Some guardrails have no row in the list, or have more behind them than a row can say. This page covers those.
Session policies
These count what one discussion does.
- Opening a way in from the internet covers cloudflared, ngrok, a Tailscale funnel,
ssh -R, binding to 0.0.0.0, publishing a container port, and opening a firewall or security group. It asks every time and is never remembered. A team can make it a refusal. - The same call three times in a row asks. For a CLI seat, answering No stops that seat only.
- The tool-call cap, when set, refuses the next call.
- A push after an install in the same discussion asks.
- Failed fixes: at the limit (3 by default, 0 for never) the seat stops with what it found. A team value works as a ceiling.
- Production markers (team only): a call naming a host, address, variable or account the team marked as production asks, or is refused if the team chose that.
Where your settings and your team's overlap, the stricter one wins on each line. A team can add a question or lower a cap, never remove one you set.
Protected instruction files
An edit to a file that tells AI tools what to do asks in every mode, with no switch, and is refused when nobody is there. That covers AGENTS.md, CLAUDE.md, GEMINI.md, .cursorrules, .windsurfrules and their kin, and anything under .letthemchat, .claude, .codex, .gemini, .cursor/rules, .github/instructions, .git/hooks and .husky. Write allow edit AGENTS.md in your rules to loosen it, or deny edit to close it. A shell command or CLI seat that writes such a file is announced and recorded afterwards, not blocked.
Commit only what the room reviewed
Where to find it. Mac only: Settings → Workspace → Where it works. Default: Off. Choices: Off, Ask first, Refuse.
When the room agrees, the file tree is fingerprinted. If anything changes before Commit, Create PR or Merge, Ask first shows "This is not what the room reviewed" with Cancel and Commit anyway, and Refuse stops the commit and asks you to have the room look again. A discussion that never agreed is not checked.

On the Approvals and safety nets card
| Setting | Default | What it does |
|---|---|---|
| Keep a copy before the room changes a file | On | In your own folder, with no worktree to go back to, each file is copied before the first change. Backups on the discussion's menu puts one back. Files over 20 MB are skipped, and a CLI seat's own edits are not seen. |
| Keep those copies for | A day | 6 hours to a week. |
| Warn before a sensitive folder becomes a workspace | On | Your home folder, a system folder, the app's data, or an iCloud, Dropbox, OneDrive or Google Drive folder is named for what it is. You can always go ahead. |
| Watched commands may tell the room | 20 lines a minute | Caps how many new output lines from a watched command reach the lead. Off removes the tool. |
The brakes beyond this page
Spend ceilings stop a discussion or a turn at a dollar figure; what a CLI seat spends on your own subscription is not counted. On the web and iPhone, an account runs at most 3 discussions at once and sends at most 20 messages a minute. Stop ends every stream, command and CLI seat in a discussion, from any device. A team owner or admin can pause every member's runs from the Team page, and an auditor reads everything but runs nothing.
Further reading. Not what you've signed up for — Greshake et al., 2023. AI Risk Management Framework — NIST, 2023.