Introduction
When Sana is about to do something in an external system, like updating a record in Workday, creating a file in Google Drive, or sending a message via Slack — it will pause and ask for your go-ahead first. Nothing happens until you say so.
This is called human-in-the-loop approval. You stay in control, and Sana stays trustworthy.
How it works
Sana pauses before acting. Instead of taking an action immediately, Sana shows you exactly what it's about to do (the system, the action, and any relevant details) and waits for your response.
You approve or reject. You can review what Sana is proposing and either approve it (Sana goes ahead) or reject it (Sana stops and nothing changes in the external system).
If you step away, you can always come back to the chat. If you close the chat or Sana is working in the background, the approval request doesn't disappear. You can always come back to it from your chat history and action it whenever you’re ready.
Supported systems
Workday: actions taken by the Workday Self-Service agent, e.g. requesting time off or modifying personal information; this is made possible by the Sana agent handing over the task to the Self-Service Agent
Third-party connectors: e.g., sending an email through Outlook, creating a ticket in Linear, generating a spreadsheet in Google Drive
Custom MCP connectors: When Sana connects to a remote MCP server, it uses the server’s tool metadata to decide if something is a write tool and should trigger a human‑in‑the‑loop artifact. However, metadata quality varies from MCP servers and this is not something Sana controls, so some write tools may be misclassified as read tools and therefore not require approval.
