Configure approval notifications.
Purpose
Alert authorized staff when an AI-proposed action is waiting for review. Notifications do not approve, execute, or verify the action.
Audience and access
For: Gym owners, site administrators, and the staff owner for Slack or Twilio<br>
Access needed: WordPress manage_options; access to the private Slack channel/app or the GymCore Twilio configuration<br>
Open: GymCore Admin > AI > Settings > General
Before you start
- Choose a private staff-only Slack channel and/or current on-call phone numbers.
- Review who can read channel history, exports, guest access, notification previews, and managed mobile devices.
- Review Twilio readiness under GymCore Admin > Communications & Automations > Channels & providers. A site administrator can save Twilio credentials and send one explicit test SMS to that administrator’s staff-owned billing phone. This does not validate AI notification delivery.
- Use staging and fictional action data for notification validation. The settings screen has no notification test button.
Exact visible steps
-
Open GymCore Admin > AI > Settings > General and find Notify on pending action.
Expected: The checkbox is on by default. The in-admin pending notice is separate and remains visible to administrators even when external notification delivery is off.
-
To use Slack, paste the restricted incoming-webhook URL into Slack incoming webhook URL.
Expected: Only an HTTPS
hooks.slack.comURL can be saved. Leave the field blank to disable Slack. -
To use SMS, enter one authorized E.164 number per line under SMS admin numbers (one per line).
Expected: Formatting is reduced to digits and a leading
+. A blank list disables SMS delivery. -
Leave Include action summary in Slack off unless the channel is approved for member-related content.
Expected: Slack receives routing metadata without the optional description. SMS is always metadata-only and does not include the action description.
-
Select Save Changes.
Expected: The General tab reloads with the saved checkbox, masked or stored URL value, recipient list, and standard WordPress settings confirmation.
-
On staging, create one fictional proposal through the supported AI flow and leave it Pending.
Expected: The admin notice appears. Configured external channels receive one approval alert; no action is approved or executed. If the current Staff Dashboard chat integration is unavailable, there is no customer-facing test control—record the configuration as saved but not delivery-validated.
-
Open the Slack message or SMS, then follow its admin link or open GymCore Admin > AI > Audit Log and filter for Pending.
Expected: The notification’s action ID, agent, and action type match the pending audit row. The source record remains unchanged until a separate approval succeeds.
-
Remove fictional external messages according to the Slack, Twilio, carrier, and device policies.
Expected: The local pending row and audit history remain; deleting an external message or expiring conversation history does not purge action history.
Expected result
Authorized recipients receive a minimal alert for a new pending action, the linked action ID exists in the local Audit Log, and no notification is mistaken for approval, completion, or source-record verification.
Defaults and limits
| Control or behavior | Current source behavior |
|---|---|
| Notify on pending action | On by default; gates Slack and SMS dispatch |
| In-admin pending notice | Always shown to administrators when pending actions exist |
| Slack URL | Blank by default; HTTPS hooks.slack.com only |
| Include action summary in Slack | Off by default |
| SMS recipients | Blank by default; one E.164 number per line |
| Slack rate limit | At most 10 posts in 5 minutes; later alerts are skipped and logged |
| SMS rate limit | One message per recipient per minute; sends are asynchronous |
| Built-in test control | None |
Side effects and privacy
Slack, Twilio, carriers, and recipient devices keep copies under their own retention and access policies. A Slack summary can include a trimmed action description containing names, phone fragments, or refund reasons. The SMS body carries only action ID, agent, and action type, but those values still reveal operational activity. Conversation retention does not delete any notification already sent or the local action/audit row.
Recover by symptom
Slack does not receive an alert
Confirm Notify on pending action is on, the saved URL is an HTTPS hooks.slack.com URL, the Slack app still belongs to the intended channel, and fewer than 10 alerts were attempted in the last 5 minutes. Check the WooCommerce or PHP log source gym-core-ai; delivery failures do not block action creation.
SMS does not receive an alert
Confirm the recipient is saved in E.164 format, GymCore Twilio credentials are current, WordPress cron or Action Scheduler is running, and no message was sent to that number in the last minute. Check Twilio delivery status; the local queue does not prove carrier delivery.
An alert contains too much personal data
Turn off Include action summary in Slack, select Save Changes, remove the exposed message where possible, review channel access, and rotate the Slack webhook if it was exposed. The already-sent copy remains subject to Slack exports and retention.
Saved settings exist but delivery cannot be tested
Do not claim notification validation. Record the exact saved values without secrets, the unavailable pending-action creation path, and the installed versions. Test after the Staff Dashboard chat integration is corrected.
Related guides
- Review and decide an AI-proposed action
- Protect AI data and connections
- Manage credentials and webhooks
- Troubleshoot email and SMS
Source review: checked-out gym-core-ai and gym-core PHP/JavaScript on 2026-07-13. Notification delivery is not described as tested unless an installed staging flow produces the pending action and provider result.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.