Agents and models

Approvals and safety

What the agent may do on its own, what it asks you first, how System One and run budgets work, and what the agent cannot touch.

The agent works in one place: your project folder. It reads and writes files there and can run commands there. This page explains what it does freely and what waits for you.

What is asked

Each thing the agent does has a risk level.

Risk Examples In the app
Read Reading and searching files Runs without asking
Write Creating and editing files in the project Runs without asking
Command Running a shell command Asks first
External Fetching a web page, searching the web Asks first

The app runs with these rules. There is no setting in the app to change them. The agent software also has a stricter mode in which file writes ask too; the app does not offer it yet.

With Claude Code, reading and editing are pre-approved only inside the project folder, and the project's build commands are pre-approved. Anything else, including a write outside the project, shows the approval card.

With the Codex CLI, there are no approval cards. Codex runs commands inside its own sandbox, limited to the project folder, without asking. Settings shows a warning about this under the option.

The approval card

When something needs your approval, the run pauses and an amber card appears with:

  • the name of the tool and its risk,
  • the command, or for a file change the exact difference it would make to the file as it is now,
  • a warning if an edit cannot apply,
  • an "estimate" line, when System One has judged the action.

Choose Allow or Deny. With the Graspable agent, a card left unanswered for five minutes counts as a denial.

After a denial the agent is told and carries on another way, or stops.

System One, in plain words

System One is an optional helper: a small, fast model that answers narrow questions such as "is this command harmless?". You set it up in Settings → System One (fast decisions).

What it can do:

  • approve a command for you, but only when Graspable's own fixed rules already find the command harmless and the model agrees with measured confidence,
  • skip the short "what did we learn" step at the end of a run when nothing was learned,
  • stop repair turns that no code change can fix.

What it cannot do:

  • deny anything. A doubtful action always goes to you.
  • approve changes to files Graspable manages (listed below).

The modes are:

Mode Meaning
Assist Auto-approve harmless commands the rules find clean, skip turns that are not needed
Shadow Judge and log only. Nothing is decided for you
Off No System One calls

With no provider added, only the rules decide and nothing is auto-approved. You can add Jev (TypeSafe), any OpenAI-compatible endpoint or Anthropic's Claude Haiku. Test shows what a provider would do with a harmless read and with a command that would leak a secret.

Every judgement appears in the run with a ⚡ mark.

Run budget

In Settings → Run budget you can set hard caps per run: max $ and max tokens. Leave a field empty for no cap.

When the reported usage crosses a cap, the run is stopped. Cost is known only for providers that report it. Tokens are always counted. With Claude Code and the Codex CLI the check happens between turns, so a run can pass the cap slightly before it stops.

Settings → Usage shows totals for every run on your computer.

Graspable also stops a run that is going nowhere, such as the same action repeated again and again. The transcript shows a ⚠ line saying why.

What the agent cannot touch

  • Files outside the project. File tools accept only paths inside the project folder. Paths that try to leave it, including through links, are refused.
  • .graspable/ in the project. It holds memory and the run journal. It is hidden from the file list and cannot be written by the agent's file tools.
  • tests/xr/, xr-dev.js and graspable-source.js. The agent is told never to edit them by hand, Claude Code is blocked from editing them, and System One never auto-approves a change to them.
  • Your sign-ins. Graspable never reads or copies the sign-in of Claude Code or the Codex CLI.

A shell command is a different matter: once you allow a command, it runs with your user's permissions. Read the card before you choose Allow.

If something goes wrong

Every file change in a run is recorded. Undo run puts the files back. See Your first project.