What it stops
Known irreversible commands are stopped by rule: a force-push, DROP TABLE, deleting outside build folders, a production deploy, a payment, sending an email. Everything else that can change something goes to TypeSafe's judgment model, which says how sure it is that the call cannot be undone. Read-only calls are not checked at all, and a tool FlockTab does not know counts as a write.
Allowing a call means saying nothing: the harness's own permission prompts still apply as they always do. Agent Guard only adds a stop on top.
Turn it on
- Open Control, Agent Guard and pick a mode for each Agent, or one for all of them. Each change saves at once and applies from the Agent's next launch.
- To start every new Agent the same way, set Agent Guard for new Agents in Settings.
- Start in Watch for a day, look at what it would have stopped, then move to Ask first or Deny.
tab policy my-agent --guard ask # one Agent
tab policy --all --guard watch # every Agent at once
tab policy my-agent --guard-level strictThe four modes
| Mode | What happens to a call it flags |
|---|---|
| Off | Nothing is checked. The default. |
| Watch | Judged and recorded, never stopped. Use it to see what the guard would catch. |
| Ask first | You confirm it in the terminal before it runs. |
| Deny | Refused, and the agent is told why. For Agents nobody is watching. |
How sensitive
Sensitivity decides what counts as a call to stop. Balanced is the default.
| Level | What it stops |
|---|---|
| Relaxed | Stops only what surely cannot be undone, by rule: a force-push, deleting outside build folders, dropping a database, a production deploy, a payment, an email. Jev flags a call only when it is 80% sure it cannot be undone. For trusted agents you watch anyway. |
| Balanced | Everything Relaxed stops, calls Jev is 50% sure cannot be undone, and calls outside the project: ssh, sudo, credentials, a database on another host, the sandbox off. Everyday project work rarely asks. |
| Strict | Also any git push, any delete, a web request that sends data, a database or cloud write, and an MCP tool that creates, changes or sends. Jev flags from 30%. For new or unattended agents, or anything near production. |
Calls outside the project
With the guard on, it also stops calls outside the project (ssh, sudo, keys): ssh, scp or rsync to another machine, sudo, kubectl exec, a database on another host, reading private keys or credentials files, or the harness turning its own sandbox off. Watch records these calls, Ask holds them until you confirm, Deny refuses them. It is on unless you turn it off (tab policy my-agent --reach off, or the checkbox beside the mode), and Relaxed never checks it. When only the model thinks a call leaves the folder (a grep or a cd elsewhere), it asks only if the call may also be hard to undo.
Your own rules
Tune it per Agent with patterns. A flagged pattern is always stopped; a trusted one always goes through, before every rule. Case and repeated spaces do not matter, and * matches anything. A trusted pattern with * never matches text that chains or redirects (; && | > and the rest), so npm test* never trusts npm test; rm -rf ~. Up to 40 of each.
tab policy my-agent --flag "*prod*"
tab policy my-agent --trust "ssh staging-bastion*"
tab policy my-agent --forget "*prod*"When a call is held
In Deny (and in Ask first where the harness cannot ask), a flagged call waits 45 seconds for a person. Allow it in that time and it runs there and then; otherwise it is refused and stays on the list.
tab guard # what is waiting, and what was blocked
tab guard allow <id> # propose letting it run once: confirm in the console
tab guard allow <id> --always # also trust that exact command on this Agent
tab guard deny <id> # keep it blockedAn allow from the terminal is only a proposal: it prints a link and a code, and the call is allowed when you confirm it in the console, signed in. The agent can reach its own terminal, but not your browser session. The Review tab of Agent Guard lists every held call and what people decided.
Learned from your answers
Say no to Agent Guard's question in Claude Code and it flags that exact command on that Agent at once. Say yes and nothing changes until you trust it on the Learned tab of Agent Guard. Your own flagged and trusted patterns are never touched. After 40 learned rules an Agent stops learning until you undo some.
The loop watch
A separate switch on the same page. It looks at the last ten tool calls every three calls and spots an agent repeating itself without progress, or polling the same check on a timer. Watch records it; pause also closes the tab, the same as tab close, once it has been stuck two checks in a row (--pause-after 1-5 changes that).
tab policy my-agent --loops pause --pause-after 3What leaves your machine
- Each checked call (the command and its arguments, including the text of a file write) goes to TypeSafe's judgment model with keys, tokens and passwords removed. Only a 200-character summary is kept.
- Tool output never leaves the machine.
- If flocktab.com cannot be reached, the rules still run on your machine; only the judgment is skipped.
Which agents
tab claude, tab codex, tab gemini, tab agy, tab opencode, tab goose, tab cline, tab grok, tab kimi and tab pi. Codex, OpenCode, Goose, Cline and Kimi Code cannot ask from a hook, and nobody can answer a headless run such as -p: there the agent is told to ask you instead. Codex asks once to trust FlockTab's hooks (choose Trust all and continue); until then its calls run unchecked, and tab says so.
Plans and limits
| Plan | Agent Guard |
|---|---|
| Solo | Not included |
| Team | Rules always, and 20,000 judged calls a month |
| Fleet | Rules always, and 200,000 judged calls a month |
The guard and the loop watch share the month's judgments (calendar month, UTC). Past them the rules keep working and judgment resumes on the 1st; every console page says so while it lasts.