Approvals & safety
Celeris never hands the model a bare shell. It offers a set of tools and checks every call before running it.
| What the call does | Examples | What happens |
|---|---|---|
| Reads something | Reading a file, listing a folder, ls, git status, grep | Runs without asking |
| Changes something | Writing a file, sending a message | Asks: Run, Deny, or Always allow |
| Cannot be undone, or sends data off your machine | Deleting files, force pushes, sudo, network fetches, package installs | Asks every time |
Celeris judges each command and its options, not the tool that carries it. ls
reads and rm -rf deletes, though both arrive through the same "run a command"
tool. find lists files, but find -delete deletes, so it asks. A command or
option Celeris does not recognise asks too, rather than being guessed safe.
Approving
The approval prompt shows what will run: the command, the working folder, and the tool's arguments.
- Run allows this call once.
- Deny refuses it. Celeris carries on with the rest of the task and tells you what it could not do.
- Always allow adds that kind of call to your allowlist, so it runs without asking from then on.
Your allowlist grows as you use Celeris. Edit it in Settings → Safety. A call that cannot be undone or leaves your machine cannot be added to it.
Auto-run, also in Settings → Safety, lets calls that change something run without asking. It never covers a call that cannot be undone or leaves your machine.
Choices for one session
The Permissions menu in the composer applies to the current session only:
- Plan only lets Celeris look and reason, but refuses any call that changes something.
- Accept edits in this folder runs ordinary file edits inside the working folder you chose without asking. Edits outside it still ask.
- Ask before tools returns to asking every time.
Stopping and reviewing
Stop in the chat header cancels the turn and kills the running command. Every tool call, approval, denial and its output is kept in that session's local history, so you can see exactly what ran.
Plugins, triggers and phone sessions do not change any of this. See Tools, Triggers and Celeris on your phone.