Risk tiers
Each action has a risk tier: none, low, medium, high or critical. The tier and your autonomy mode decide whether a worker acts, acts and tells you, asks, or is stopped.
The tiersLink to The tiers
- None: reads, for example a status lookup.
- Low: small changes that are easy to undo.
- Medium: actions with the platform's own native tools, and changes to settings.
- High: deletes, actions outside the platform that cannot be undone, merging a pull request, and a push to a main branch.
- Critical: for example a force push, or a merge into a production repository's main branch.
Content from outside, such as a web page or an email, can raise an action by one tier, but not above high.
What each tier does by defaultLink to What each tier does by default
| Tier | Default |
|---|---|
| None, low | Act |
| Medium | Act, then tell |
| High | Ask the operator |
| Critical | Prohibited, unless a policy asks for approval |
The setting is autonomy.tiers. The autonomy mode adds its own cap. See Autonomy modes.
Checked against the product on 2026-10-05.
Was this helpful?
Related articles
- Autonomy modesThe autonomy mode decides how much workers do before they ask you. Auto is the default: internal work runs at once, and outside or risky actions wait for you.
- PoliciesA policy says what workers may do with a tool: allow, notify, require approval or deny. The most specific policy wins.
- ApprovalsActions that need a person wait in Approvals. An approver, admin or owner approves or denies each one, with an optional comment.