---
title: Safe Mode
---

# Safe Mode

## What it is

**What it is:** A Windows-Safe-Mode-style boot mode for Omniscio. When you turn
it on, Omniscio restarts and comes up with **all of its automatic, background behavior switched
off** — nothing runs on its own — so you can look at what's going on and fix things when
something feels broken. You stay in full manual control the whole time.

## Where to find it

### What you see

- **A Safe Mode launcher.** In the installed app there is a separate **"Omniscio
  — Safe Mode"** shortcut (its own shield icon) sitting in the app's install folder. Double-click
  it and Omniscio opens in Safe Mode. Because it's a separate launcher, it works **even when the
  normal app is too broken to open** — that's the whole point. (It's kept in the install folder
  rather than the Start Menu/Desktop to avoid clutter; the quickest way to reach it is to
  right-click your normal Omniscio shortcut → **Open file location**.)
- **A "Restart in Safe Mode" button** inside **Settings → Diagnostics**, for when the app
  _is_ open and you want to drop into Safe Mode.
- **A banner across the top** while you're in Safe Mode — _"⚠️ Safe Mode — automation and
  integrations are off. You can still view and run sessions manually."_ — with a **Restart
  Normally** button to leave.

## How it behaves

### What's OFF in Safe Mode

Everything that acts on its own:

- **Automation** — auto-landing code to your main branch, the master-debt auto-fixer, the
  dev-pipeline auto-advance, auto-spawning sessions from email/chat intake, the inbox pilot,
  and per-session auto-run rules.
- **Scheduled sending** — scheduled messages, drips, digests, send-later, and alarms.
- **Every integration's background activity** — Gmail, SMS/Telegram, JIRA/Linear/Mission Control,
  agent-email, and the Firestore share sync.
- **Remote/mobile access** — the Tailscale tunnel that serves Omniscio to your phone is off (this
  also shrinks your exposure while you're poking at a broken app).
- **Self-acting watchdogs** — the background helpers that restart or re-spawn sessions on their
  own.
- **Hardware graphics acceleration** — Safe Mode falls back to basic graphics, exactly like
  Windows Safe Mode, so the app can still open even if a display/GPU problem is what broke it.

### What stays ON

- Viewing every session, all history and messages.
- Changing settings (so you can actually fix what's wrong).
- Manually opening a session, sending a message, or starting a new session yourself.
- Login/credentials, the database, the local control server (127.0.0.1) — all normal.

The net effect: the app still _works_, it just does nothing on its own.

- **It's sticky.** Once Safe Mode is on, it **stays on across restarts** — even if the app
  crashes — until you deliberately choose **Restart Normally**. That way a broken app can't
  quietly pull you back into the state that was misbehaving. Leaving is always one click away
  via the banner.
- **It's always one app.** Omniscio never runs two copies on your data at once. If the app is closed,
  the Safe Mode launcher opens it in Safe Mode; if it's already running and misbehaving, the
  launcher tells the running app to restart itself into Safe Mode. Restarts are graceful — your
  running sessions are cleaned up, not killed.
- **New features are safe by default.** Any background service added to Omniscio in the future is
  automatically inert in Safe Mode unless a developer explicitly marks it as essential — so Safe
  Mode can't slowly rot into being un-safe as the app grows.

### When to use it

Reach for Safe Mode when Omniscio is misbehaving and you want a calm, do-nothing app to diagnose or
fix from — runaway automation, a session storm, something that won't stop on its own, or an app
that won't open normally. It's a break-glass recovery tool, not an everyday mode.

## For agents

### Under the hood (for agents)

- The signal that Omniscio is in Safe Mode is a small **marker file** (`SAFE_MODE`) in the user-data
  directory — deliberately **not** a normal setting, because the settings database is exactly
  what might be broken. Three things activate Safe Mode: the marker file, the `--safe-mode` launch
  flag (what the launcher passes), or the `AMC_SAFE_MODE=1` environment variable (used by tests
  and power-recovery).
- Safe Mode is a **boot mode**: the automation/integration layer is simply **never started**
  (rather than paused mid-run), which is why it's reliable. It reuses Omniscio's startup-task registry
  as the on/off seam — the runner skips every task not opted in via `runInSafeMode`, while the
  fragile inline core boot (window, database, auth, IPC) is untouched.
- The read-only CLI `GET /state` endpoint reports `safeMode: true|false`.
- Full engineering detail + the test-locked invariants: `.claude/memory/contracts/safe-mode-contract.md`.

## Related

Safe Mode switches off many areas of the product at once — automation, scheduled sending, integrations and remote access — so [INDEX.md](INDEX.md), the library index, is the way to reach the page for whichever of those you were diagnosing when the app misbehaved.
