Skip to main content

Autonomy & permissions

Imaginne acts on your machine — so control over when it asks permission and what it can run is central. There are three complementary mechanisms: autonomy, execution mode, and the vault (firewall).

Autonomy levels​

Autonomy defines how much the agent asks before acting.

Three levels: low (confirms everything), medium (confirms sensitive operations, default), and high (doesn't ask).
Low, medium (default), and high. The command vault still applies at any level.
LevelBehavior
LowConfirms every action with an effect (edit a file, run a command). Maximum control.
Medium (default)Approves trivial actions on its own; asks for confirmation only on sensitive operations.
HighRuns everything without asking. Use only in trusted workspaces.

You adjust autonomy on each surface:

  • Desktop — Settings → Autonomy (Low / Medium / High).
  • Terminal (TUI) — /autonomy (or /a, or Ctrl+A).
  • VS Code — picker in the panel (Ask / Fix / Agent / Bypass — see Use in VS Code).

Command execution mode​

Independent of autonomy, there's a stricter control over running terminal commands:

  • safe — the most restrictive: no shell strings, operators, or redirection.
  • auto (default) — today it behaves like safe.
  • dangerous_bypass — turns off the shell validations (allows sh -c, pipes, redirections). It's only available if the application was started with an explicit flag; otherwise the request is downgraded to auto. Even in bypass, the workspace and audit limits still apply.
"Bypass" requires intent

The dangerous mode does not turn itself on from configuration — it requires starting the binary with the appropriate option. It's a deliberate decision for trusted workspaces.

The vault (firewall) — always on​

Underneath everything, a set of rules protects your system, at any autonomy level:

  • Strict workspace scope by default: reading, writing, and executing outside the workspace is denied unless policy opens it. (Your ~/.imaginne configuration folders are an exception.)
  • Hard denials: catastrophic commands (rm -rf /, system paths like /etc, /usr, C:\Windows) never run.
  • Credential paths (.ssh, .aws, .env, credentials) require sensitive confirmation.
  • Write review ("see the diff first"): the VS Code extension shows each edit as a diff for you to Apply/Reject.

Failure-repeat guard​

An internal watcher tracks failure streaks during a task. If the agent enters an unproductive loop, it can be nudged or stopped — preventing a "stuck" agent from burning time and tokens for nothing.

How to choose​

  • Exploring, shared machine, sensitive data → low autonomy.
  • Day-to-day → medium (the default).
  • Disposable/your own workspace, repetitive task → high, and consider the appropriate execution mode.

See also​