Shared permissions

Not every permission belongs to the person talking to the agent. Some data belongs to a resource that has its own owner — a company, an account, a record — and another person can't read or share it just because they asked. The owner has to approve. OAP routes that approval to the owner, wherever they are, and only releases the data once they say yes.

Sam asks for Circldot's contacts; the approval routes to Circldot's owner (Jordan), who approves before the data is shared.

Some data has an owner

In the clip, Sam asks the CRM agent for Circldot's contacts to build a QBR deck. But Circldot's contacts aren't Sam's to hand out — Circldot is a resource with an owner, Jordan, the account owner. So the agent doesn't just run the query and return the data. It recognizes the contacts are owned, and pauses to get the owner's approval first.

The request goes to the owner, not whoever asked

This is the part that makes it a shared permission: the approval is routed to the owner of the resource — Jordan — and DMed to them directly. Not to Sam, who asked. Not to whoever happens to own the session. To the person the data actually belongs to.

The approval is DMed to the company's owner — not to whoever asked — with what's being shared, why, and the permission it grants.
The approval is DMed to the company's owner — not to whoever asked — with what's being shared, why, and the permission it grants.

The card tells Jordan exactly what is being asked (share Circldot's contacts), why (Sam's request), and which permission on which resource it grants — enough to decide without leaving Slack.

Only after approval is the data shared

When Jordan approves, the card resolves and the agent finally returns the contacts — to Sam, back in the channel where the request started. The approval didn't just unblock one reply; it granted the session access to Circldot's contacts specifically. A request for a different company's data would be a different owner's call, and would ask again.

Only after the owner approves does the agent return the contacts to the requester.
Only after the owner approves does the agent return the contacts to the requester.

That's a shared permission end to end: data owned by a resource, released only with its owner's approval, routed to the owner rather than the requester — so "who is allowed to see this" is answered by the person who actually owns it.