Approved command types
What "Always allow" approves, and how to review the types you approved.
"Always allow" approves a command type: the program and the one to three words after it that say
what it does, such as systemctl restart, net user or Restart-Service. It is yours alone, with all
your colleagues, on every host and on the runner; anyone else is still asked. A line made of several
commands is split into its pieces and only the types still missing are asked: in
systemctl restart nginx && systemctl status nginx that is systemctl restart. sudo makes a type
of its own (sudo systemctl restart), and writing a file with > is the type >.
Some commands cannot be read to the end, such as $(...), bash -c, a script, a command run through
ssh or one that reads a key or password file: they have no type to remember and are approved once
each time, as are MCP tools.
Review your types at Account → Approved command types: turn one off and your colleagues ask again, or remove it. An administrator can turn off one of your types for good: it is then approved once each time, until an administrator turns it on again. Your types stay when you delete a colleague or change a credential, because they approve a kind of command, not an account.