Approvals
Review target writes, migration loads, rollback and sensitive-value reversal.
DataMaker uses approvals for specific operations that need a human decision. Read the tool, target and volume in the request before granting it. A plan approval and a target-write approval serve different purposes.
What can request approval
| Operation | Review |
|---|---|
| Standard data load | Target endpoint or connection and intended rows. |
| Migration-scale load | Larger scope and target; requires a different grant from a standard load. |
| Load rollback | Prior run, target records and the configured delete or compensating reversal request. |
| Agent unmasking | The specific token map and why originals are needed. |
| MCP write above the volume threshold | Tool, target and supplied rows. |
Grants are target-bound and consumed once. A denied or consumed request cannot be reused as permission for a new operation. Retrying may produce a new approval request.
Scenario environment confirmation
When the agent asks you to confirm scenario environment variables, check the actual values and destination before continuing. Changed values require a new confirmation. Do not approve a generic description if the environment selects a production target or changes credentials.
What approval does not prove
An approval is authorization for the stated operation, not proof that its data is correct or that every possible downstream action is separately gated. Not every write has a measurable row count, and arbitrary scenario code can perform its own network operations. Review scripts and target credentials as well as approval prompts.
For data preparation, first inspect a sample, then approve the intended load. Afterward, check the job result and reconciliation evidence.