# Approvals and control

> How you stay in charge of StellarFirm: risky steps wait for Approve unless your house rules allow them, Reject stops them, and activity is visible.

The control model is simple. Your assistants prepare, and you decide. Nothing that sends, deploys, charges, publishes, or creates runs until you approve it, unless your house rules allow that kind of step.

## The control model

| Layer | What it does |
| --- | --- |
| Approve and Reject | Every risky step waits for you. Approve lets that one step go ahead. Reject cancels it. |
| House rules | The rules in your company brief plus what you allow without asking. They decide what happens after the work. |
| Auto-approve switches | Off until you turn them on. Only you can turn them on. |
| Visibility | Jobs, the assistant's computer, and chat show what is happening. |

## Approve and Reject

A risky step is held, and the job stays open while it waits. You answer on [Approvals](https://stellarfirm.ai/app/approvals) or in the chat.

- **Approve** carries out that one step. It does not give blanket permission for the next one.
- **Reject** cancels the step. Nothing is sent, pushed, or created.

See [Approvals](/docs/ceo/approvals) for the full list of what asks.

## Stopping something

You do not need to catch a job mid-run to stop it. The risky step is the one that matters, and it cannot happen without you. If something looks wrong:

1. Open [Approvals](https://stellarfirm.ai/app/approvals) and reject the waiting step.
2. Tell the CEO assistant in chat what went wrong, so it can adjust.
3. If a change has already been published, close or revert it in your source control service.

## What you allow without asking

[Settings](https://stellarfirm.ai/app/settings) has an **Auto-approve** page. Every switch starts off. When you turn one on, StellarFirm asks you to confirm, and warns that the assistant may do something unexpected.

- The assistant does that kind of step without asking, and tells you afterwards in the same chat.
- You can turn a switch off at any time, and it applies straight away.
- Steps that reach other people, such as pull requests, always ask today.

No assistant can turn on auto-approve for itself, and the CEO assistant cannot do it for you.

## See what happened

| Where | What you can check |
| --- | --- |
| Chat | Updates as an assistant works, and a report when it finishes. |
| [Jobs](https://stellarfirm.ai/app/jobs) | Each job, with the Coder's actual changes when you expand it. |
| [Computer](https://stellarfirm.ai/app/computer) | The assistant's own computer, including its terminal. |
| [Usage](https://stellarfirm.ai/app/usage) | What your assistants have used, by assistant and job. |
| [Activity log](/docs/workspaces/activity-log) | A record of what happened in a workspace. |

## Prompts to try

```prompt title="Get a recap"
CEO, give me a recap of what your assistants did today: what was finished, what was approved, and what is still waiting.
```

```prompt title="Ask before acting"
CEO, for [goal], tell me what you plan to do and which steps will need my approval before anyone starts.
```

## Next

- [Approvals](/docs/ceo/approvals)
- [House rules](/docs/ceo/house-rules)
- [Security](/docs/trust/security)

---

Source: https://stellarfirm.ai/docs/trust/approvals-and-control
