Permissions matrix
What each approval level does with each kind of action, what the approval buttons remember, and which turns get stricter rules.
The detailed version of Permissions and the stop line. The matrix describes a turn you started yourself. Turns started by routines, webhooks, channel messages or other people follow stricter rules, covered further down.
The matrix
- Asks: a card appears and the bot waits for you.
- Goes ahead: no card. The step still shows in the chat.
- Stop line: a stop-line card, even on Full access. On Hermes and other ACP engines, only for what the engine asks Murage about. When Murage can tell where the action lands, it offers Allow for this task as well as Allow once.
| Action | Ask | Auto | Full access | No limits |
|---|---|---|---|---|
| Read files | Asks | Goes ahead | Goes ahead | Goes ahead |
| Write in the bot's own Murage folders (its workspace, thread folder and memory) | Goes ahead | Goes ahead | Goes ahead | Goes ahead |
| Edit files in its working folder | Asks | Goes ahead | Goes ahead | Goes ahead |
| Delete inside its working folder | Asks | Goes ahead, but rm -rf-style deletes ask | Goes ahead | Goes ahead |
| Delete outside its folder | Stop line | Stop line | Stop line | Goes ahead |
| Ordinary shell commands | Asks | Goes ahead | Goes ahead | Goes ahead |
Other commands that look destructive (shutdown, reboot) | Asks | Asks | Goes ahead | Goes ahead |
| Web and network requests | Asks | Goes ahead | Goes ahead | Goes ahead |
| Replies in an existing conversation | Asks | Goes ahead | Goes ahead | Goes ahead |
| Messaging someone new | Stop line | Stop line | Stop line | Goes ahead |
| Posting publicly | Stop line | Stop line | Stop line | Goes ahead |
| Paying | Stop line | Stop line | Stop line | Goes ahead |
| Reading your keys and passwords | Asks | Asks | Asks | Asks |
| Using your screen on this computer | Asks | Goes ahead after a one-time warning. Destructive or sensitive steps still ask | Goes ahead | Goes ahead |
| Making an image | Asks | Asks | Asks | Asks |
| Setup requests (installing a skill, proposing a routine, trusting a folder) | Asks | Asks | Asks, unless you turn on the setup switch | Asks, unless you turn on the setup switch |
| Connecting an app | Asks | Asks | Asks | Asks |
| Connected-app and MCP tools | Asks | Goes ahead | Goes ahead | Goes ahead |
| Contacting another bot, with Ask me before contacting other bots on | Asks | Asks | Goes ahead | Goes ahead |
| Questions the bot asks you | Reach you | Reach you | Reach you | Reach you |
Some notes on the table:
- Whether an engine raises a request at all for reading, editing or fetching is partly up to the engine. Some engines read and edit files in the bot's working folder without asking, whatever the level.
- A connected-app or MCP tool that pays, deletes, posts publicly or messages someone new hits the stop line like any other action.
- "Keys and passwords" covers things like
.envfiles, SSH keys, cloud credential files, the keychain and shell profile files. No level turns this off.
The stop line
The stop line covers three kinds of action:
- Deleting outside the bot's folder. The folder counts as the turn's working folder, the bot's own Murage workspace and thread folder, and temp folders. Your home folder, a disk root and folders like Documents, Desktop and Downloads never count as the bot's folder. Also covered: deleting mail, files or records through a connected app, dropping or emptying a database table, irreversible git (force push, deleting a remote branch,
reset --hard) and wiping a disk. - Paying. Charges, payouts, refunds, purchases and transfers, through a connected app or a direct call to a payment service.
- Messaging someone new or posting publicly. A new person or group, a social post, a mass email or broadcast, or an issue, pull request, comment or release on GitHub.
When Murage can't tell where a delete lands or who a message goes to, it stops for you.
What is never "new"
- Messages to you, and to your own linked Telegram, Slack and Discord accounts.
- The person a channel conversation is with.
- Anyone the bot has already sent a message to. Once you allow a message, its recipients are remembered for that bot, on this computer.
- A reply in an existing conversation. Only people the bot adds to it are new.
- A GitHub repository you've already allowed a post in.
The stop line applies on Ask, Auto and Full access. No limits turns it off, but the key guard stays on even there.
The approval buttons
- Allow once: this action, this time.
- Allow for this task: offered on stop-line cards. Covers the same kind of action in the same place: the same folder (and everything inside it), the same recipients, or the same payee. It lasts until the conversation is reset, Murage restarts, or 12 hours pass, whichever comes first. You can also give it in chat by naming the place yourself, for example "you can delete anything in ~/Projects/site today". It only works on turns you're present for.
- Always allow: offered in the desktop app. It's remembered for that bot.
- On a stop-line card it's tied to that folder, recipient or payee, never the tool as a whole.
- For a shell command it's tied to the program, such as
git, not the whole shell. Commands with pipes, variables or other shell syntax don't offer it. - Every grant is listed in Bot settings → Permissions → Always allowed, where you can remove it.
- On other cards, including connected-app tools, it covers the whole tool.
- It never covers destructive or sensitive actions, never covers screen control, and never answers for a turn nobody is watching.
- Always allow this exact command here: offered on command cards. That exact command, in that folder, on that engine, and nothing else. It isn't offered for a command that looks destructive or touches keys.
- Always allow for this routine: offered on cards a routine raises. The same command or place, for that routine only, on every later run.
- Deny: the bot is told you denied it and can try another way.
- Cancel turn: stops the bot's current turn.
Some cards differ: skill requests offer Enable or Update and Deny, routine proposals Confirm and Cancel, and image cards Allow and Deny.
From Telegram, approval cards offer Approve once, Allow for this task (on stop-line cards) and Deny. Always allow is desktop only. See Approve from your phone.
Turns nobody is watching
Full access only covers turns you started. Everything else is judged more strictly:
- Routine runs use the routine's own level (Advanced → Approvals for this routine). A routine you haven't set follows the bot's level when each run starts. Reading your keys always asks.
- Webhook turns and channel messages are treated as unattended. Auto and Always allow don't answer for them, so each permission waits for you. Writing in the bot's own Murage folders still goes ahead.
- Your own messages from Telegram, Slack and Discord are unattended too, unless the bot is on Full access with the channel switch on (below).
- A conversation with someone other than you in a channel runs on Ask, with no remembered grants, no computer, no browser and no connected apps.
The two Full access switches
In Bot settings → Permissions → Approvals, two switches apply only when the default is Full access or No limits. Both are off until you turn them on, and both can only be changed in the desktop app.
- Also skip approvals for my messages from Telegram, Slack and Discord. Messages from anyone else and webhooks still ask.
- Also approve setup requests: installing skills, proposing routines and trusting folders. Connecting an app still asks, because you sign in to it yourself.
Desktop-only levels
Full access and No limits can only be turned on in the Murage desktop app, not from the phone web app or a script. The first time you pick either for a bot, you confirm a warning. It's remembered after that. Picking Auto, Full access or No limits for a bot that uses this computer's screen shows a separate warning first.