MURAGE
How it worksFeaturesSolutionsUse casesComparePricingDocs
DownloadDownload
MURAGE

An AI Chief of Staff and a team that does the work. Free and open source, from Ferrox Labs.

Product

  • Features
  • How it works
  • Engines and apps
  • Privacy and security
  • Pricing
  • Murage Cloud
  • Download
  • Changelog
  • FAQ

Solutions

  • Solopreneurs
  • Founders and startups
  • Agencies
  • Ecommerce
  • Small business
  • Creators and educators
  • Developers
  • SaaS
  • Nonprofits
  • Consultants and freelancers
  • Customer success teams
  • Legal and professional services
  • Small teams
  • Sales teams
  • Operations managers
  • Industries
  • Use cases
  • Build your team

Compare

  • vs Claude Code
  • vs Codex (ChatGPT Work)
  • vs Claude (Cowork)
  • vs Paperclip
  • vs OpenClaw
  • vs Hermes Agent
  • vs Manus
  • vs Genspark
  • vs n8n
  • vs Zapier
  • vs Grok Bot
  • vs Viktor
  • vs Lindy
  • vs Tasklet

Resources

  • Docs
  • Team library
  • Skill library
  • AI Chief of Staff
  • How we test
  • Limits
  • Switching to Murage
  • Open source
  • Blog
  • Release notes

Company

  • About
  • Partners
  • Enterprise
  • Contact
  • Privacy
  • Terms
  • Cookies
© 2026 Ferrox Labs. Murage is open source under AGPL-3.0.
Blog

By Sean Donahoe·Sep 24, 2026·2 min read

The stop line: how Murage keeps you in charge

Murage bots can run fast, but some actions stop for you on every level except one: paying, deleting outside their folder, messaging someone new and posting publicly. How the stop line works, and the one level that removes it.

Cover image for The stop line: how Murage keeps you in charge

Every AI agent product has to answer the same question: how much should it do without asking?

Ask too often and nobody uses it. You approve forty small steps to get one report, and you go back to doing it yourself. Ask too rarely and one bad instruction, or one clever email the bot reads, ends with a payment you did not make or a message you would never have sent.

Murage answers it with two things: permission levels you set per bot, and a stop line that holds even when a bot is running fast. Murage 0.1.59 made the stop line part of every permission check Murage receives.

Four levels, per bot

Each bot has its own permission level. You set it, and you can change it at any time.

  • Ask is where every new bot, task and imported team starts. The bot asks before each action it tells Murage about.
  • Auto keeps going on its own, but still asks about anything destructive and about questions it has for you.
  • Full access keeps going without asking, but stops at the stop line and before reading your keys and passwords. You can only set it on the desktop.
  • No limits does anything without asking, except reading your keys and passwords. It has no stop line for your own chats with that bot. You can only set it on the desktop, after a warning.

Most people run most bots on Ask or Auto, and move a trusted bot to Full access for a specific kind of work.

What the stop line catches

The stop line is a short list of actions that stop and ask in Ask, Auto and Full access:

  • Paying. Anything that spends money, including payment apps like Stripe and PayPal.
  • Deleting outside the bot's own folder. A bot can tidy its own workspace. Your files, and records in your connected apps, are different.
  • Messaging someone new. An email, a DM or a message to a person the bot has not been talking to.
  • Posting publicly. A social post, a comment, or a first post in a public place.

These are the actions that are hard to undo and that other people see. That is the whole reasoning behind the list.

Messages to you, to your own linked accounts, and replies to the person a channel conversation is already with do not stop. Neither do replies to someone the bot has already written to in that thread, because they are not "new". If you want every single reply checked, keep that bot on Ask.

What you can say when it stops

When a bot hits the stop line, you see a card with exactly what it wants to do and where. You can answer:

  • Allow once: just this action.
  • Allow for this task: the same folder, person or payee, until this job ends.
  • Always allow: from now on, for that specific folder, payee or recipient. Never for the tool as a whole.
  • Deny, or cancel the turn.

"Allow for this task" is the one people use most. It means you can say yes to a bot emailing the five people on this proposal without saying yes to it emailing anyone, forever.

You can answer from the app, from the Inbox, or from Telegram, where stop-line cards show Approve once, Allow for this task and Deny. Ordinary requests can also be approved from the menu bar.

What it covers on each engine

Bots in Murage run on different engines: Claude Code, Codex, Hermes, Pi, the bundled Fuigo, and others. Under Full access, each engine sends its permission asks to Murage, and the stop line judges them, so you do not have to learn each tool's own permission settings. The stop line can only judge what it is asked about, so what it covers depends on the engine. On Claude Code and Codex, the stop line also covers tools from MCP servers you add. On Hermes and other ACP engines, Ask and the stop line cover only what the engine asks Murage about: Hermes asks before shell commands and file edits, but not before MCP or connected-app tools.

Runs started by a webhook are handled more carefully still: they ask, whatever level the bot has. A routine runs at the level you give it, and a routine you haven't set follows its bot. Since 0.1.60, Pi bots ask Murage first as well.

No limits, and why it exists

No limits removes the stop line for your own chats with that bot. It exists because some people have a bot doing work where stopping would defeat the point, on accounts where they accept the risk: a sandboxed test account, a scratch folder, a throwaway environment.

It is deliberately hard to switch on by accident. It is only available on the desktop, not from your phone. It shows a warning the first time you set it for a bot. And it still asks before reading your keys and passwords.

If you are not sure whether you need No limits, you do not.

What it is and what it is not

It is worth being precise, because guardrails are easy to oversell.

The stop line is an automated check on the actions a bot tries to take. It covers a lot of ground: deletes and sends in connected apps, payment apps, first posts on GitHub, and file deletes made through the Finder, code or Windows command lines. But it is a classifier, not a sandbox. It can miss something it does not recognize. It sits alongside other protections rather than replacing them:

  • House Rules that every bot reads first, which by default tell bots to treat emails and web pages as information, not orders.
  • Ask mode for bots you have not built trust with yet.
  • Access you grant per bot. A bot with no email connection cannot email anyone, stop line or not.

Our terms of service are plain about this too: you are responsible for what your bots do and for what you approve.

Why this design

We wanted a line that is easy to explain. "It stops before it pays, deletes outside its folder, messages someone new or posts publicly" is something you can hold in your head, and check against what you see.

That clarity is what makes it reasonable to let a bot run fast. You can give a research bot Full access and let it read, search, compare and write all afternoon, knowing it will stop and ask before any of the four things that matter, within what its engine asks Murage about.

The approvals and stop line feature page has the full details, and privacy and security covers the rest of the security model. Download Murage and look at a bot's Permissions tab to see the four levels for yourself.

Sean Donahoe, founder of Ferrox Labs, which makes Murage.

Checked against Murage 0.1.60.

Keep reading

Sep 16, 2026

Can I let AI send emails? How approvals and the stop line work

Yes, if you decide where the line is. How Murage's four approval levels and its stop line let a bot draft all day, reply where you allow it, and stop before writing to anyone new.

Sep 24, 2026

2,237 skills, and Skill Guard

Murage ships with a library of 2,237 skills your bots can use, and a scanner that checks every skill before a bot can switch it on. What skills are, where they come from, and how Skill Guard works.

Sep 27, 2026

What's new in Murage 0.1.60

Backups that work from start to finish on Mac, Windows and Linux, off-site copies to your own server, an approval level per routine, Always allow this exact command, Snooze, team management and About me.

Try the thing you just read about.

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

Free · Download Murage

No account needed · Runs on the AI plan you already pay for