ncode

Desktop docs Limits and isolation

ncode Desktop Customize

Limits and isolation

Limits keep a runaway swarm from spending forever, and isolation keeps parallel agents from editing the same files at once. Both live in Settings → Limits; change the fields and click Save limits.

Agent limits#

SettingDefaultWhat it bounds
Max concurrent agents4how many sub-agents of one swarm or one chat turn work at the same time; two runs in two conversations each get this many
Max agent depth2how many levels of agents may start agents
Max agent turns60the steps one agent may take before it must answer
Sub-agent time limit (s)1800 (30 minutes)a sub-agent that runs longer is stopped and its partial work reported; 0 means no limit
Workflow agent budget128the most agents a workflow run may start in total, when the workflow sets no budget of its own
Max live workflow agents16how many of them work at the same time, when the workflow sets no max_live; each one uses memory
Command timeout (ms)120,000 (2 minutes)the floor for every shell command; an agent may ask for more for one command (up to 10 minutes), never less
Tool timeout (s)120web fetch, web search and MCP calls

A command that is still running after 10 seconds is not killed: it moves to the background, the agent gets its output so far and can check on it or stop it later. See Watching agents work.

Isolating sub-agents#

With Isolate sub-agents in git worktrees on (the default), sub-agents in a git project can work in their own copy of the project, so two agents editing at once never overwrite each other. Their changes wait on a branch until they are merged back into the project, and the Changes view shows them under Branches.

Isolation backend:

  • Auto (default): an APFS clone when the disk supports it, otherwise a git worktree.
  • APFS clone: a fast copy-on-write copy of the project folder.
  • Git worktree: a separate git worktree.

An isolated agent's finished changes are kept as a patch under .swarm_code/isolation/ in the project until they are merged; ncode removes the ones nothing needs any more.

The agents' shell#

Commands agents run go through your shell, with a few safeguards:

  • Hide secrets from commands the agent runs (on): environment variables whose names look like secrets are removed before a command starts. Keep these variables lists the exceptions (by default GITHUB_TOKEN, GH_TOKEN, so git and gh keep working).
  • Shell (blank = detect): the shell to use; blank uses the shell in your $SHELL.
  • Run commands in a login shell (on): the shell reads your login files (.zprofile, .profile, .bash_profile), not .zshrc. Put PATH changes for tools such as mise, asdf, nvm or Homebrew there, so node, mix or cargo are found.

What an agent can do#

Agents act only through tools. Each tool call is its own step you can watch, and file tools are confined to the project folder.

GroupToolsNotes
Readread_file, list_dir, find_files, grep, lspgrep and find_files use ripgrep when rg is installed
Writewrite_file, edit_file, edit_files, move_file, delete_filea snapshot of each file is taken before it changes; edit_files changes several files all or nothing
Runrun_commanda command still running after 10 seconds moves to the background, where it can be checked or stopped
Gitgit_status, git_diff, git_log, git_commit
Webweb_search, web_fetchsearch uses the engines you enabled, in your order
Memoryrememberadds a dated line to the project's memory file
Teamspawn_agent, message_agent, inbox, wait_for_message, agent_result, integrate_agent, start_swarmsub-agents, messages between agents, merging an isolated agent's changes
Askask_userthe assistant and a lead may ask you a question; workers may not
Planssubmit_plan, write_speconly in judged (consensus) runs
Workflowsworkflow_list, workflow_smoke_check, workflow_save, workflow_run, workflow_controlonly the top-level assistant
MCPevery tool of every enabled MCP serverper-tool switches let you turn single tools off

run_command keeps up to 160,000 characters of output by default (an agent may ask for up to 512,000). Whether a write or a command needs your approval depends on the project's approval mode.

Approved commands#

The last part of Settings → Limits lists the command families you allowed with Always allow, per project. See Approvals and trust.