. These controls govern access; they do not depend only on the assistant following an instruction.
Where you are a member of a team workspace, it sees what your role in that workspace permits — no more.
Personal memory can carry across conversations. Projects prioritise relevant material but do not create separate employer data boundaries: other eligible material belonging to your account can still be retrieved.
Whose data it is
Your account is personal. Only upload or reuse an employer's material where you have authority to do so; changing employer does not create permission to keep or reuse it. The privacy policy describes data handling, the non-training policy and retention exceptions for shared records.
Your Brain notes can be exported from the Brain settings menu. That export is not a complete copy of every account or shared-workspace record; check the export and retention arrangements for the other material you need to keep.
Everything is metered
Every AI call, transcription and external request is counted against your allowance, so cost cannot run away silently. Runs also have per-turn spending caps. What each plan includes is on the pricing page.
Informational only — you verify against the approved exposition before you act.
Frequently asked questions
Can Metis approve its own actions?
No. The approval gate is in the core of the assistant and applies on every surface. It cannot be granted to itself, and an unattended scheduled run refuses anything that would need approval rather than proceeding.
Can I turn approvals off to save time?
Remembered approval is limited to allowlisted read-only external lookups. It cannot grant standing permission for sending, deleting or submitting. Ordinary authorised saves and updates may not need a separate approval.