ncode Desktop The workspace
Approvals and trust
Agents in ncode can write files and run commands on your Mac. Two things keep you in control: the project's approval mode, and approval cards that ask you before a step the mode does not allow on its own.
Choosing the mode#
The approval control in the composer shows the current project's mode. Click it to switch:
| Mode | In the menu |
|---|---|
| Read-only | agents can only read and search |
| Auto | write & run safe commands |
| Full access | everything, no prompts |
Even in Full access, a command ncode classifies as dangerous still asks. The mode belongs to the project, so every conversation in it follows the same mode.
Approval modes#
Every project has one approval mode. It decides what an agent may do without asking you first.
| Mode | Reads and searches | File writes | Shell commands | Fetching a local or private address |
|---|---|---|---|---|
| Read-only | allowed | blocked | blocked | asks |
| Auto | allowed | allowed | a safe command runs; any other command asks | asks |
| Full access | allowed | allowed | allowed | allowed |
Three rules sit on top of the table:
- A command ncode classifies as dangerous always asks, even in Full access, and "always allow" can never cover it.
- A command classified as safe (for example
ls,git statusorcat notes.txt | grep todo) runs without asking in Auto and Full access. - Reading a page on
localhost, a private range such as10.xor192.168.x, or a link-local address asks in Read-only and Auto. Public pages never ask.
Project trust#
A folder you add is untrusted and starts in Read-only. Until you trust it:
- its instruction files (
AGENTS.mdand friends) reach no prompt; - its hooks do not run.
Trusting a project records your consent and moves it to Auto. A project you already put in Full access stays in Full access.
Remembered commands#
When you allow a command family "always", ncode stores that prefix with the project, so the next matching command in any conversation of that project runs without asking. Dangerous commands are never remembered, and a conversation without a project remembers nothing. You can review and forget remembered prefixes later.
Trusting a new project#
When you add a folder, a banner above the composer says the project is read-only until you trust it. Click Trust and allow edits to trust it and switch it to Auto. Until then, agents can read and search but not write or run anything, and the project's AGENTS.md and hooks are ignored.
Only trust folders you know: a repository you just downloaded can contain instructions and hooks written by someone else.
Answering an approval card#
When a step needs your approval, a card appears in the transcript and on the agent in the agents pane, with the exact command or change:
| Button | What it does |
|---|---|
| Approve | allows this one step |
| Deny | refuses it; the agent is told and carries on |
| Deny & stop | refuses it and stops the run |
| Always allow "…" | allows it and remembers the command family (for example mix test) for this project |
| Allow all … this run | shown instead when there is no command family: allows every call of that tool until the run ends |
An approval nobody answers expires after 10 minutes, and the agent is told it timed out. A conversation with an open approval shows a waiting dot in the sidebar, and the menu bar icon lists it under Waiting for you.
Forgetting remembered commands#
Open Settings → Limits and scroll to Approved commands. It lists, per project, every command family you allowed with Always allow. Click the × on one to forget it, or Clear all to forget every one of a project.
Questions from agents#
Sometimes the assistant or a lead agent asks you instead of guessing: an unclear request, two valid approaches, a destructive choice. A question card shows one to four questions, each with a few options; pick one or type your own answer. A question waits up to 30 minutes for an answer.