Documentation v1.1.1

Permissions and Confirmations

·

The two permission modes, which entry point uses which, and how confirmation prompts are routed.

Permission mode

Mode Behavior
single-confirm Each non-ReadOnly tool call requires user confirmation (the TUI default)
always-allow Tools auto-execute; the LLM is instructed to invoke ask_user first for seven categories of truly irreversible operations

The seven irreversible categories that still require explicit ask_user under always-allow:

  1. Filesystem — rm -rf / rm -r, deleting directories or existing files not produced by this task
  2. Database — DROP DATABASE / DROP TABLE / TRUNCATE, DELETE / UPDATE without WHERE, any production DSN
  3. Git — reset --hard, push --force to main/master, deleting shared branches, clean -fdx
  4. System — chmod 777 / chown -R, edits under /etc / /usr / /System, launchctl / systemd changes, sudo escalation
  5. Overwrite — an unread non-empty existing file, .env / credentials / lock files / .git/index
  6. Cloud & infra — gcloud / aws / kubectl delete, terraform destroy
  7. Process — shutdown / reboot, kill -9 on system service PIDs

Ordinary writes (edit_file, build and test commands, git status / add / commit, read-only shell) proceed directly. The gate is enforced by the system prompt (configs/prompts/system_prompt/permission/always_allow.md), not by hardcoded Go-side filters.

Mode by entry point

The active permission mode (single-confirm vs always-allow) is decided by entry point:

Entry Mode
TUI single-confirm, toggled per session with Shift+Tab
POST /v1/send single-confirm; confirms are answered through the web dashboard. The allow_all request field was removed
POST /v1/chat/completions always-allow
Telegram single-confirm (confirm gate uses a Telegram inline-keyboard select)
Discord single-confirm (confirm gate uses a Discord select menu)
Resumed pending task Keeps the mode stored with the task
Subagent Inherits parent ctx

The mode is rendered into the system prompt under ## Permission Mode. Commands on the read-only list skip the gate in every mode.

Tool mode gating

A tool that carries a mode is gated by it: list / read / search are treated as read-only and skip confirmation, while remove / restore always confirm even on an otherwise auto-approved tool.

Origin-routed confirmations

Every interactive request carries an origin prefix — cli-, chat-, tg-, or dc-. CLI confirmations are consumed only by the TUI, web requests by the web confirmation stream, and Telegram or Discord requests by their matching channel listeners. A confirmation from a channel other than the TUI that is left unanswered for five minutes is skipped and the task is kept as pending (since v1.1.1 TUI confirmations wait without a time limit), so one channel can neither intercept nor indefinitely hold another channel's prompt.

中文