Approvals & safety
Celeris never hands the model a bare shell. It offers a set of tools, and it checks every call before running it. Reads run on their own, writes ask, and anything that cannot be undone or leaves your machine asks every time. A step Celeris does not recognise asks too rather than guessing it is safe, and you can stop a running task at any time from the chat window.
Reads run, writes ask
| What the call does | Examples | What happens |
|---|---|---|
| Reads something | Reading a file, listing a folder, commands like ls, cat, git status, grep, and a few approved reads that query a service you are already signed in to, such as gh pr view | Runs without asking |
| Changes something | Writing a file, sending a message, anything that changes state | Asks: Run, Deny, or Always allow |
| Cannot be undone, or sends data off your machine | Deleting files, force pushes, sudo, permission changes, output redirection, network fetches, package installs, killing processes | Asks every time, even with auto-run on, unless you turn on the explicitly labelled dangerous bypass setting |
Celeris judges commands one at a time, not by the tool that carries them. ls
reads and rm -rf deletes, even though both arrive through the same "run a
command" tool.
It judges a command's options too. find, fd and tree list files, but
find -delete deletes, find -exec and fd -x run another program, and
tree -o writes a file, so those forms ask like any other change. A listing
that would print more than names asks too: ps e shows other programs'
environment, wc --files0-from= prints the file it reads, git remote show origin contacts the remote, and gh pr view --web opens a browser. For
commands like these, an option Celeris does not recognise asks as well, and so
does a setting in front of the command that can load other code, such as
LD_PRELOAD=.
Approving
When a call needs approval, the chat window shows what will run: the command, the working folder, the tool and its arguments. You have three choices.
- Run allows this call once.
- Deny refuses it. Celeris carries on with the rest of the task and tells you what it could not do.
- Always allow adds that shape of call to your allowlist, so it runs without asking from then on.
Approving as you go means the set of things Celeris can do without interrupting you grows through use, rather than by turning safety off before you start. Edit your allowlist in Settings → Safety. A call that cannot be undone or leaves your machine cannot be added to it.
Auto-run
Auto-run lets calls that change something proceed without asking. It never covers a call that cannot be undone or leaves your machine. Turn it on only for work you would have approved anyway.
Choices that last one session
The Permissions menu in the composer also has choices that apply only to the current session:
- Plan only for this session lets Celeris look and reason, but refuses any call that changes something until you choose again.
- Accept edits in this folder becomes available after you choose a working
folder. It runs ordinary
write_file,edit_file, andmulti_editcalls under that folder without asking again. Calls outside the folder, other tools that change things, overwrites that would destroy work, and sensitive or escalated edits still stop and ask. - Ask before tools returns to asking every time. The existing verified-read setting remains available as a separate choice in the same menu.
The choice stays visible in the composer. It is not saved in Settings and does not survive a restart.
Stopping a run
Stop in the chat header cancels the turn and kills the command that is running. Commands run in a folder you named and under a timeout. Long output is truncated in the transcript, and the full output stays in the session log.
What is recorded
Celeris appends every step to that session's local log: tool calls, approvals, denials, and output. You can replay exactly what happened from the session list. See Privacy for where those logs live and what leaves your machine.