An assistant that can act in your apps should never act without asking. But being asked to approve the same harmless action for the tenth time isn't safety — it's friction. Today's release keeps the safety and removes the friction.
gmail · search inboxread-only — ran automatically
gmail · send emailmakes changes — held for approval
Draft ready — send it to the team?Not yetSend
Safe mode: reads run on their own, anything that changes something waits for a tap.
The new "Always allow"
Every time the assistant wants to use a connected app, you still see the approval card showing exactly what it will do. Now that card has three choices instead of two:
Approve — allow this one action.
Reject — don't.
Always allow — trust this tool from now on, so future calls to it skip the card.
Still safe by default
"Always allow" is opt-in and per-tool. You decide which routine, low-risk tools earn it; everything else keeps asking. Risky actions — sending, deleting, posting — stay behind an explicit approval unless you've deliberately waved a specific tool through.
Always reversible
Changed your mind? Every always-allowed tool is listed in Settings, and you can revoke any of them with one click — the card comes straight back the next time that tool runs.
The goal is the same as it's always been: you hold the final click on anything that matters, and stop clicking on the things that don't.
Try it yourself
Every model, one memory, and agents that work the way you do.