AI agent
Agent approvals and safety boundaries
Use the shell-command approval card and feature-specific previews without assuming Kition 0.1.41 has a universal per-tool permission editor.
Updated
By Kition Docs
Verified against Kition 0.1.41 (d3e1b931) on 2026-08-29
Shell commands have a resumable approval flow
When shell_exec or exec_command is blocked by execution policy, the runtime can return the exact command, a reason, and an optional suggested command prefix. Kition displays a Shell command approval card.
- Allow once — retry the exact command for this approval
- Always allow — available only when the runtime suggests a prefix; sends a remembered-prefix decision
- Deny — tell the Agent not to run the command and to continue without it when possible
Heads up
Read the full command, working directory implications, arguments, redirects, and shell operators before approving. A safe-looking prefix can still permit risky later arguments.
Execution-policy contract
The client exposes runtime helpers for command-prefix rules with decisions such as allow, prompt, and forbidden. The public Desktop UI does not expose a general execution-policy editor or the on-disk rule path.
An Always allow decision is sent back with the pending tool-call ID. A different command that is not covered by a remembered rule should request approval again.
There is no universal tool permission editor
Kition 0.1.41 does not ship Settings → Agent → Permissions, a workspace .kition/permissions.json, or general allow/ask/deny rules for every document, table, browser, MCP, and filesystem tool.
Do not assume reads are always silent, writes always ask, or destructive tools always deny. Actual availability and governance come from the runtime and feature-specific flows.
Feature-specific review controls
- Table write plans can require an explicit Apply action
- Document and patch tools can expose changed-file paths and previews
- Whiteboard proposals can be shown before the final patch is accepted
- The Agent can request additional user input before continuing
- The Stop button aborts the current stream but does not undo completed actions
Practical safety rules
- Back up the workspace before broad edits
- Use least-privilege provider, website, database, and external-service accounts
- Treat browser pages and external tool output as untrusted prompt input
- Verify filesystem, table, browser, and remote-system changes at the source
- Deny commands you cannot explain and ask for a safer alternative
Implementation sources
Related pages
Agent tool calls
Read the actual runtime tool names, availability signals, inputs, outputs, errors, and changed-file results shown in the Agent timeline.
Plans, previews, and apply confirmation
Distinguish informational Agent plans from the table write plans and previews that have an explicit Apply step in Kition 0.1.41.
Browser context for the Agent
Open pages in Kition’s embedded desktop browser, sign in manually, and let the Agent read supported page context without promising full browser automation.
