How Approvals Work
Understand normal, sensitive, destructive, cross-layer, and human-gated Noxgild actions.
Noxgild does not treat every requested action as equivalent.
Normal actions
Read-only and ordinary write capabilities can run when the target computer, worker, scope, schema, and policy checks succeed.
Sensitive actions
Trusted sensitive capabilities may run when the account, device, capability, scope, schema, and policy checks succeed. Noxgild does not add a separate approval round-trip merely because a capability is classified as sensitive.
If a sensitive request crosses an untrusted browser or remote-content boundary into Machine or Desktop control, the untrusted-boundary rule applies and an exact command approval is required.
Destructive actions
Destructive capabilities are queued and are not dispatched until the exact command is approved.
Examples include deleting files, terminating an unmanaged process, or invoking a consequential OS-level shortcut.
Exact command scope
Approval is scoped to THIS_COMMAND. It does not grant standing permission for future commands.
The command record includes the selected computer, capability, arguments, and unique command ID so the user can review what will actually execute.
Browser-to-computer boundary
Browser and remote content are treated as untrusted. If untrusted content attempts to pivot into Machine or Desktop control, Noxgild requires an exact per-command approval even when the underlying action would otherwise be read-only.
Human gates
A protected security challenge is different from an approvable Noxgild command. CAPTCHA, OTP, passkeys, secure-desktop prompts, and similar challenges return a human-action requirement and cannot be programmatically approved through Noxgild.
