Control scopes and approval

Choose the app’s control scope before sending commands. These scopes are enforced by the server and are separate from the API key used to ingest telemetry.

Choose a control scope

Scope Allowed commands
monitor Telemetry only; no command dispatch.
control pause, resume, stop, restart, update_model, verify, ping.
full All command types, including update_prompt. Prompt approval still applies.

A prompt update enters pending_approval. An owner or admin can inspect the proposed difference and approve or deny it. Approval rechecks the relevant control policy. Inspect command status for delivery errors; a sent command is not the same as a confirmed change.

Start in monitor scope, confirm heartbeats, then enable only the control your app needs. The SDK’s ACP_DISABLE_CONTROL=1 setting can disable receiving control locally.