Permissions & Limits

What bounds what Ava can do — agent permissions, what's in them, where Auto runs, and how to see and change them.

Permissions & Limits#

Ava can act in two ways, and each has its own boundary:

  • Manual — Ava prepares a transaction and you sign it in your own wallet. The boundary is your signature: nothing moves unless you sign.
  • Auto (optional) — Ava acts on its own, but only inside an agent permission you sign: which apps, how much, and until when. Your wallet enforces it on-chain.

The rest of this page is about Auto, because that's where Ava acts without a signature each time.

What an agent permission contains#

  • What it covers. One or more capabilities: Send tokens, Trade on Uniswap V3, Aave V3, or Claim. Each lists the contracts it allows, with addresses you can check on a block explorer.
  • A total spending limit per token. For example, up to 500 USDC. It's a running total over the permission's life — it doesn't refill.
  • An expiry. Every permission has one: 1 day, 7 days, 30 days (the default), or a date you pick.
  • A network. Each permission is for one chain.

These limits are enforced on-chain by your wallet itself. A call to a contract the permission doesn't cover, spending past the limit, or any use after expiry is refused by the chain, not just by Ava.

Signing a permission is a signature, not a transaction, so it costs no gas. Ava can't create or widen a permission itself — only your signature can — and a permission never gives Ava full control of your wallet.

Everything Auto does runs under a permission#

That includes one-off actions you ask for in chat (you still tap Confirm) and standing jobs that run on a schedule without asking each time:

  • Health-factor protection — checks your Aave position every hour and repays debt or adds collateral when it gets risky.
  • Weekly pay and weekly swap — recurring transfers or purchases.
  • Token claims — claims tokens you're owed from the verified contract when they unlock.

Revoke the permission and every job and action that used it stops.

Be precise about what a permission covers#

A permission is scoped to an app, not to individual functions:

  • The Aave V3 permission covers supply, withdraw, borrow, repay and collateral settings on the Aave V3 pool. Ava doesn't borrow or withdraw unless you ask it to, but that's how Ava behaves — the permission itself doesn't block those functions.
  • The Send tokens permission isn't tied to a recipient on-chain. The recipient is set in the job or request you confirm; the permission only limits how much can be sent.

The permission bounds what Ava can do: its apps, its spending limits, and its expiry. Spending limits cap what Ava is authorized to spend. They don't cap losses on your DeFi positions. A permission that covers Aave V3 can, for example, borrow or withdraw on your position, and positions carry market risk of their own.

Where Auto runs#

  • Your own wallet. A one-time upgrade (EIP-7702) lets your existing wallet — same address, same keys — hold agent permissions. The upgrade is an authorization you sign, not a transfer; your funds don't move.
  • A separate Ava smart wallet, if your wallet can't sign the upgrade or you want a hard ceiling. You fund it with only what Ava may use, and withdraw anytime. It holds agent permissions the same way.

Seeing your permissions#

In Ava Studio, open Wallets, pick the wallet, and choose Edit permissions. The Agent permissions window shows, for each capability:

  • A plain-English summary — "Ava is authorized to … on Base".
  • The allowed contracts, each linked to a block explorer.
  • The total spending limit per token.
  • The expiry date.
  • Enable or Disable, per network.

Changing a permission#

Each change is a new signature from your wallet. You get one usable permission per capability on each wallet and network, and Studio combines the capabilities you enable into one shared permission. Raising a limit, adding a capability or extending the expiry all mean signing again.

Stopping Ava#

  • One job: pause it on the Running page.
  • A permission: disable it on Wallets — every job and action that used it stops.
  • Everything on your wallet: undo the upgrade. One transaction turns it back into a plain wallet, and Auto can no longer run on it on that network. It doesn't erase the permissions stored on your wallet, so if you might upgrade again, disable them and finish their on-chain removal first.

See Revoking Access for the step-by-step.