ALLOW
Permit a supported operation within the configured scope. This does not override product safety rules or authorize arbitrary commands.
Security / VEYLUM
Permission before action
Permit a supported operation within the configured scope. This does not override product safety rules or authorize arbitrary commands.
Pause for explicit review. Check the proposed paths and exact changes; write approvals are one-use and become stale when relevant workspace state changes.
Refuse the operation. Imported content or a model request cannot elevate this policy.
Bounded Windows tools
Choose an attached project folder with the operating system picker. Supported file tools resolve workspace-relative paths and enforce containment, sensitivity restrictions, output limits, and permissions. A model cannot turn a read into an unrestricted disk scan.
An opt-in Development bot can propose create, edit, patch, rename, or delete actions. Review exact edits in the existing approval flow; delete also requires typed path confirmation. The fixed offline Node test profile uses a restricted Windows process with network and outside-workspace access denied. It is for dependency-free JavaScript tests, not general build commands.
Git actions are structured and local. There is no exposed raw shell, Git push, reset, or clean tool. Tool activity is audited; task cancellation and restart do not grant new access.
Workspace containment is not a guarantee against an administrator or another process running as your Windows user and altering files concurrently. Use trusted folders and review proposed edits.
More surfaces, the same authority
Mobile access is off by default and binds to a selected private LAN address. A local certificate, expiring invitation, desktop approval, and revocable session establish access. Trust only your desktop’s identity. Stop the listener or revoke a device when needed.
Current paired personal-chat sessions do not grant project file, command, Git, or approval authority. Broader companion access remains in final release validation.
Backups contain private data, are integrity-checked, and do not include model weights. Restored workspaces require fresh folder authorization. Keep an independent private backup before migration or restore.
Compare the exact package SHA-256 before running it. Preview builds are currently unsigned; signing requires external credentials. Genuine previous-version rollback remains unverified. There is no configured automatic updater.