The AI assistant

The safety switch

Read mode, Execute mode, approval cards and auto-approve — how the assistant is stopped from breaking things.

The question everybody asks first is "will it break my website?" This page is the answer.

Under the message box there is a switch with two positions — Read and Execute — and a toggle called Auto-approve. Together they decide what the assistant is allowed to do.

New chats always start in Read.

Read mode

The assistant can look. It cannot change anything.

It can read logs, check whether services are running, list files, describe your cloud resources and run SELECT queries. If it tries to do anything that would change something, the panel refuses — and you see a card saying "Needs Execute mode" with a button to switch.

This is not an instruction to the AI that it might ignore. It is a block in our code, in front of the command, that the model cannot talk its way past.

Read mode is where you should do all your investigating. "What's wrong with my site?" never needs more than Read.

Execute mode

Each change stops and asks you first.

You get a card showing:

  • the exact command it wants to run,
  • which server or resource it will run against,
  • a one-line reason why.

Two buttons: Yes, run it and No.

  • Nothing happens until you press Yes.
  • No answer within 10 minutes counts as No.
  • Closing the chat cancels anything waiting.

Every decision is recorded — approved (and by whom), declined, auto-approved or blocked — in the chat and on the server's Activity log.

Auto-approve

Available only in Execute mode. Changes run without asking each time.

Use it when you have already decided to let it get on with a job — a long install, a cleanup with many steps — and you do not want to press Yes fourteen times.

Destructive commands always ask, even with auto-approve on. The list:

  • rm -r (recursive delete)
  • reboot and shutdown
  • mkfs and dd (wiping or overwriting a disk)
  • DROP and TRUNCATE in a database
  • DELETE or UPDATE with no WHERE clause
  • terminating or deleting cloud resources
  • Docker prune and volume removal
  • git reset --hard and push --force
  • iptables -F (flushing firewall rules)
  • crontab -r (deleting all scheduled jobs)
  • deleting users

What the gate covers

Everything: server commands, the Terminal AI helper, AWS, Google Cloud, Jenkins, Grafana, Jira edits and MCP tools.

Anything we cannot classify counts as a change and needs approval. The default is always the cautious one.

Where the gate is weaker — be honest with yourself

Read mode is strong protection, not a sandbox. Two things it cannot promise:

  1. We decide "read or change" from the text of the command. Something that looks read-only but has side effects would still run in Read mode: a URL fetch that triggers an action, a SELECT that calls a function which writes, a script with an innocent name.

  2. On AWS, "get" commands count as reads. That means in Read mode the assistant can still run commands like secretsmanager get-secret-value or ssm get-parameter --with-decryption, and the result goes into the chat history. It cannot read your stored DevOps Agent credentials — but it can read secrets your AWS key is allowed to read. If that matters to you, give the project a more limited AWS key.

MCP servers tell us which of their tools are read-only, and we trust that label. Only connect MCP servers you trust.

Waiting approvals do not survive a restart

Approval cards live in the app's memory. If DevOps Agent is updated while a card is waiting, the card is cancelled and nothing runs. That is the safe failure, but it means a card left open overnight may simply disappear.

Roles

Viewers cannot use Execute mode at all, cannot answer approval cards, and are refused commands that read secrets. Operators and above have the full switch. See Roles.

How to work with it

  1. Investigate in Read. Let it find the problem and explain it.
  2. Read the plan. Ask "what would you change?" before switching.
  3. Switch to Execute and approve one step at a time.
  4. Turn on auto-approve only once you are happy with the direction — and remember the destructive list still stops.
  5. Check the Activity log afterwards.