> ## Documentation Index
> Fetch the complete documentation index at: https://docs.monk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Approvals and secrets

> Nothing changes without a plan you approve, and your secrets never pass through the chat

Giving a coding agent access to your infrastructure raises two questions: what can it change without asking, and where do your keys go? With Monk, changes wait for a plan you approve in a dashboard on your own computer, and credentials are typed into local forms, never pasted into the conversation.

## What you can do

### Review every change before it happens

Deploys that change what is running, and cluster create, grow and delete, open an approval in the local dashboard at `127.0.0.1:7419`. It shows what will change, warnings and the cost impact. Nothing happens until you approve.

**How:** Ask Monk, then approve in the local dashboard. See [Local dashboard](/getting-started/local-dashboard).

### Confirm destructive actions by name

Approvals for destructive actions, such as deleting a cluster, ask you to type the name of the thing being deleted.

**How:** you approve it in the local dashboard. See [Security](/concepts/security).

### Keep the agent from approving itself

Approvals are created by Monk's tools and answered by a click in your dashboard session. The coding agent can't approve its own request.

**How:** built in. See [Security](/concepts/security).

### Keep secrets out of the chat

Credentials and secrets are entered in forms in the local dashboard. Monk's tools return names and metadata, never values, so the model sees which secrets exist but not what they contain.

**How:** Ask Monk, then fill in the form in the local dashboard. See [Secrets and configuration](/guides/secrets-and-config).

### Store them safely, push them when needed

Local secrets are kept in your operating system's credential store (macOS Keychain, Linux Secret Service, Windows DPAPI), or an encrypted file where there is none. Monk pushes a named secret to the cluster when a deploy needs it, or when you ask.

**How:** Ask Monk. See [Secrets and configuration](/guides/secrets-and-config).

### Control writes to cluster secrets

Adding, pushing or removing a secret at a cluster scope (organization, project, environment or account) needs your approval, and the approval shows where the secret will land.

**How:** Ask Monk, then approve in the local dashboard. See [Security](/concepts/security).

### Enforce permissions in the tools

In an organization, Monk's tools check your role before acting and refuse what it doesn't allow.

**How:** built in. See [Teams and access](/features/teams).

## Try it

```
/monk the api needs a STRIPE_SECRET_KEY
```

## Good to know

* Your coding agent is a separate program with its own permissions. Monk can't limit what it does outside Monk's tools, so review its own approval settings too.
* Monk doesn't edit your application code. Your coding agent writes the configuration, and Monk validates and deploys it.
* If you paste a secret into chat by accident, rotate it.

## Related

<CardGroup cols={2}>
  <Card title="Secrets and configuration" icon="key" href="/guides/secrets-and-config">
    Add and remove secrets
  </Card>

  <Card title="Local dashboard" icon="laptop" href="/getting-started/local-dashboard">
    Where approvals and forms appear
  </Card>

  <Card title="Security" icon="shield" href="/concepts/security">
    What needs approval and how secrets are stored
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.