ncode

CLI docs Approvals and trust

ncode CLI Using ncode

Approvals and trust

Agents act only through tools, and every tool call that could change something is checked against the project's approval mode first. The mode belongs to the project, not to the conversation, and the desktop app uses the same one. It is always shown on the status line.

The rules#

Approval modes#

Every project has one approval mode. It decides what an agent may do without asking you first.

ModeReads and searchesFile writesShell commandsFetching a local or private address
Read-onlyallowedblockedblockedasks
Autoallowedalloweda safe command runs; any other command asksasks
Full accessallowedallowedallowedallowed

Three rules sit on top of the table:

  • A command ncode classifies as dangerous always asks, even in Full access, and "always allow" can never cover it.
  • A command classified as safe (for example ls, git status or cat notes.txt | grep todo) runs without asking in Auto and Full access.
  • Reading a page on localhost, a private range such as 10.x or 192.168.x, or a link-local address asks in Read-only and Auto. Public pages never ask.

Project trust#

A folder you add is untrusted and starts in Read-only. Until you trust it:

  • its instruction files (AGENTS.md and friends) reach no prompt;
  • its hooks do not run.

Trusting a project records your consent and moves it to Auto. A project you already put in Full access stays in Full access.

Remembered commands#

When you allow a command family "always", ncode stores that prefix with the project, so the next matching command in any conversation of that project runs without asking. Dangerous commands are never remembered, and a conversation without a project remembers nothing. You can review and forget remembered prefixes later.

Changing the mode#

text
/approval auto

/approval read-only, /approval auto and /approval full switch the project's mode; /approval alone opens a picker of the three with the current one checked. Every change, from here, from Settings or from the desktop app, is said in the chat:

Approvals: auto → full access

/trust trusts the project: its instruction files are read from then on, its hooks may run, and a read-only project moves to auto. In Settings, Approvals & trust shows the mode, the trust switch and the list of always-allowed commands, which you can edit.

The approval card#

When an agent needs your answer, a card opens by itself above the composer. It shows the command in a code block of at most six lines; with your draft empty, Enter shows every line and Enter again folds them back.

KeyAnswer
yallow once
Yallow for the rest of this run
Aalways allow this command family in this project
ddeny
Ddeny and stop the run
nleave this one and show the next thing waiting

A card offers only the answers that apply to it, and only those letters answer it. Three rules keep you from answering by accident:

  • For a moment after a card opens, your keys keep typing into the draft, so a sentence you are in the middle of is never taken as an answer.
  • The letters answer only while your draft is empty. Any other letter types, and Enter with a draft sends the draft; the card stays.
  • The same applies to a card you brought back with Ctrl+N or n.

Ctrl+N opens the next approval or question waiting on you. In an agent overlay the same letters answer that agent's request.

Approvals in headless runs#

A headless run (ncode -p) has nobody to ask. It uses the project's approval mode as it is: whatever the mode allows runs, and anything that would still need a person is denied, with a line on stderr saying what was denied. In full access the stderr line says that nothing asks. An agent's question stops a headless run.