Control scopes and approval
Choose the app’s control scope before sending commands. These scopes are enforced by the server and are separate from the API key used to ingest telemetry.
Choose a control scope
| Scope | Allowed commands |
|---|---|
| monitor | Telemetry only; no command dispatch. |
| control | pause, resume, stop, restart, update_model, verify, ping. |
| full | All command types, including update_prompt. Prompt approval still applies. |
A prompt update enters pending_approval. An owner or admin can inspect the proposed difference and approve or deny it. Approval rechecks the relevant control policy. Inspect command status for delivery errors; a sent command is not the same as a confirmed change.
Start in monitor scope, confirm heartbeats, then enable only the control your app needs. The SDK’s ACP_DISABLE_CONTROL=1 setting can disable receiving control locally.