All documentation

Documentation Settings: This Mac

The Guardrails list

Every guardrail the Mac can keep for you, what each one does, and how a switch becomes a rule.

In force now shows what protects you; the Guardrails list shows what could. Switch a row on and it holds in every discussion on this Mac. What your team requires applies whatever you set here.

Where to find it. Mac only: Settings → Workspace → Guardrails. A row already on is marked. Rows that take a value or a pattern open a small field when you switch them on.

Settings → Workspace → Guardrails, with the first rows switched on
Settings → Workspace → Guardrails, with the first rows switched on

Limits and asks

GuardrailDefaultWhat it does
Stop a discussion after it has spentOffA hard stop at a dollar figure across the whole discussion. Same as the ceiling under Spending → Brakes.
Stop one turn after it has spentOffThe same, for one question.
Stop after so many tool callsOffRefuses the next call once a discussion reaches the count.
Hand over after so many failed fixes3An edit then a failing check is one try. At the limit the seat stops and shows what it tried.
Refuse tools without the kernel sandboxOffFail closed: no sandbox, no commands and no CLI seats.
Ask when a seat repeats the same call three timesOnAsks on the third identical call, then every third after.
Ask before a push after something was installedOnA dependency added and a push straight after asks first.
Ask before a command opens a way in from the internetOnTunnels, servers on every interface, firewall openings. Asked every time, never remembered.
Honour robots.txt when the room reads a pageOnA path closed to bots is not fetched; the seat is told why.

Project files the room reads

GuardrailDefaultWhat it does
Read the project's objectives and measure them after an agreed runOnReads .letthemchat/objectives.md; the receipt says which held.
Read the project guide's index, and a chapter when the task fitsOnReads .letthemchat/guide/index.md.
Triage an issue before the room builds itOnOne cheap call files an issue as ready, needs a spec, needs a person, or parked.
Run the automations a project keeps in its repositoryOnReads .letthemchat/automations.json.
Write a closing answer even when nobody objected and nothing was builtOffSynced with the web and iPhone.

Rules and checks

GuardrailWritesWhat it does
Never change these filesdeny editA pattern nothing may write to.
Never read these filesdeny readSecrets a seat should not see.
Always ask before this commandask commandAsks whatever the mode says.
Never run this commanddeny commandRefused in every mode.
Let these commands run without askingallow commandSpares the question only; the sandbox and dangerous list still apply.
Run this after every writea hookYour formatter or linter, output handed to the lead.
A rule in your own wordsa prompt hookA sentence a model judges before each command. If no model answers, work continues.
Let a model decide the restSmart modeEdits go through; the rest is judged.
Read every commit I makea reviewReviews each commit in its own discussion, with an optional dollar cap.
Keep every discussion out of my checkoutworktreesEach discussion works in its own git worktree. On by default.

Pattern rows add a line to your rules rather than replacing what you wrote. You can read and edit those lines under Rules you already have → Advanced.

Further reading. OWASP Top 10 for LLM Applications 2025 — OWASP.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.