The AI assistant
The safety switch
Read mode, Execute mode, approval cards and auto-approve — how the assistant is stopped from breaking things.
The question everybody asks first is "will it break my website?" This page is the answer.
Under the message box there is a switch with two positions — Read and Execute — and a toggle called Auto-approve. Together they decide what the assistant is allowed to do.
New chats always start in Read.
Read mode
The assistant can look. It cannot change anything.
It can read logs, check whether services are running, list files, describe your
cloud resources and run SELECT queries. If it tries to do anything that would
change something, the panel refuses — and you see a card saying "Needs
Execute mode" with a button to switch.
This is not an instruction to the AI that it might ignore. It is a block in our code, in front of the command, that the model cannot talk its way past.
Read mode is where you should do all your investigating. "What's wrong with my site?" never needs more than Read.
Execute mode
Each change stops and asks you first.
You get a card showing:
- the exact command it wants to run,
- which server or resource it will run against,
- a one-line reason why.
Two buttons: Yes, run it and No.
- Nothing happens until you press Yes.
- No answer within 10 minutes counts as No.
- Closing the chat cancels anything waiting.
Every decision is recorded — approved (and by whom), declined, auto-approved or blocked — in the chat and on the server's Activity log.
Auto-approve
Available only in Execute mode. Changes run without asking each time.
Use it when you have already decided to let it get on with a job — a long install, a cleanup with many steps — and you do not want to press Yes fourteen times.
Destructive commands always ask, even with auto-approve on. The list:
rm -r(recursive delete)- reboot and shutdown
mkfsanddd(wiping or overwriting a disk)DROPandTRUNCATEin a databaseDELETEorUPDATEwith noWHEREclause- terminating or deleting cloud resources
- Docker
pruneand volume removal git reset --hardandpush --forceiptables -F(flushing firewall rules)crontab -r(deleting all scheduled jobs)- deleting users
What the gate covers
Everything: server commands, the Terminal AI helper, AWS, Google Cloud, Jenkins, Grafana, Jira edits and MCP tools.
Anything we cannot classify counts as a change and needs approval. The default is always the cautious one.
Where the gate is weaker — be honest with yourself
Read mode is strong protection, not a sandbox. Two things it cannot promise:
-
We decide "read or change" from the text of the command. Something that looks read-only but has side effects would still run in Read mode: a URL fetch that triggers an action, a
SELECTthat calls a function which writes, a script with an innocent name. -
On AWS, "get" commands count as reads. That means in Read mode the assistant can still run commands like
secretsmanager get-secret-valueorssm get-parameter --with-decryption, and the result goes into the chat history. It cannot read your stored DevOps Agent credentials — but it can read secrets your AWS key is allowed to read. If that matters to you, give the project a more limited AWS key.
MCP servers tell us which of their tools are read-only, and we trust that label. Only connect MCP servers you trust.
Waiting approvals do not survive a restart
Approval cards live in the app's memory. If DevOps Agent is updated while a card is waiting, the card is cancelled and nothing runs. That is the safe failure, but it means a card left open overnight may simply disappear.
Roles
Viewers cannot use Execute mode at all, cannot answer approval cards, and are refused commands that read secrets. Operators and above have the full switch. See Roles.
How to work with it
- Investigate in Read. Let it find the problem and explain it.
- Read the plan. Ask "what would you change?" before switching.
- Switch to Execute and approve one step at a time.
- Turn on auto-approve only once you are happy with the direction — and remember the destructive list still stops.
- Check the Activity log afterwards.
