# Accounts and approvals

Know which sign-in or permission a task is asking for before you continue.

SpringBrand CLI installation normally uses an installation key. The client-specific guide explains when browser OAuth is available. A later task can ask for separate access to an external service or approval before an action. Read each request in the context of the task you chose.

## Three separate moments

| Moment | What to check |
| --- | --- |
| SpringBrand sign-in | Confirm you are completing the browser sign-in initiated by your Agent installation. Return to a fresh Agent session afterward. |
| External service access | Check the service, account, requested scope, and why the selected operation needs it. |
| Approval for an action | Check the proposed recipient, content, destination, cost, or change before approving. |

## Before authorizing

- Ask which operation requested access and what it will do with it.
- Confirm the request matches your intended task and account.
- For publication, outreach, payment, or other external effects, review the proposed action before it runs.

> Review the scope and approval shown for the operation you choose. Each task can request different access.

- [Installation](/developers/docs/installation): Choose your Agent and complete SpringBrand sign-in.
- [Troubleshooting](/developers/docs/troubleshooting): Find a failed authorization step.
