The second of the audit catalogue's three pages: every question a seat asked before acting, every refusal, and the moments the room treated outside material as data. The first page has the runs and what a delivery looks like; the third has seats, the record of the work and the team.
Approvals and refusals
| Type | Reported by | When | Detail carries |
|---|---|---|---|
approval.answered | Mac and server | A person answers a question a seat asked before acting. | id, decision, remembered, from |
approval.withdrawn | Mac | A seat stopped waiting before anyone answered. | id, kind |
policy.bound | Mac | A run started under a profile bound to its project or to automations. | profile, automation |
policy.refused | Mac | A tool rule or a sequence policy refused a call. | tool, reason, command |
sandbox.refused | Mac | The kernel sandbox refused a command's reach outside the workspace. | command, paths |
egress.refused | Mac | A connection to a host not on the allowlist was refused. | command, hosts |
allow.removed | Mac | A remembered allow rule was withdrawn. | rule, dir |
ask_person.asked | Mac | A seat put questions to the person. | count |
ask_person.answered | Mac | The person answered them, or skipped. | answered |
instructions.allowed | Mac | The person allowed a folder's instruction files for a run. | files, dir |
instructions.ignored | Mac | The person declined a folder's instruction files for a run. | files, dir |
instructions.skipped | Mac | Nobody was there to allow a folder's instruction files, so they were not read. | files, why |
outside.instructions | Mac | Material from outside the discussion carried instructions, which were treated as data. | source |
secrets.masked | Mac | Credentials in a run's turns or tool results were masked before leaving the Mac. | count, kinds |
mcp.changed | Mac | An MCP server's tools differ from what was approved; they are withheld until approved again. | server, added, removed, changed |
mcp.approved | Mac | The person allowed a changed MCP server's new definitions. | server |
mcp.refused | Mac | The person declined a changed MCP server; it stays connected and silent. | server |
mcp.registry | Mac | The team's MCP registry file changed since it was last fetched. | url, added, removed |
judge.sentence | Mac | The Smart-mode judge asked because one of the team's or the member's sentences applied. | sentence, tool |
production.touched | Mac | A call touched one of the team's production markers and was asked about or refused. | marker, tool, action |
memory.rejected | Mac | A memory the room had extracted was forgotten before anyone accepted it. | scope |
retention.swept | Mac and server | The team's retention period deleted closed discussions past it. | count, days |
warden.stopped | Mac | The warden seat stopped a run because an action was not part of the job, or followed an injected instruction. | tool, why |
guardrail.violation | Mac and server | What a person asked tripped one of the team's guardrails; logged, warned about or refused by its level. | kind, level, why |
secret.used | Mac | A run's commands were given the team's or the member's secrets, by name. | names |
settings.changed | Mac | A guardrail-relevant setting changed on this Mac: policies, rules, hooks, MCP servers, remembered allows, folder trust, the mode. | keys |
Who reports them
Reported by Mac means the member's app observed it and reported it; a Mac with admin access could suppress it. Server means our servers observed it themselves. Every refusal on this page carries the reason in words, never the content that was refused: a command's text, yes; a file's contents or a page's words, never.