# Automation that cannot act on its own.

Mission Control is built so the AI can only propose. A person approves every action, the action runs with that person's own access, and the decision is recorded.

## The guarantees

- **Nothing runs without approval** — Every drafted action waits in the reviewer inbox. Rejecting a case means nothing executes.
- **The approver's own tokens** — Approved steps run with the approver's Google and Slack access, so existing permissions keep applying.
- **Per-user connections** — Each person connects and disconnects their own accounts. There is no shared service account.
- **Payment is off** — Mission Control files and reports invoices. It does not pay them.
- **Audit trail on every case** — Who decided, when, the approved payload and each step's result are recorded.
- **The model only drafts** — Codex reads cases and proposes payloads. It has no path to execute anything itself.

## Approval is the only way to execute

Drafting and execution are separate. Codex produces a proposed payload for each step; it is stored on the case and shown to a reviewer. Only an explicit approval from a signed-in person queues those exact payloads for execution. There is no timeout that approves on its own and no setting that skips review.

## Execution uses the approver's access

When a case is approved, each step runs with the approver's own OAuth connection. That has two effects. Actions are attributable — a Slack post shows who approved it. And permissions you already manage in Google Workspace and Slack keep applying: if the approver cannot write to a folder, neither can Mission Control on their behalf.

## Reads use the mailbox owner's access

To draft a case, Codex reads the email and any context it needs through the connections of the person who owns the mailbox. It does not borrow anyone else's access.

## Connections belong to people

Google, Slack and Povio Dashboard connections are created by each user for themselves and can be removed at any time from the Connections page.

## Payment stays disabled

Mission Control does not execute payments. Invoice workflows end at notification, filing and logging.

## Every decision is recorded

Each case keeps its history: the source email, the drafted payloads, who approved or rejected the case and when, and the result returned by every executed step.

[Ask a security question](/contact)
