Orlok

Modes and what runs without asking

The four modes of a colleague profile, which commands run at once, which ones ask, and which ones are always refused.

Every colleague profile has a mode: how the colleagues that use it may run commands. An administrator picks it when creating the profile, and decides who may use it by granting the profile in Admin → People.

The four modes

Mode Commands MCP tools Who it is for
Deny None: chat and wiki only None People who should not delegate operations
Ask Read-only commands and your approved command types run at once; the others wait for your approval Read-only tools run at once; the others follow the server's tool policy Everyday operations, with a person deciding every change
Full access Run without approval; catastrophic commands are refused Run without approval, unless the server asks for every tool People who would run the same commands themselves, on systems they know well
Yolo Run without approval, catastrophic ones too As in full access Test machines only

The runner and the office's MCP servers are available in every mode except deny.

Full access and yolo have no human in the loop. A colleague can change or break a server without anyone approving, and text it reads in a document or in a command's output can steer it. Grant these profiles only to people who would run those commands themselves.

What counts as read-only

In ask mode a command runs at once when every piece of it only reads state and reveals no secret. Orlok recognises a list of diagnostics, and checks the arguments of the ones that can also write.

Linux and the runner (POSIX shell), for example:

  • files and text: cat, head, tail, less, grep, wc, sort, ls, stat, find, awk and sed used only to print;
  • system: uname, uptime, df, du, free, ps, top, lsblk, lscpu, id, whoami;
  • network: ping with a count of at most 20, dig, nslookup, host, ss, netstat, traceroute, mtr, ip to show addresses, routes and links, curl for a plain GET or HEAD;
  • services and containers: systemctl status, show, list-units and similar, journalctl --no-pager with a line count or a time range, docker ps, logs, inspect, images, stats --no-stream;
  • Proxmox and storage: pvesh get, zpool, zfs, and the read commands of qm and pct;
  • JSON and YAML: jq, yq.

Windows (PowerShell), for example:

  • every Get-* cmdlet, Test-Path, Test-Connection, Test-NetConnection, Resolve-DnsName;
  • pipeline helpers: Where-Object, Select-Object, Sort-Object, Group-Object, Measure-Object, ForEach-Object, Format-Table, Format-List, ConvertTo-Json;
  • classic tools: ipconfig, systeminfo, tasklist, whoami, hostname, netstat, nslookup, tracert, ping -n, gpresult, dcdiag.

A pipeline such as ps aux | grep nginx | head runs at once because each piece is read-only.

What asks

In ask mode, everything else waits for your approval. For example:

  • anything that changes state: systemctl restart, Restart-Service, apt install, rm, Remove-Item;
  • writing a file with > or >>;
  • anything run through sudo;
  • a read-only command pointed at a sensitive file: SSH keys and the .ssh folder, /etc/shadow and /etc/sudoers, .pem and .key files, .env files, .pgpass, .htpasswd, cloud and Docker credentials.

When you allow a command "always", you approve its command type, not just that line: see Approved command types.

What can only be approved once

Some commands cannot be read to the end, so there is no type to remember and "Always allow" is not offered:

  • $(...), bash -c, sh -c, powershell -Command, and scripts in general;
  • a command run through ssh from the runner;
  • a command that reads a sensitive file;
  • PowerShell lines built from variables, foreach, try, or .NET method calls such as .AddDays();
  • MCP tools that are not read-only;
  • a command type that an administrator turned off for you.

Prefer plain commands. A colleague in ask mode is told to prefer plain commands to scripts, because each script needs your approval every time. If you find yourself approving the same long script again and again, ask the colleague to split it into plain commands.

What is refused

In ask and full access, a short list of catastrophic commands is refused, with no way to approve them. Only yolo runs them:

  • on Linux: removing /, mkfs, wipefs, dd or shred on a device, chmod or chown on the whole filesystem;
  • on Windows: Format-Volume, Clear-Disk, diskpart, deleting boot entries with bcdedit, wiping with cipher /w, deleting shadow copies with vssadmin, clearing event logs with wevtutil, removing a drive root, Remove-ADDomain, Remove-ADForest.

Everything destructive that is not on this list asks for approval in ask mode.

MCP tools

Each MCP server has a tool policy, set by an administrator in Admin → Operations:

  • Read-only tools run immediately, the others wait for approval: the default. In full access and yolo the others run too;
  • Every tool waits for approval: in every mode, full access and yolo included;
  • Every tool runs without approval: in every mode but deny, tools that change or delete data included.