Orlok

Approved command types

What "Always allow" approves, and how to review the types you approved.

"Always allow" approves a command type: the program and the one to three words after it that say what it does, such as systemctl restart, net user or Restart-Service. It is yours alone, with all your colleagues, on every host and on the runner; anyone else is still asked. A line made of several commands is split into its pieces and only the types still missing are asked: in systemctl restart nginx && systemctl status nginx that is systemctl restart. sudo makes a type of its own (sudo systemctl restart), and writing a file with > is the type >.

Some commands cannot be read to the end, such as $(...), bash -c, a script, a command run through ssh or one that reads a key or password file: they have no type to remember and are approved once each time, as are MCP tools.

Review your types at Account → Approved command types: turn one off and your colleagues ask again, or remove it. An administrator can turn off one of your types for good: it is then approved once each time, until an administrator turns it on again. Your types stay when you delete a colleague or change a credential, because they approve a kind of command, not an account.