Approval before risky actions
Send, spend, publish, delete or commit anything important — only after you say yes.
Safety
Your operator can move fast. But it can’t burn the house down. It can read, prepare, draft, and organize. Before it sends, spends, publishes, deletes or commits anything important, it asks.
Reads, drafts, prepares — freely. Sends, spends, publishes — only with your yes.
The boundaries
Send, spend, publish, delete or commit anything important — only after you say yes.
Only the tools the plan actually needs. Permissions are visible and revocable.
Every step has a log. You can read what happened, when, and why.
Plans are written in plain language. No prompts in dialects you can’t read.
One word in chat — "stop", "pause", "wait" — and the operator holds.
Isolated per user. Your operator works in its own space, not on your laptop.
Built to surface what it’s about to do — not to hide work behind autonomy.