Permissions and approvals
Working in a project used to mean approving every step. Now it is one simple choice - and whatever you choose, every action the agent takes is written to your records. Approvals are a convenience; accountability is not.
The three levels
| Choice | What happens |
|---|---|
| Ask every time | Your AI asks before every command and file change. The default. |
| Auto | Ordinary work inside the project folder - reading and searching, editing files in the folder, building, testing, routine git - runs without asking. Anything that reaches beyond the folder, can't be undone, or that it isn't sure about still asks, and the card says why. |
| Approve everything | Nothing asks. Every action is still written to your records. |
Settings → Agent sets the default for new projects. The project chip in the header switches one project live - mid-session if you like - and a project's own choice sticks, whatever the default later becomes.
Auto needs a current Your Own AI Build; the app offers the update in the folder menu and in Add-ons › Components.
The same choice for tools in chat
An AI that carries tools uses the same three levels in chat. Set them from the chip beside the model chip: the choice is remembered per AI and applied to the open session at once.
The safety net
Every finished turn that changed files offers Undo this turn's changes - edits put back, created files removed, deleted files restored, with or without git - and writes what was undone into your records. That is what makes Approve everything a reasonable choice rather than a leap. See Projects.
What the record keeps
Automatic allows show as receipts on the working rail - with which rule allowed them - and each turn keeps a compact ledger of everything the agent was allowed to do, written into your records with the turn. Permission answers record the decision, its scope, when and how it was answered; the app's own automatic allow of project-memory reads is recorded too.
The permission card
When something does ask: the exact command in full, never truncated; diffs expandable; touched paths listed. "Don't ask again" is a clear, full-width control and applies only to the action it names, only in this project.