> ## Content Index
> Fetch the complete content index at: https://blog.cloud-station.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Allow a blocked delete from the chat, once or for a while
- URL: https://blog.cloud-station.io/changelog/allow-a-blocked-delete-from-the-chat/
- Published: 2026-09-24T11:00:00.000Z
- Updated: 2026-09-24T17:07:34.000Z
- Description: When an agent’s delete is refused, a card appears in the conversation. Allow that one call, allow deletes for 30 minutes, or keep it blocked. Charlie re-runs the work after you decide.
- Author: Oumnya Benhassou
- Tags: #changelog, #cat-agents, #tr-allow-a-blocked-delete-from-the-chat

Deletes are now blocked by default. Most of the time that is exactly right. Sometimes it is not: you asked an agent to clean up a folder, and the refusal is in the way of the job you gave it.

You no longer have to leave the conversation to sort that out. The moment an agent’s delete is refused, a card appears in the chat. It says which agent tried what, on which connection or key, and gives you three choices.

![A card in the chat saying a delete on Google Drive was blocked, with the buttons Allow this once, Allow for 30 min and Keep blocked](https://blog.cloud-station.io/content/images/2026/09/cl191-card-blocked-three-choices.png)

The card names the agent, the exact command and the connection. Allow this once is the narrowest option.

## What you can do now

- **Allow this once:** exactly the refused call goes through, once, within ten minutes. The same file, the same record. Anything else stays blocked.
- **Allow for 30 minutes:** deletes are allowed on that key or connection for half an hour, then the door closes on its own. Nothing to remember to turn off.
- **Keep blocked:** the job stops there and Charlie tells you so.
- After you allow, Charlie re-runs the refused work with the same agent. You do not have to repeat the request.

![The same card after the owner allowed the call once, marked Allowed](https://blog.cloud-station.io/content/images/2026/09/cl191-card-allowed-once.png)

Once you answer, the card records it. Charlie’s reply below it confirms what happened.

## Why it matters

A safety rule that forces you into Settings every time it fires is a rule people turn off. The card keeps the decision where the work is, at the moment it is needed, with the exact call in front of you.

The narrow option is deliberate. Allowing one call lets the agent finish the job you asked for without handing it a general permission to remove things. Both grants expire on their own, so a temporary yes never turns into a permanent one by forgetfulness.

The answer is enforced everywhere the same way: through saved API keys, through Microsoft 365 and Business Central, and through Google Workspace. An agent cannot find a side door.

## Example workflows

- **Content teams:** an agent replaces a wrong video on the channel. The delete of the old one is blocked; you allow that one call and the swap completes.
- **Operations:** a monthly cleanup of a shared drive needs many deletes. Allow for 30 minutes, let the agent work, and the permission is gone before lunch.
- **Anyone:** an agent tries a delete you never asked for. Keep it blocked, and the card tells you exactly what it attempted.

## What’s next

For agents that will clearly need to delete, we want to ask before they start rather than when they get blocked. That card exists today for saved API keys and is coming to connections.