Security & permissions
Control tool execution, approvals, autonomy presets, and session-specific grants in the desktop app.
What the permission tab controls
Open the desktop app Settings → Security & Permissions tab to govern automated tool execution. The policy is applied by the runtime before a tool runs; it is not a Windows permission dialog and it does not replace operating-system security.
Each tool is classified into a capability category and evaluated as allow, ask, or deny. The policy badge beside the settings tab shows the active autonomy mode.
Choose an autonomy preset
| Preset | Behavior |
|---|---|
| Strict Control | Ask before shell, Python, file writes, file deletion, network access, storage, and custom tools. RAG and reasoning remain allowed. |
| Balanced (Standard) | Allow file writes, network, storage, RAG, and reasoning; ask before shell, Python, file deletion, and custom tools. |
| Full Autonomy | Allow every capability without interactive approval. |
Selecting a preset fills the capability matrix. The selection is only staged in the settings form until you choose Apply Security Policy.
Customize individual capabilities
| Capability | Examples | Available policies |
|---|---|---|
| Terminal & Shell | execute_command, shell tools | Ask, Auto-Execute, Block |
| Python Sandbox | run_sandboxed_script | Ask, Auto-Execute, Block |
| File & Artifact Writes | save_artifact, write_file | Ask, Auto-Execute, Block |
| Destructive File Deletion | delete_artifact, clear_artifacts, clean_sandbox | Ask, Auto-Execute, Block |
| Web Search & Network | web_search, read_web_page | Ask, Auto-Execute, Block |
| Vector Memory & RAG | query_knowledge_base, document search | Ask, Auto-Execute, Block |
| Plugin Storage | ctx.storage.get / set | Ask, Auto-Execute, Block |
| Reasoning Scratchpad | record_reasoning_step | Ask, Auto-Execute, Block |
| Custom Dynamic Plugins | user-installed custom tool handlers | Ask, Auto-Execute, Block |
When a tool requires approval
- AI Plate classifies the requested tool and reads the policy for its capability.
- With Auto-Execute, the tool runs immediately. With Block Action, it is refused.
- With Ask for Approval, AI Plate shows the tool, arguments, capability, and risk level for an interactive decision.
- Approving once permits that request. Choosing “Always Allow this Session” adds that exact tool to the current session whitelist.
- An unanswered approval expires after three minutes and is denied.
Review and revoke session grants
The Active Session Whitelist section lists tools approved with “Always Allow this Session”, grouped by chat session with their capability, risk level, and grant time.
- Revoke removes one tool from one session.
- Clear Session removes all grants for a selected session.
- Clear All removes grants across every session.
- Session grants are temporary in-memory permissions; they are separate from the saved global policy and are cleared when the security policy is reset.
Persistence and security boundaries
The global mode and capability choices are stored in the application SQLite metadata and restored when AI Plate starts. Reset to Defaults restores Balanced and clears the session whitelists.
Implementation sources
Paths in your AI Plate source checkout:
ui/index.htmlui/app.jscore/security-manager.tscore/types.tselectron/ipc-bridge.ts
