Guarded Mode
Let the agent work without permission prompts, and ask you only before actions that are hard to undo, leave the project, or reach other people.
Guarded is a permission mode between Ask to Edit and Execute. The agent works as in Execute — no prompts for ordinary work — but before each command or change, the decision model checks it, and you are asked first when it looks risky.
Use it when you want an agent to get on with a task unattended, without handing it a blank cheque.
Turn it on
- Set up a decision model.
clef-flashis the best fit: it checks a call in about 40 ms. - Under Advanced settings, switch on Guarded mode.
- In a session, choose Guarded in the permission mode picker, or press
Shift + Tabto cycle through Explore → Ask to Edit → Guarded → Execute.
What is checked
Bash commands, writes through MCP tools and non-GET API calls. Reading files, searching and other read-only work is never checked.
For each one, the decision model is asked three questions:
| Risk | The question |
|---|---|
| Hard to undo | Would this permanently delete, overwrite or destroy data? |
| Outside the project | Does it change files, settings or processes outside the project directory — your home folder, system locations, other repositories? |
| Reaches others | Does it send data or messages to other people or services, publish something, or change a remote system (push, deploy, email, post, pay)? |
If any answer is "yes" with high confidence, the call becomes an ordinary permission prompt that says why. Otherwise it runs.
Some things always ask, without consulting the model: writing a file outside the working directory and the session's plans and data folders.
When the check can't answer
- If a single check times out or fails, you are asked, and the prompt says the call could not be checked. Guarded never runs an unchecked call silently.
- If the decision model is turned off or unavailable altogether, a Guarded session behaves like Ask to Edit.
Good to know
- Guarded prompts don't offer Always Allow: approving one risky call should never approve the next.
- A plan approved from Explore returns the session to Guarded if it came from there.
- Automations, task specs and
spawn_sessioncan't start in Guarded, but sessions started from a Guarded session stay at most Guarded. - Execute never consults the decision model.
- Pair it with Risk badges (Advanced settings), which tag every permission prompt with what the action does: deletes, sends, publishes, credentials, system, spends.
Example
You ask the agent to clean up a repository and open a pull request. In Guarded mode it reads files, edits code and runs tests without asking. It stops to ask before git push --force, before rm -rf ~/old-builds (outside the project), and before gh pr create (reaches other people) — each prompt naming the risk.
Set Up a Decision Model
Connect Jev (TypeSafe AI, OpenRouter, Vercel AI Gateway), Cloudflare Clef (Workers AI or AI Gateway), a local Laya server or your own endpoint.
Adaptive Thinking
Use less reasoning on simple messages for faster, cheaper turns — never more than the thinking level you chose, and never less than a request needs.