Permissions, approvals and connected apps
Understand delegated access, human decisions and connected-app permissions.
A connection grants access to an eligible workspace under your own authority. It does not approve every future external action or give an automated client the right to make human decisions.
On this page
Overview
The external client acts with your enrolled identity and existing workspace permissions. Connected app suggestions, catalog listings and saved logins are not proof that an account is connected, authorized for this Artisan, or ready for a specific provider action.
Use the normal dashboard's Apps and decision flow to connect accounts and approve requested actions. Provider failures, expired credentials and unavailable capabilities need their actual recovery; they do not mean the same approved payload needs a new approval merely because execution failed.
Delegated MCP has no generic approve tool. The optional native operator route requires a separately registered first-party client and credentials isolated from automation. It is not yet available for general customer use. Use the normal Artie conversation or dashboard to make human decisions.
For organizations with an explicitly provisioned native operator client, these commands use the separate human profile:
artie login --operator --profile operator --origin https://api.artie.ai --client-id REGISTERED_NATIVE_PERSON_CLIENT_ID --workspace WORKSPACE_UUID
artie approval list TASK_UUID --profile operator --json
artie approval show DECISION_UUID TASK_UUID --profile operator --kind schedule --json
artie approval decide DECISION_UUID TASK_UUID --profile operator --kind schedule --expected-revision CURRENT_REVISION
artie task outcome TASK_UUID --profile operator --run RUN_UUID --expected-revision CURRENT_REVISIONDecision kinds are web, mail, calendar and schedule. The actual proposal is displayed before a person decides. These commands do not enable delegated automation to click yes, bypass account setup, grant itself authority, or record a human quality verdict.
The normal workspace connection management also supports preview/enroll/revoke with revision and operation identity. Revoke the intended grant deliberately; a delegated CLI logout clears local credentials and is not equivalent to revoking the standing workspace connection. Do not revoke a working client as a generic diagnostic step.
Need help with your workspace?
Contact support