Skip to main content

Approvals & safety

Celeris never hands the model a bare shell. It offers a set of tools, and it checks every call before running it. Reads run on their own, writes ask, and anything that cannot be undone or leaves your machine asks every time. A step Celeris does not recognise asks too rather than guessing it is safe, and you can stop a running task at any time from the chat window.

Reads run, writes ask​

What the call doesExamplesWhat happens
Reads somethingReading a file, listing a folder, commands like ls, cat, git status, grep, and a few approved reads that query a service you are already signed in to, such as gh pr viewRuns without asking
Changes somethingWriting a file, sending a message, anything that changes stateAsks: Run, Deny, or Always allow
Cannot be undone, or sends data off your machineDeleting files, force pushes, sudo, permission changes, output redirection, network fetches, package installs, killing processesAsks every time, even with auto-run on, unless you turn on the explicitly labelled dangerous bypass setting

Celeris judges commands one at a time, not by the tool that carries them. ls reads and rm -rf deletes, even though both arrive through the same "run a command" tool.

It judges a command's options too. find, fd and tree list files, but find -delete deletes, find -exec and fd -x run another program, and tree -o writes a file, so those forms ask like any other change. A listing that would print more than names asks too: ps e shows other programs' environment, wc --files0-from= prints the file it reads, git remote show origin contacts the remote, and gh pr view --web opens a browser. For commands like these, an option Celeris does not recognise asks as well, and so does a setting in front of the command that can load other code, such as LD_PRELOAD=.

Approving​

When a call needs approval, the chat window shows what will run: the command, the working folder, the tool and its arguments. You have three choices.

  • Run allows this call once.
  • Deny refuses it. Celeris carries on with the rest of the task and tells you what it could not do.
  • Always allow adds that shape of call to your allowlist, so it runs without asking from then on.

Approving as you go means the set of things Celeris can do without interrupting you grows through use, rather than by turning safety off before you start. Edit your allowlist in Settings → Safety. A call that cannot be undone or leaves your machine cannot be added to it.

Auto-run​

Auto-run lets calls that change something proceed without asking. It never covers a call that cannot be undone or leaves your machine. Turn it on only for work you would have approved anyway.

Choices that last one session​

The Permissions menu in the composer also has choices that apply only to the current session:

  • Plan only for this session lets Celeris look and reason, but refuses any call that changes something until you choose again.
  • Accept edits in this folder becomes available after you choose a working folder. It runs ordinary write_file, edit_file, and multi_edit calls under that folder without asking again. Calls outside the folder, other tools that change things, overwrites that would destroy work, and sensitive or escalated edits still stop and ask.
  • Ask before tools returns to asking every time. The existing verified-read setting remains available as a separate choice in the same menu.

The choice stays visible in the composer. It is not saved in Settings and does not survive a restart.

Stopping a run​

Stop in the chat header cancels the turn and kills the command that is running. Commands run in a folder you named and under a timeout. Long output is truncated in the transcript, and the full output stays in the session log.

What is recorded​

Celeris appends every step to that session's local log: tool calls, approvals, denials, and output. You can replay exactly what happened from the session list. See Privacy for where those logs live and what leaves your machine.