Dhanur AI
Docs menu· What your AI can do

What your AI team can do on its own

Live

You decide what each agent does by itself and what waits for you. The levels in plain words, when an agent asks first anyway, what you can always see and what it can't do.

You decide what each agent does on its own and what waits for you. You set it tool by tool on the agent's Build tab, and you can change it any time. The Build tab also sums it up, after the tools, in What it does without asking you.

This page puts it all in one place. The details are in Tasks and approvals and Tools.

The levels, in plain words

  • Runs freely. The agent goes ahead. The task still records what it did and what it cost.
  • Ask first. The action waits in Needs approval until someone on your team approves or rejects it.
  • Ask, then run after N hours. The action waits for you, and goes ahead by itself if nobody decides in time. Auto-approve after, in the agent's Advanced settings, sets the wait: 2 hours unless you change it.
  • Off. Untick the tool, and the agent isn't given it at all.
  • Hands back. The agent stops and passes the task to your team with the Hand over to a person tool, for example for a refund or a question it can't answer. The task shows as Escalated. It also hands back when it reaches its autonomy limit.

You choose the first four for each tool under Tools. Reply to the customer is always on, so for replies you choose only whether they ask first. Say when to hand back in the agent's instructions, such as "hand refunds to the team". When it hands back, you can answer for the agent, and it replies to the customer in its own words.

See Approval settings and Hand-overs and failures.

When it asks first anyway

Some tools start by asking you, and some actions wait for your OK even when their tool is set to Runs freely:

  • Sensitive tools start by asking. Reply to the customer, Send an email and the tools that post for you act outside the app, so they start with an approval step. Tools from MCP servers, and your own tools that change data, start as Ask first too. You can change any of them. See Tools.
  • Deletes in connected apps always ask. An app action that can delete data asks first every time. See Tools that change data.
  • Workspace rules. Owners and Admins can set rules for every agent, such as "sending email always asks first". When a rule and an agent's setting differ, the stricter one wins. See Set rules for every agent.
  • Approval limits. An action with an amount, such as a refund, asks first when the amount is over your limit, whatever its setting. See Approval limits.
  • After it reads something from outside. Once a task reads a web page, a file, an email or a tool's results, actions that reach other people wait for your OK for the rest of the task. Replying to the person the conversation is with isn't affected. See After it reads something from outside.
  • Checks on every outgoing message. A message waits if it has an ID or card number the person didn't send, or a link to a site that isn't yours. See Checks on every message.

The last two are fixed rules, not AI, so they cost nothing. They are on for every workspace. See When your AI asks first on its own.

What you can always see

  • Every task, step by step, with its rupee cost. Open a task to see the conversation, the decisions and who made them, and every step with its model, tokens, time and cost in rupees. See Inside a task and Cost per task.
  • The memory it keeps. With long-term memory on, the agent keeps short notes between conversations. You see every note on the agent's Build tab under Long-term memory, with where it came from and when it was last used. You can add, search, edit and delete notes. A new note from the agent waits for your OK, unless you change the Remember for later tool. See Long-term memory.
  • No training on your data. We don't use your content to train AI models. See Data and privacy.

Long-term memory is off for new agents. To turn it off, untick Remember things between conversations: the agent stops reading and saving notes, and the notes you have stay until you delete them. To delete one note, select Delete note beside it; this can't be undone. Deleting the agent deletes all its notes.

What it can't do

  • Use a tool you haven't given it. An agent can only use the tools and app actions switched on for it. The details it passes to a tool are checked before the tool runs. See Tools.
  • Email just anyone. It can email only a teammate, a lead saved in the conversation, or the person the conversation is with. Any other address is refused. See Checks on every message.
  • Keep going without end. It takes at most the number of steps you set as its autonomy limit on one message, then hands the task to your team. Each task has a spending cap too. See Spending caps.
  • Read ID and card numbers your customers type. Unless you switch it off, Aadhaar, PAN, card and bank account numbers and OTPs are replaced before the AI reads a message. Numbers inside photos and PDFs aren't covered. See What the AI never sees.
  • Read the web without limit. It reads up to 8 web pages and makes up to 5 web searches in one task. See Tools.
  • Send anything from the test chat. In the test chat, replies, emails and changes in connected apps are simulated. See Tools.

Last updated 24 September 2026

Something unclear or wrong? Tell us