Modes and what runs without asking
The four modes of a colleague profile, which commands run at once, which ones ask, and which ones are always refused.
Every colleague profile has a mode: how the colleagues that use it may run commands. An administrator picks it when creating the profile, and decides who may use it by granting the profile in Admin → People.
The four modes
| Mode | Commands | MCP tools | Who it is for |
|---|---|---|---|
| Deny | None: chat and wiki only | None | People who should not delegate operations |
| Ask | Read-only commands and your approved command types run at once; the others wait for your approval | Read-only tools run at once; the others follow the server's tool policy | Everyday operations, with a person deciding every change |
| Full access | Run without approval; catastrophic commands are refused | Run without approval, unless the server asks for every tool | People who would run the same commands themselves, on systems they know well |
| Yolo | Run without approval, catastrophic ones too | As in full access | Test machines only |
The runner and the office's MCP servers are available in every mode except deny.
Full access and yolo have no human in the loop. A colleague can change or break a server without anyone approving, and text it reads in a document or in a command's output can steer it. Grant these profiles only to people who would run those commands themselves.
What counts as read-only
In ask mode a command runs at once when every piece of it only reads state and reveals no secret. Orlok recognises a list of diagnostics, and checks the arguments of the ones that can also write.
Linux and the runner (POSIX shell), for example:
- files and text:
cat,head,tail,less,grep,wc,sort,ls,stat,find,awkandsedused only to print; - system:
uname,uptime,df,du,free,ps,top,lsblk,lscpu,id,whoami; - network:
pingwith a count of at most 20,dig,nslookup,host,ss,netstat,traceroute,mtr,ipto show addresses, routes and links,curlfor a plain GET or HEAD; - services and containers:
systemctl status,show,list-unitsand similar,journalctl --no-pagerwith a line count or a time range,docker ps,logs,inspect,images,stats --no-stream; - Proxmox and storage:
pvesh get,zpool,zfs, and the read commands ofqmandpct; - JSON and YAML:
jq,yq.
Windows (PowerShell), for example:
- every
Get-*cmdlet,Test-Path,Test-Connection,Test-NetConnection,Resolve-DnsName; - pipeline helpers:
Where-Object,Select-Object,Sort-Object,Group-Object,Measure-Object,ForEach-Object,Format-Table,Format-List,ConvertTo-Json; - classic tools:
ipconfig,systeminfo,tasklist,whoami,hostname,netstat,nslookup,tracert,ping -n,gpresult,dcdiag.
A pipeline such as ps aux | grep nginx | head runs at once because each piece is read-only.
What asks
In ask mode, everything else waits for your approval. For example:
- anything that changes state:
systemctl restart,Restart-Service,apt install,rm,Remove-Item; - writing a file with
>or>>; - anything run through
sudo; - a read-only command pointed at a sensitive file: SSH keys and the
.sshfolder,/etc/shadowand/etc/sudoers,.pemand.keyfiles,.envfiles,.pgpass,.htpasswd, cloud and Docker credentials.
When you allow a command "always", you approve its command type, not just that line: see Approved command types.
What can only be approved once
Some commands cannot be read to the end, so there is no type to remember and "Always allow" is not offered:
$(...),bash -c,sh -c,powershell -Command, and scripts in general;- a command run through
sshfrom the runner; - a command that reads a sensitive file;
- PowerShell lines built from variables,
foreach,try, or .NET method calls such as.AddDays(); - MCP tools that are not read-only;
- a command type that an administrator turned off for you.
Prefer plain commands. A colleague in ask mode is told to prefer plain commands to scripts, because each script needs your approval every time. If you find yourself approving the same long script again and again, ask the colleague to split it into plain commands.
What is refused
In ask and full access, a short list of catastrophic commands is refused, with no way to approve them. Only yolo runs them:
- on Linux: removing
/,mkfs,wipefs,ddorshredon a device,chmodorchownon the whole filesystem; - on Windows:
Format-Volume,Clear-Disk,diskpart, deleting boot entries withbcdedit, wiping withcipher /w, deleting shadow copies withvssadmin, clearing event logs withwevtutil, removing a drive root,Remove-ADDomain,Remove-ADForest.
Everything destructive that is not on this list asks for approval in ask mode.
MCP tools
Each MCP server has a tool policy, set by an administrator in Admin → Operations:
- Read-only tools run immediately, the others wait for approval: the default. In full access and yolo the others run too;
- Every tool waits for approval: in every mode, full access and yolo included;
- Every tool runs without approval: in every mode but deny, tools that change or delete data included.