Skip to content

How approvals protect you

An agent can run commands and edit files on your computer. Approvals are the check between what it wants and what it does.

In Regular mode the agent stops before an action that needs approval and waits. The card shows the exact command or file. Nothing runs until you choose Approve.

Risky actions carry a label: Destructive command, Network access, Writes outside workspace, Secret file, Package install, Git push or Publish. Read those first.

  • Approve covers one action.
  • Approve similar covers the same kind of action in one workspace, and the card shows the rule it adds.
  • Approve all similar covers one tool for the rest of the session.

Start with the narrowest one. Wide approvals are convenient, and they approve actions you have not seen yet. Clear standing approvals in the session menu removes every remembered rule.

Each approval is checked on your computer. A phone paired as Viewer cannot answer one. A phone paired as Approver, Driver or Admin can. Pair each phone with the smallest role it needs.

The computer refuses to show or send files that hold credentials, such as the settings folders of your agent programs, ~/.remotxai, the GitHub CLI settings, keychains and browser profiles. An approval does not change that.

Yolo mode approves everything without asking. No one reads what the agent does. What Yolo means.

Panic stop interrupts every session on a computer, cancels the sub-agents and switches off Yolo and remembered approvals. Press and hold it for 1.5 seconds.

A new phone only connects after you type its verification code at the computer. A phone you did not pair cannot send an approval.

Last updated: