LatentWorkUsing LatentWork
Permissions and approvals
The agent works freely inside your workspace, but asks before anything riskier: most shell commands, going online, sensitive files, and folders outside the workspace.
When the agent asks
A request appears in a panel above the message box, and the task waits until you answer. The panel shows what kind of request it is (Permission), what it covers (Scope), such as the command or the files, and a Details section with everything the agent sent.
| Panel title | The agent wants to |
|---|---|
| Run a shell command? | Run a command in the workspace. Scope shows the command. |
| Modify files? | Change a protected file, such as a credentials or configuration file. |
| Read files? | Read a file that holds passwords, keys or other credentials. |
| Access an external folder? | Read or change something outside the workspace folder. |
| Start a subtask? | Hand part of the work to another agent. |
| Approve …? | Anything else, named after the permission, for example Approve webfetch? (the agent wants to open a web page). |
| Doom Loop Detected | The agent keeps repeating the same step. Deny to stop it, or allow it to keep trying. |
Your choices
| Choice | Effect |
|---|---|
| Deny | Refuses the request. Any other requests the task is waiting on are refused too. |
| Allow once | Allows this one request. The next similar request asks again. |
| Allow for session | Allows this request and remembers it for the rest of the task, so matching requests go through without asking. Other tasks still ask. |
The panel's own advice: allow once for this request, or allow for session when you trust this scope. A request allowed for the session is remembered only while LatentWork is running.
What needs approval
These are the agent's default rules.
Asks first
- Shell commands, except a few that only look at files without changing anything.
- Going online: fetching web pages, web searches and other network access.
- Reading secrets: files that hold passwords, keys and other credentials.
- Editing protected files: credentials, project configuration files, and LatentWork's own settings in the workspace.
- Anything outside the workspace folder, unless you authorized that folder.
- Repeating itself: the agent keeps repeating the same step.
Give access to another folder
If a workspace often needs files from another folder, authorize it in Settings → Permissions instead of approving each request. The agent can then read and edit it without asking, in that workspace only. See Folders outside the workspace.
Your own terminal
Approvals apply to the agent. Commands you type yourself in the Terminal panel run straight away. See The terminal.