FabricFabric
Decision Models

Guarded Mode

Let the agent work without permission prompts, and ask you only before actions that are hard to undo, leave the project, or reach other people.

Guarded is a permission mode between Ask to Edit and Execute. The agent works as in Execute — no prompts for ordinary work — but before each command or change, the decision model checks it, and you are asked first when it looks risky.

Use it when you want an agent to get on with a task unattended, without handing it a blank cheque.

Turn it on

  1. Set up a decision model. clef-flash is the best fit: it checks a call in about 40 ms.
  2. Under Advanced settings, switch on Guarded mode.
  3. In a session, choose Guarded in the permission mode picker, or press Shift + Tab to cycle through Explore → Ask to Edit → Guarded → Execute.

What is checked

Bash commands, writes through MCP tools and non-GET API calls. Reading files, searching and other read-only work is never checked.

For each one, the decision model is asked three questions:

RiskThe question
Hard to undoWould this permanently delete, overwrite or destroy data?
Outside the projectDoes it change files, settings or processes outside the project directory — your home folder, system locations, other repositories?
Reaches othersDoes it send data or messages to other people or services, publish something, or change a remote system (push, deploy, email, post, pay)?

If any answer is "yes" with high confidence, the call becomes an ordinary permission prompt that says why. Otherwise it runs.

Some things always ask, without consulting the model: writing a file outside the working directory and the session's plans and data folders.

When the check can't answer

  • If a single check times out or fails, you are asked, and the prompt says the call could not be checked. Guarded never runs an unchecked call silently.
  • If the decision model is turned off or unavailable altogether, a Guarded session behaves like Ask to Edit.

Good to know

  • Guarded prompts don't offer Always Allow: approving one risky call should never approve the next.
  • A plan approved from Explore returns the session to Guarded if it came from there.
  • Automations, task specs and spawn_session can't start in Guarded, but sessions started from a Guarded session stay at most Guarded.
  • Execute never consults the decision model.
  • Pair it with Risk badges (Advanced settings), which tag every permission prompt with what the action does: deletes, sends, publishes, credentials, system, spends.

Example

You ask the agent to clean up a repository and open a pull request. In Guarded mode it reads files, edits code and runs tests without asking. It stops to ask before git push --force, before rm -rf ~/old-builds (outside the project), and before gh pr create (reaches other people) — each prompt naming the risk.

On this page