AI agent

Agent approvals and safety boundaries

Use the shell-command approval card and feature-specific previews without assuming Kition 0.1.41 has a universal per-tool permission editor.

Updated

By Kition Docs

Verified against Kition 0.1.41 (d3e1b931) on 2026-08-29

Shell commands have a resumable approval flow

When shell_exec or exec_command is blocked by execution policy, the runtime can return the exact command, a reason, and an optional suggested command prefix. Kition displays a Shell command approval card.

  • Allow once — retry the exact command for this approval
  • Always allow — available only when the runtime suggests a prefix; sends a remembered-prefix decision
  • Deny — tell the Agent not to run the command and to continue without it when possible

Heads up

Read the full command, working directory implications, arguments, redirects, and shell operators before approving. A safe-looking prefix can still permit risky later arguments.

Execution-policy contract

The client exposes runtime helpers for command-prefix rules with decisions such as allow, prompt, and forbidden. The public Desktop UI does not expose a general execution-policy editor or the on-disk rule path.

An Always allow decision is sent back with the pending tool-call ID. A different command that is not covered by a remembered rule should request approval again.

There is no universal tool permission editor

Kition 0.1.41 does not ship Settings → Agent → Permissions, a workspace .kition/permissions.json, or general allow/ask/deny rules for every document, table, browser, MCP, and filesystem tool.

Do not assume reads are always silent, writes always ask, or destructive tools always deny. Actual availability and governance come from the runtime and feature-specific flows.

Feature-specific review controls

  • Table write plans can require an explicit Apply action
  • Document and patch tools can expose changed-file paths and previews
  • Whiteboard proposals can be shown before the final patch is accepted
  • The Agent can request additional user input before continuing
  • The Stop button aborts the current stream but does not undo completed actions

Practical safety rules

  • Back up the workspace before broad edits
  • Use least-privilege provider, website, database, and external-service accounts
  • Treat browser pages and external tool output as untrusted prompt input
  • Verify filesystem, table, browser, and remote-system changes at the source
  • Deny commands you cannot explain and ask for a safer alternative

Implementation sources

Related pages

Ready when you are.

Kition is a desktop AI workspace for connected documents, structured tables, editable designs, whiteboards, visual workflows, and reviewable AI agents.