Permissions & safety
The agent can change files and run commands, so Pathvela is built so that nothing destructive happens without a person in the loop and dangerous operations are caught before they run. This page explains the guardrails and what you control.
Read-only vs full access
The agent runs in one of two tool profiles, chosen by how the session started:
- Read-only. A headless
lily rungets a read-only profile — it can read files, search, and run read-only commands, but it will not modify files or take destructive actions, because no one is present to approve them. This makeslily runsafe to drop into scripts and pipelines. - Full. An interactive session — the
lilyterminal UI, or your browser through auto mode — gets the full tool set, so the agent can make changes. Risky actions still pass through the approval gate below.
Approving actions
In an interactive session, actions that change your system surface for approval rather than running silently. You review what the agent wants to do and allow or decline it.
To see and manage what's pending in the current session:
/permissions
This lists the permissions the agent has requested so you can review them in one place.
The guardrail on shell commands
Before any shell command runs, Pathvela classifies it for risk. Commands that are plainly destructive — recursive deletes (rm -rf), disk writes (dd), shred, find -delete, output redirections that could clobber files — are held for confirmation or refused outright, even in a full-access session. The classifier is deterministic and runs first, so a dangerous command can't slip through on a model's say-so.
This is a safety net, not your only line of defense: the agent is confined to the folder it's working in (see Auto mode → scope and safety), and read-only sessions can't reach these commands at all.
What the agent can reach
- In the CLI, the agent works in your current folder —
cdinto a project first, or point it with--cwd. - In auto mode, it's confined to the folder you granted when you ran
lily bridge install. - In the browser (WASM) SDK, it runs in the browser's sandbox with no access to your real disk — see Browser vs Node.
Access ends when you stop the session: close the terminal, or lily bridge stop / lily bridge reset for the bridge.
See also
- Tools — the full tool catalog and the read-only vs full split.
- Auto mode — folder scoping and pairing for the browser.
- Browser vs Node — the browser sandbox.