The second half of Where it works, on Settings → This Mac → Workspace. These rows decide what a commit has to match, and how far a project's own files may steer the seats. All are Mac only.
Commit only what the room reviewed
When the room agrees, the files are remembered as they stood. If anything changes before you commit (a file, a commit, the branch), this setting decides what happens. It applies to Commit, Create PR and Merge.
Where to find it. Settings → This Mac → Workspace → Where it works. Default: Off.
How to use it.
- Choose Ask first to be told what changed and allowed to carry on.
- Or choose Refuse, and nothing is committed until the room looks again.
When to use it. You edit by hand after the room agrees, and want to be sure the reviewed version is the one that ships.
When not to use it. Quick throwaway work, where a re-review costs more than it saves.
The other switches
| Setting | Default | What it does | Change it when |
|---|---|---|---|
| Point out duplicated code before a push | On | Before a push or a pull request, looks for runs of six or more added lines that already exist in the repository, or twice in the change, and names both places. Also counts lines added and removed. Shown, never a block. If your team has decided this, the switch is disabled and says so. | Generated code makes it noisy. |
| Seats may schedule and notify through their own CLI | Off | A seat's CLI (Claude Code, for one) has its own tools for scheduled jobs, wake-ups, remote triggers and push notices. Off, the app keeps those for itself so nothing outlives the run behind your back. | You rely on those CLI tools and accept jobs the app does not track. |
| Hold runs to a project's forbidden outcomes | On | Reads .letthemchat/forbidden.md. Lines starting with command, edit, read, url or mcp are patterns refused when a tool would act; other lines are sentences the lead is told and Smart mode's judge refuses. Every refusal is an audit event. | Rarely. Turn it off only to debug the file. |
| Ask before using a project's instruction files | On | CLAUDE.md, AGENTS.md and similar are read into every seat's instructions. A folder you did not write can carry text meant to steer the models, so you are asked once per discussion. | Never, unless every folder you open is your own. |
| Say when a configured tool went unused | On | If a run had an MCP server connected and ran shell commands instead of calling it, the Summary says so on every app. Name which tool is for which job in .letthemchat/tool-preferences.md. | You keep a server connected that is not meant for this project. |
| Folders whose instruction files are read | — | Folders you allowed with Always here, and folders this app made. Remove one to be asked again there. | You no longer trust a folder. |

Further reading. OWASP LLM01:2025 Prompt Injection, OWASP GenAI Security Project, 2025, on why a project's own files are treated with care. Modern Code Review: A Case Study at Google, Sadowski et al., 2018.