Control and review
Approve sensitive agent tools from your phone
Sensitive tool requests are where remote supervision earns its keep. FireCursor presents the request in the active run so you can decide based on scope and evidence instead of leaving an agent blocked or granting blanket access.

Quick answer
The shortest useful version.
Read the tool, arguments, project, and reason. Prefer allow once for a clearly expected action, reject anything outside the task, and reserve persistent choices for narrowly understood tools.
Step by step
Do this with confidence.
- 01
Identify the request
Confirm which provider, project, session, tool, and arguments are asking for permission.
- 02
Compare it with the task
The action should be necessary for the stated outcome and stay inside the files, services, and people already in scope.
- 03
Choose the narrow response
Allow once is the safest positive default. Reject or reject always when the request is unexpected or categorically inappropriate.
- 04
Inspect what happened next
Approval is not the end of review. Watch the resulting output and verify the final diff or artifact.
Four decisions, four meanings
- Allow once: permit this specific request
- Allow always: persist permission for the understood tool scope
- Reject: deny this request and let the run recover
- Reject always: persist a denial for the understood tool scope
Pause when context is incomplete
A familiar command can still be dangerous with unfamiliar arguments. If the mobile surface does not provide enough context, reject the request and ask the agent to explain the exact operation, impact, and recovery path.
Never approve a destructive filesystem, deployment, billing, or external-message action merely to keep a run moving.