ncode Desktop Customize
Limits and isolation
Limits keep a runaway swarm from spending forever, and isolation keeps parallel agents from editing the same files at once. Both live in Settings → Limits; change the fields and click Save limits.
Agent limits#
| Setting | Default | What it bounds |
|---|---|---|
| Max concurrent agents | 4 | how many sub-agents of one swarm or one chat turn work at the same time; two runs in two conversations each get this many |
| Max agent depth | 2 | how many levels of agents may start agents |
| Max agent turns | 60 | the steps one agent may take before it must answer |
| Sub-agent time limit (s) | 1800 (30 minutes) | a sub-agent that runs longer is stopped and its partial work reported; 0 means no limit |
| Workflow agent budget | 128 | the most agents a workflow run may start in total, when the workflow sets no budget of its own |
| Max live workflow agents | 16 | how many of them work at the same time, when the workflow sets no max_live; each one uses memory |
| Command timeout (ms) | 120,000 (2 minutes) | the floor for every shell command; an agent may ask for more for one command (up to 10 minutes), never less |
| Tool timeout (s) | 120 | web fetch, web search and MCP calls |
A command that is still running after 10 seconds is not killed: it moves to the background, the agent gets its output so far and can check on it or stop it later. See Watching agents work.
Isolating sub-agents#
With Isolate sub-agents in git worktrees on (the default), sub-agents in a git project can work in their own copy of the project, so two agents editing at once never overwrite each other. Their changes wait on a branch until they are merged back into the project, and the Changes view shows them under Branches.
Isolation backend:
- Auto (default): an APFS clone when the disk supports it, otherwise a git worktree.
- APFS clone: a fast copy-on-write copy of the project folder.
- Git worktree: a separate git worktree.
An isolated agent's finished changes are kept as a patch under .swarm_code/isolation/ in the project until they are merged; ncode removes the ones nothing needs any more.
The agents' shell#
Commands agents run go through your shell, with a few safeguards:
- Hide secrets from commands the agent runs (on): environment variables whose names look like secrets are removed before a command starts. Keep these variables lists the exceptions (by default
GITHUB_TOKEN, GH_TOKEN, sogitandghkeep working). - Shell (blank = detect): the shell to use; blank uses the shell in your
$SHELL. - Run commands in a login shell (on): the shell reads your login files (
.zprofile,.profile,.bash_profile), not.zshrc. PutPATHchanges for tools such as mise, asdf, nvm or Homebrew there, sonode,mixorcargoare found.
What an agent can do#
Agents act only through tools. Each tool call is its own step you can watch, and file tools are confined to the project folder.
| Group | Tools | Notes |
|---|---|---|
| Read | read_file, list_dir, find_files, grep, lsp | grep and find_files use ripgrep when rg is installed |
| Write | write_file, edit_file, edit_files, move_file, delete_file | a snapshot of each file is taken before it changes; edit_files changes several files all or nothing |
| Run | run_command | a command still running after 10 seconds moves to the background, where it can be checked or stopped |
| Git | git_status, git_diff, git_log, git_commit | |
| Web | web_search, web_fetch | search uses the engines you enabled, in your order |
| Memory | remember | adds a dated line to the project's memory file |
| Team | spawn_agent, message_agent, inbox, wait_for_message, agent_result, integrate_agent, start_swarm | sub-agents, messages between agents, merging an isolated agent's changes |
| Ask | ask_user | the assistant and a lead may ask you a question; workers may not |
| Plans | submit_plan, write_spec | only in judged (consensus) runs |
| Workflows | workflow_list, workflow_smoke_check, workflow_save, workflow_run, workflow_control | only the top-level assistant |
| MCP | every tool of every enabled MCP server | per-tool switches let you turn single tools off |
run_command keeps up to 160,000 characters of output by default (an agent may ask for up to 512,000). Whether a write or a command needs your approval depends on the project's approval mode.
Approved commands#
The last part of Settings → Limits lists the command families you allowed with Always allow, per project. See Approvals and trust.