Each agent has an identity and is approved once per computer for chosen project folders—not once per chat. The owner sees the grant, can revoke it, and keeps irreversible effects behind an explicit check.
Reversible by default: trash, snapshots, branchesOwner decides irreversible effects
Five risk classes
01Readautomatic within the grantAuto
02Reversible writeauto-snapshotAuto
03Runbuild + test in sandboxAuto
04Networkallowlisted destinationsAuto
05Irreversibledelete, publish, deploy, send, push to main, payments, secretsTouch ID
After untrusted web, email, or foreign-file content, Network and Irreversible need approval again.
Identity + project scope
A narrow grant that stays understandable.
agent identity
Each agent receives an identity. Approval is once per computer and is scoped to the chosen project folders, not to a chat transcript.
scope
reviewed plan
One approval can cover a reviewed plan shown as a plain summary plus a diff, so the owner can see the intended work before it starts.
review
listed grants
Grants are listed and revocable. The owner can change the route rather than relying on an invisible background permission.
revoke
Reversible by default
Progress without hiding the exit.
Automatic inside a grant
Four bounded classes
Read, reversible write with an auto-snapshot, sandboxed build/test runs, and network to allowlisted destinations can proceed without repeated prompts while they stay inside the grant.
Owner authentication every time
Irreversible is never inherited
Delete outside snapshots, publish, deploy, send, push to main, payments, and secrets always require the owner’s Touch ID or system password for every agent at every level.
Custody + closure
Actions remain visible to the owner.
secrets
Agents never see secrets.
isolated
journal + undo
Every action is logged per agent, with undo for reversible work. Completion still needs a receipt with evidence.
record
OFF + PANIC
OFF and PANIC are owner-only controls.
owner
refusal
If work cannot proceed, the refusal says what is needed next so the agent can re-orient rather than loop.
next step
Current scope
An adopted design, still in active development.
This is the DotBridge Beta security design. It describes the intended owner controls and does not claim certification, universal protection, or a complete support matrix. Linux, Windows through WSL, and macOS are planned.