LuumenAI can propose commands. It cannot run them. Every command that would run on a host is shown to you first and waits for your decision, so nothing reaches your infrastructure without a person choosing to let it.
Each decision is tied to the person who made it, and on Enterprise both the command and the approval are recorded. When someone asks what ran, who allowed it, and why, the audit log answers all three.
Approving a Command
When LuumenAI wants to act, the conversation shows the exact command it intends to run, a plain-language explanation of what the command does, and the host it is aimed at. Below that it asks whether to run it.
You have three answer choices:
Yes. The command runs in your session, as you, and its output comes back into the conversation for LuumenAI to read.
No. The command does not run. The conversation records that you declined, and Co-Pilot may propose a different approach to the same goal.
No, tell me what to do differently. This declines and hands the conversation back to you so you can redirect it. Use it when the goal is right but the approach is wrong, because it keeps everything worked out so far instead of starting over.
Some proposals may show only Yes and No, tell me what to do differently. Either way, the command runs only on Yes.
Why Commands Cannot Be Pre-Approved
Luumen has no way to pre-approve a command, remember a decision, or auto-approve a category of host command. Every command is its own decision, every time, including every step of a Skill.
That is more clicking. It is also what keeps an assistant with shell access safe on production systems, and it is what gives the Enterprise audit log its meaning: every recorded action has a recorded human decision beside it.
Actions in connected tools work differently: your administrator sets which integration actions run automatically, which require approval, and which are not available. See Integrations tool permissions.
Before You Approve
Confirm the target host, especially when a conversation has more than one connected, and read the full command before approving anything that removes files, restarts a service, or changes configuration.
Destructive actions are highlighted in the approval prompt. The highlight flags risk; it is not a measure of severity.
Pending Approvals
Approvals do not expire while you are away. When you return and answer, Luumen refreshes its authorization and submits your decision; you do not need to restart the conversation. If the decision can no longer be applied, for example because the host disconnected, Luumen says so in the conversation.
Commands That Need a Live Terminal
Commands that need a live terminal, such as an editor or a program that prompts for input, are not suitable for LuumenAI to run, and it will say so. You can run those yourself in the terminal alongside the conversation.
Declining a Command
Declining stops that command only. LuumenAI may propose a different approach to the same goal. To stop the task entirely, tell it to stop or close the conversation.

