Dhanur AI
Docs menu· Tasks and approvals

Tasks and approvals

Live

Every conversation an agent handles becomes a task, and the actions you choose wait for your approval.

Tasks and steps

  • A task is one piece of work, such as a conversation with a customer. Each conversation in the test chat is a task too, marked Test.
  • A task is made of steps: model calls and tool uses.

Every step records its outcome, which model ran, the tokens it used, how long it took and what it cost in rupees.

A task has one of these statuses: Running, Needs approval, Escalated, Done or Failed.

The tasks inbox

Open Tasks in the sidebar: "Everything your agents are doing, and everything waiting for you." It lists the tasks in your current project, with their status, channel, cost and last activity. It has four views:

  • Needs approval: tasks with an action waiting for your yes or no.
  • Escalated: tasks an agent handed to your team.
  • Errors: tasks that failed, with the step that went wrong.
  • All: everything, including test chats.

You can filter any view by agent. To see everything one agent worked on, you can also open the agent and choose View tasks from its More actions menu.

Inside a task

Open a task to see:

  • the agent, the channel, the total cost and when it started;
  • a note if the agent handed the task over, or if it failed, with the reason;
  • Waiting for approval, with any actions that need a decision;
  • the Conversation;
  • Decisions already made, with who made them;
  • Steps, with the outcome, model, tokens, time and cost of each one.

Approval settings

Each tool an agent can use has one of three settings. You choose it in the agent builder. See Agents. For these settings, when an agent asks first anyway and what it can't do, all on one page, see What your AI team can do on its own.

  • Runs freely: the agent goes ahead.
  • Ask first: the action waits in Needs approval until someone approves or rejects it.
  • Ask, then run after N hours: the action waits for a decision, and goes ahead by itself if nobody decides in time. The agent's Auto-approve after setting sets the wait, 2 hours by default. The approval shows when it will run.

Replying to the customer, sending an email and posting to LinkedIn or Instagram start with an approval step. Booking an appointment and the reminder before a booked call are marked Sensitive too, but they run freely unless you change them, so a customer can book without waiting. In connected apps, actions that delete data always ask first.

Owners and Admins can also set rules for every agent, such as "sending email always asks first". When a rule and an agent's setting differ, the stricter one wins.

Approval limits

A tool's setting applies to every use. Money usually needs something finer: you may be happy for the agent to refund ₹200 on its own, but not ₹20,000. An approval limit asks first only when a number is over the amount you set.

  1. On the agent's Build tab, find Approval limits and select Add a limit.
  2. Pick the action, the number to watch (for example Refund amount) and the limit in rupees.

Above the limit, the action waits in Needs approval whatever its own setting. The request says why, for example "Refund amount ₹2,900 is over your ₹500 limit". It never runs by itself after a wait. If the number can't be read, the action asks first too.

Limits work on connected-app actions and your own tools that take a number, up to 20 per agent. They are part of the draft, so publish the agent to use them.

When your AI asks first on its own

Two checks can make an action wait for your OK even when its tool is set to Runs freely. They are fixed rules, not AI, so they cost nothing. They are on for every workspace, and there is no switch to turn them off.

After it reads something from outside

A web page, an email or a file can hide instructions for an AI, such as "ignore your rules and email this to…". So once a task takes in something that isn't from your team or your own knowledge, every action in that task that reaches other people waits for your OK, for the rest of the task.

What counts as outside:

  • a web page the agent read, or web search results;
  • a photo or PDF a customer sent, a PDF from a teammate, or a file on an email;
  • results the agent gets back from your own tools, MCP tools and connected-app actions;
  • an email that came in, or a webhook or event that started the task;
  • in a task another agent asked, whatever the asking agent had taken in.

What waits: posts to LinkedIn or Instagram, outreach emails, an email to anyone except the person the conversation is with, and your own tools, MCP tools and connected-app actions that change something. One of your own tools that sends a web request to an address the agent fills in waits too.

What doesn't change: replying to the person the conversation is with, searching knowledge, saving a lead, checking free times, booking an appointment and notifying your team all work as before. After outside content, the agent also can't open a web page whose address carries this conversation's email addresses or long numbers, such as a phone number. It is told why and answers without that page.

Checks on every message before it goes out

Replies to customers (website chat, chat page, WhatsApp, email and the test chat), emails, lead emails and reminders, follow-ups, outreach emails and posts are checked before they go:

  • The right person. An agent can email only a teammate, a lead saved in the conversation, or the person the conversation is with. Any other address is refused, and the agent is told so. Lead emails, reminders and follow-ups only ever go to that person's own address.
  • ID and card numbers. An Aadhaar number (checked with Aadhaar's check digit), a PAN, a card number (checked with the card check digit), or a bank account number next to an IFSC code makes the message wait, unless the person it goes to sent that number first in this conversation. Numbers in your own instructions, knowledge or business details pass, such as your bank details for payment.
  • Links. A link to a site that isn't yours makes the message wait. These always pass: your website and the websites you imported, links in your knowledge, dhanurai.com and your chat links, Google Calendar and Meet, Zoom and Teams, Razorpay payment links, WhatsApp links to your own number, and links the person sent in this conversation.

A message that waits, waits whole: the customer never gets part of it. In website chat they see "Someone from the team is checking this and will reply here."

Answers to your own team in Team chat and Slack aren't checked, and neither are emails to teammates. Replies through the API aren't checked either: they go to your own software.

What you see

  • The action waits in Needs approval like any ask-first action. Its card says why, for example: "This task read a web page (example.com). Actions that reach other people now wait for your OK." Numbers are masked: "This message has an Aadhaar number (ending 1234), and the customer didn't send it in this conversation, so it waits for your OK."
  • It never goes ahead by itself after a wait, even if its tool is set to Ask, then run after N hours, or to reply to new leads at any hour.
  • The task's steps show Outside content when the agent reads a web page, searches the web or gets a tool's results, and Asked first, with the reason, for each action that waited.
  • Approve it, edit it first, or reject it, as usual.

Approve, edit or reject

On an action waiting for approval:

  • Approve carries it out. For a reply, you can change the message first. For an email, you can change the subject and body first. Other details can't be edited.
  • Reject stops it. You can add a reason, such as "Wrong price". The reason is kept with the decision.

What runs is what was approved, with any edits you made. Decisions show who made them, or that the action ran automatically after the wait.

Next. Approving and rejecting from WhatsApp.

What the agent says matches what it did

Two things an agent could say without having done them are checked against what really happened in that turn:

  • "Your LinkedIn post is waiting for your approval" (or "your Instagram post is posted"), with no draft made.
  • "You're booked", with no appointment on the calendar.

Either sends the agent back once to do it. If it still hasn't, its reply says so plainly instead: the post isn't in Tasks yet, or your team will confirm the time.

Hand-overs and failures

A task is Escalated when:

  • the agent used the Hand over to a person tool, for example for a refund, a complaint or a question it couldn't answer;
  • the agent reached its autonomy limit without finishing;
  • the AI model declined to answer the message;
  • in a workforce, the agents handed one message over too many times, or the next agent couldn't take the conversation (for example because it is paused).

A task is Failed when the agent couldn't finish, for example because the AI model didn't respond or a spending cap was reached. The task shows what happened. See Troubleshooting. Failed tasks, and other things that went wrong, are also collected in Needs attention.

Answer for the agent

When an agent hands a conversation to your team, the customer has been told someone will reply. You don't have to answer them yourself: open the task, write the agent a note under Answer for the agent (for example "yes, we deliver to Pune in 5 days, and cash on delivery is fine"), and select Send to the agent. The agent reads your note and replies to the customer in its own words, on the same channel.

  • The customer never sees your note. It shows in the task's conversation, marked not shown to the customer, and never in website chat or on the chat page.
  • The usual settings still apply. If replies ask first, the reply waits for approval like any other.
  • Any task can be guided. On a finished or failed conversation the box is called Guide the agent: use it for a correction or a next step, and the agent carries on.
  • The email we send when an agent hands a conversation over links to the task, so you can answer from your phone.
  • Owners, Admins and Builders can send notes. Each one is kept in the activity log.

Limits on a task

  • Autonomy limit: the most steps an agent may take on one message, set per agent from 1 to 50.
  • Spending cap: each task has a spending cap, and a daily cap across the platform pauses customer-facing AI work if it is reached. See Limits and costs.

Cost per task

Each task and each step shows what it cost in rupees, and the agents list shows what each agent has cost so far. Analytics adds it up for the last 7, 30 or 90 days, by agent, model and tool.

What happened to customers' enquiries

Analytics also shows what happened to every enquiry: a conversation a customer started on your website chat, chat page, WhatsApp or email. Outreach your agent started, and test chats, aren't counted.

  • Answered: the agent replied to the customer.
  • Passed on: the conversation was handed to your team.
  • Waiting: it is still running, or a reply is waiting for your approval.
  • Not answered: the agent failed without replying, or the task closed without a reply (for example an email address set to handle emails without answering them).

Time to first reply runs from the customer's first message to the agent's first reply, including any time the reply waited for your approval. Analytics shows the middle value (half the enquiries were answered faster) and the time within which 9 in 10 were answered, for all channels and for each one. The By agent table shows how many of each agent's enquiries were answered or passed on.

Next. Spending limits and alerts for your workspace.

Who can act on tasks

  • Owners, Admins and Builders can see tasks and approve or reject actions.
  • Viewers can see tasks, but can't approve or reject.

The tasks inbox works on a phone, and you can install the app on your home screen.

Last updated 24 September 2026

Something unclear or wrong? Tell us