Sometimes the right move is to put your hands on the environment: a login the Worker cannot complete, a flow that has gone somewhere unexpected, or simply wanting to see what it sees. A control lease does that, for a bounded time.
A control lease is taken on a live run, and as of 2026-09-10 a run does not complete end to end (Overview). The route answers; there is nothing to attend yet.

Take the lease

200
duration_seconds is between 30 and 3600 and defaults to 300. purpose is takeover, assisted_login or inspection.

Why it is time-boxed, and why it needs the higher grant

A control lease is how a user-assisted login happens, so it is the one place a person is at a keyboard inside an environment that may hold a session profile. An open-ended lease would be an unattended authenticated environment with extra steps — so the lease expires, by construction. It is gated on CHANGE_APPLY rather than the propose grant. Check before you offer it:
A surface that renders a Take control button someone cannot use is the dashboard equivalent of listing a tool a key cannot call.

What the lease is not

It is not a widening of what the Worker may do. It is the opposite: the lease is also the only place a high-impact arbitrary UI action may happen at all, and that restriction stands in every execution mode. autonomous asks for fewer approvals and enforces every limit; it does not turn an unattended agent into one that may click anything consequential. That is a semantic boundary — Obol cannot express the application-level meaning of an arbitrary click to a policy engine — rather than a preference somebody may flip. The response carries the lease, its holder and its expiry. It never carries a handle to the environment itself; the run view’s control_lease field reports who is attending and never the handle.

After the takeover

Whatever you did by hand is your action, recorded as an attended interval. It does not become part of the Worker’s typed record of what it did, and it does not raise what the run’s evidence is worth: an observation made while a person was driving is still an observation of a screen. If the run was paused while you worked, resume it — and note that resuming re-allocates, so concurrency is checked again and can refuse:
A resume also re-reads current policy before the next attempt runs. A permission revoked while the run waited is not still granted.