> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackshift.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Connection access and approvals

> Understand selected resources, permitted actions, owner decisions and revocation.

<Tip>
  **Live.** This area is documented as current, user-reliable behavior.
</Tip>

## Goal

Grant the access a client needs while keeping approvals and actual execution distinct.

## Prerequisites

* Access to the resources being selected.
* An enabled agent-connections backend and compatible dashboard.

## Workflow

<Steps>
  <Step>
    Review the client request and return destination.
  </Step>

  <Step>
    Choose explicit resources, keeping child inclusion separate.
  </Step>

  <Step>
    Review required reads and select only the optional actions needed for the task.
  </Step>

  <Step>
    Keep manual approval or choose an available existing policy, then choose expiry.
  </Step>

  <Step>
    Authorize or deny the request. Inspect actual operations for execution results.
  </Step>
</Steps>

## Resources and actions are separate choices

Required reads appear separately from optional actions. Selecting a resource does not select every action, and selecting an action does not grant access to unrelated resources.

Including accessible children authorizes only the eligible children retained in that grant. It does not automatically authorize future children. Each child is independently checked; a moved resource, lost membership or revoked access can invalidate later work.

Create one Application is a bounded creation permission. It is reserved and bound to the resulting Application and authorized new resources; it is not account-wide permission to create arbitrary Applications.

## Manual approval and existing policies

Manual approval is the default. An available standing policy can authorize actions within its effective rules and the connection grant. A client cannot approve its own request, edit the policy or expand its grant.

A human approval is bound to the retained action and affected resource versions. Changed targets require a fresh valid proposal. Historical authorization reflects the human decision or automatic rule recorded at the time, not a policy inferred from current settings.

Approval means permission to proceed, not deployment success. Inspect the controller operation for the workload outcome. Waiting approval, queued execution, build success and deployment failure remain separate states.

## Expiry and revocation

Connections expire and can be revoked earlier by their owner. Revocation removes the connection credential and authority for pending work. It does not delete resources or claim that a controller operation already dispatched has stopped.

Permissions are checked when work arrives and again before queued execution. Expired or revoked grants, lost access and changed targets cannot be repaired by retrying an old approval.

Use the existing resource controls to inspect or cancel running work where supported. Resource reads remain subject to resource authorization and do not require native AI credits.

## Safe operational evidence

Connection activity exposes operational facts and permitted links. It does not grant access to private conversations, other users’ tasks, prompts, secrets or billing details.

A client name is claimed identity unless separately verified. Review the registered callback and last observed use when checking a connection.

## Expected result

<Check>
  The connection is limited to its authorized resources and actions, subject to current resource permissions and recorded approval requirements.
</Check>

## Related guides

<CardGroup cols={2}>
  <Card title="Connect your coding agent" href="/ai-features/agent-connections">
    Connect an external client, choose its access and inspect its work in StackShift.
  </Card>

  <Card title="Live workload workspace" href="/operations/live-workload-workspace">
    Follow a deployment, release or database operation alongside its activity and approval decisions.
  </Card>

  <Card title="Resource activity" href="/operations/resource-activity">
    Follow builds, deployments, releases and database operations from the resource you are working on.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.