
# Settings reference (every configurable setting)

> Generated from the settings schema by `npm run settings:catalog` -- do NOT edit by hand. The comprehensive, always-current list of every setting you can change in Omniscio, so "does a setting for X exist?" and "how do I configure X?" can always be answered from here.

Each row is one setting: its key (the id used by `PATCH /settings/:key` and shown in `GET /settings`), the kind of value it takes, the accepted values, and what it does. A blank "What it does" means this row carries no one-line catalog description -- the setting still exists and is settable, and its key, type and accepted values confirm it. A blank row is NOT the same as an undocumented setting: a good many of these keys have a full prose section of their own under the settings pages, which are written separately from this schema-generated table, so search the settings pages for the key before concluding it is described nowhere. Secret credentials and server-managed keys are omitted (they are not user-settable).

## Settings shown in the Settings UI (585)

The toggles and fields you can change from Omniscio Settings screens.

| Setting | Type | Accepted values | What it does |
| --- | --- | --- | --- |
| `accountAutoReloginEnabled` | toggle | `true \| false` | Check every few hours and automatically sign back in any Claude account that has dropped out, instead of waiting for you to press the button |
| `accountsClassicLayout` | toggle | `true \| false` | Switch the Accounts page back to the previous flat layout instead of the grouped "Other AI tools" list |
| `agentAlertsEnabled` | toggle | `true \| false` | Agents drop persistent inbox rows via POST /alert |
| `agentCliUpdateAlertsEnabled` | toggle | `true \| false` | Inbox card with a one-click Update now whenever Claude Code or Codex CLI falls behind its latest release; the update runs in a terminal on your computer and Omniscio never updates them on its own. On by default |
| `agentDrivenMaxConcurrent` | number | `integer 0..10` | Global concurrency limit across all active agent-driven sessions. New spawns are refused beyond this count. |
| `agentDrivenMaxDollarsPerSession` | number | `number 0..20` | Ceiling in USD on the cumulative cost of a single agent-driven session. NOT enforced today - the value is stored and shown back to you, but nothing stops a session at the amount. |
| `agentDrivenMaxTurnsPerSession` | number | `integer 0..200` | Ceiling on follow-up turns for a single agent-driven session. NOT enforced today - the value is stored and shown back to you, but nothing stops a session at the count. |
| `agentDrivenSessionsEnabled` | toggle | `true \| false` | Allow external scripts to spawn Omniscio sessions and send follow-up messages on their own. Off by default — leave it off unless you have a script you trust to do so. |
| `agentFindBatchingEnabled` | toggle | `true \| false` | Rewrites your agents’ find commands to run their per-file work in efficient batches instead of launching one process per file — one runaway find can otherwise spawn tens of thousands of processes and freeze this computer. On by default and actually faster. Only turn off if a specific command genuinely needs the old one-process-per-file behavior. Takes effect on your next new session. |
| `agentInputRequestsEnabled` | toggle | `true \| false` | Lets a session pop a box asking you to fill in a value it cannot set itself, like an API key. The AI never sees what you type. |
| `agentInstructionsSyncCanonical` | select | `"CLAUDE.md" \| "AGENTS.md"` | Which filename Omniscio reads as the source of truth for agent instructions sync. CLAUDE.md by default; switch to AGENTS.md if that is your primary tool. |
| `agentInstructionsSyncEnabled` | toggle | `true \| false` | Mirror your canonical agent instructions file (CLAUDE.md or AGENTS.md) into the filenames other AI coding tools read — Codex, Gemini CLI, Cursor, Cline, Copilot, Windsurf. Off by default. |
| `agentInstructionsSyncGitMode` | select | `"local" \| "committed"` | Whether the generated agent-instruction copies are committed to git or kept out of it. Keeping them out avoids merge conflicts; committing them is for teammates who use other AI tools. |
| `agentInstructionsSyncMirrors` | list | `array of "AGENTS.md" \| "CLAUDE.md" \| "GEMINI.md" \| ".cursorrules" \| ".clinerules/base.md" \| ".github/copilot-instructions.md" \| ".windsurfrules"` | Pick which agent-instruction filenames to write alongside the canonical file. The canonical file itself is hidden — no self-copies. |
| `agentModelTiers` | object | `object { basic: string (≤100); genius: string (≤100); smart: string (≤100); worker: string (≤100) }` | When an agent asks for a model by tier instead of by name, these are the models it gets. Agents cannot reliably remember model names, so asking by tier is what keeps them from starting a session on a model that no longer exists. |
| `agentPermissionLevel` | select | `"read_only" \| "guarded" \| "autonomous" \| "full"` | How much an agent can do on its own before Omniscio stops to ask you. Below Full trust, the built-in protection for sensitive files (SSH keys, credentials, system files) always asks; Full trust auto-approves them too. Email-triggered sessions stay locked down at every level. Applies to Claude Code sessions, and to new Codex sessions unless Codex has its own level set under Accounts. |
| `agentShortLinkDefault` | toggle | `true \| false` | When on, agents that publish a share use a short link by default instead of the long one (paid plans) |
| `agentStatusBoardEnabled` | toggle | `true \| false` | Show a live board of every agent Omniscio has launched — its workspace, status, dev-pipeline phase, and to-do checklist — each with one click to jump to that session. Adds an Agent Board icon to the toolbar. |
| `aiCoachingCliEnabled` | toggle | `true \| false` | Allow external agents to read your AI coaching artifacts (interview prompts, drafts) and start coaching interviews over the local CLI control server. On by default. Flip off to disable all AI coaching CLI access at once. |
| `aiCoachingStyle` | select | `"warm" \| "neutral" \| "direct"` | Set the overall tone — warm, neutral, or direct — for all coaching interviews |
| `aiSuggestionModel` | text | `string (≤100)` | Model used for session suggestions and session title generation |
| `alarmNlpDailyCostCap` | number | `number 0..5` | Max daily spend on Haiku-assisted natural-language alarm parsing |
| `alarmsAssertiveness` | select | `"modal" \| "banner" \| "silent-banner"` | How alarms surface when they fire. |
| `alarmsBringToForeground` | toggle | `true \| false` | Raise the Omniscio window above other apps when an alarm fires |
| `alarmsDefaultMaxSnoozes` | number | `integer -1..20` | Maximum number of times an alarm can be snoozed before only Dismiss remains |
| `alarmsDefaultSnoozeMinutes` | unknown | `5 \| 9 \| 15 \| 30` | How long to snooze a firing alarm by default |
| `alarmsDefaultSound` | text | `string (≤200)` | Sound played when an alarm fires |
| `alarmsDefaultSoundDurationSeconds` | number | `integer -1..300` | How long the alarm sound plays before stopping (or forever) |
| `alarmsDefaultSoundFadeInSeconds` | number | `integer 0..300` | Ramp the alarm volume from silent to full over this many seconds — gentle wake or crescendo |
| `alarmsDefaultSoundPlayMode` | select | `"once" \| "loop"` | Play the alarm sound once or loop until you dismiss |
| `alarmsDefaultSpeakLabel` | toggle | `true \| false` | Have the alarm read its label aloud when it fires (text-to-speech) |
| `alarmsEnabled` | toggle | `true \| false` | Master switch for the Alarms feature |
| `alarmsMaxRingingMinutes` | number | `integer 1..60` | Auto-dismiss alarms to inbox after this many minutes |
| `alarmsPierceFocusMode` | toggle | `true \| false` | Fire alarms immediately even during Focus Mode batching |
| `alertSessionDefaultProjectId` | text | `string (≤64)` | Which hub the Start session button on an alert opens in, when the alert does not name one itself. Automatic uses the hub holding this app’s own code if you have one, so alerts about Omniscio start where you develop it — otherwise Claude. |
| `allowAgentAppRestart` | toggle | `true \| false` | When OFF (default), the local CLI restart route is disabled, so an agent or external script can never quit and relaunch Omniscio on its own — not even one holding the global CLI token. Your own "Restart Omniscio" button is unaffected. Turn ON only if you want to let a headless caller restart the app. |
| `allowAgentDirectNavigation` | toggle | `true \| false` | When OFF (default), an agent's request to switch your view — jump you to a hub, the inbox, a settings pane, a note, a mind map, or a Gmail thread — drops a click-to-go toast instead of moving you, so Omniscio never takes over your screen and puts you somewhere else. When ON, agents may switch your view immediately (guided tours, "let me show you this"). Either way your own clicks, taps, notification and link clicks always navigate instantly, and if you're away in another app the request still can't move you — you get a dismissible inbox note instead. |
| `allowAgentForegroundFromBackground` | toggle | `true \| false` | When OFF (default), an agent's request to focus or pop Omniscio to the front is ignored while you're working in another app — instead you get a dismissible inbox note naming the session that tried. When ON, agents may pull Omniscio to the front from behind. Either way agents can still drive the UI while you're already in Omniscio (settings tours, tutorials), and your own shortcuts, notification clicks, and phone taps are never affected. |
| `allowAgentTokenSpawn` | toggle | `true \| false` | When OFF (default), a command-line session spawn is rejected if it presents only an agent's scoped token (the Omniscio-injected $AMC_CLI_TOKEN) — so a compromised MCP server or npm dependency that reads an agent's environment can't spend your money by spawning paid sessions. Agents still spawn normally using the global CLI token. Turn ON to let an agent spawn sessions directly with its own scoped token. |
| `allowAgentTokenTeamChat` | toggle | `true \| false` | When OFF (default), a Team Chat write over the CLI (send a DM or channel message, react, edit, delete, pin, schedule a DM, invite a guest) is rejected if it presents only an agent's scoped token (the Omniscio-injected $AMC_CLI_TOKEN) — so a compromised MCP server or npm dependency that reads an agent's environment can't message your teammates as you. Turn ON to let your agents write to Team Chat with their own token; every message they send is still labeled "<your name>'s agent". |
| `allowAntigravitySessionSpawn` | toggle | `true \| false` | Enable spawning Anti-Gravity-provider sessions across all projects |
| `allowCodexSessionSpawn` | toggle | `true \| false` | Enable spawning Codex-provider sessions across all projects |
| `allowCursorSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Cursor as a session provider in the new-session menu |
| `allowDeepseekSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose DeepSeek as a session provider in the new-session menu |
| `allowDevinSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Devin as a session provider in the new-session menu |
| `allowDshSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose DeepSeek Harness (DeepSeek's own ACP coding CLI, `dsh`) as a session provider in the new-session menu |
| `allowGeminiSessionSpawn` | toggle | `true \| false` | Opt-in toggle to allow spawning Gemini-provider sessions across all projects |
| `allowGlmSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose GLM (Zhipu z.ai) as a session provider in the new-session menu |
| `allowGptSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose GPT (your ChatGPT subscription, via the local model proxy) as a session provider in the new-session menu |
| `allowGrokSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Grok Build as a session provider in the new-session menu |
| `allowHermesSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Hermes as a session provider in the new-session menu |
| `allowKimiSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Kimi (Moonshot) as a session provider in the new-session menu |
| `allowKimicodeSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Kimi Code (Moonshot's own ACP coding CLI) as a session provider in the new-session menu |
| `allowMetaSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Meta (Muse Spark, Anthropic-compatible API) as a session provider in the new-session menu |
| `allowMinimaxSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose MiniMax as a session provider in the new-session menu |
| `allowOpencodeSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose OpenCode as a session provider in the new-session menu |
| `allowOpenrouterSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose OpenRouter (run any model with one key, no account — Anthropic-compatible) as a session provider in the new-session menu |
| `allowPiSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Pi as a session provider in the new-session menu |
| `allowQwenSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose Qwen (Alibaba DashScope) as a session provider in the new-session menu |
| `allowUnverifiedPluginBackends` | toggle | `true \| false` | Let third-party (marketplace) plugins run a backend with full system access. Off by default. |
| `allowXaiSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose xAI Grok (your Grok subscription, via the local model proxy) as a session provider in the new-session menu |
| `alwaysUseDefaultStartConfig` | toggle | `true \| false` | Hide the tool/model/thinking picker on new sessions so they start on your default; you can still change one session before its first message |
| `amcAwarenessPromptEnabled` | toggle | `true \| false` | Adds a short note to every session so the agent knows it is running in Omniscio and how to reach it. |
| `animatedLogo` | toggle | `true \| false` | Let the Omniscio logo swirl in the title bar, Quick Launch and the loading screen while you use the app. It stays still whenever your computer asks for less motion or Low Power Mode is on. You can also right-click the logo to turn it off. |
| `antigravityProjectEnabled` | toggle | `true \| false` | Adds a dedicated Anti-Gravity virtual project to the sidebar |
| `archiveDigestCadence` | select | `"off" \| "daily" \| "weekly"` | How often to post an Archive Insights AI digest to your inbox automatically — off, daily, or weekly. On-demand analysis is always available inside Archive Insights. |
| `articleReaderModel` | text | `string (≤100)` | Per-feature model override for RSS article summarization — null inherits the global Utility AI model |
| `asideCostCapUsd` | number | `number 0..50` | Maximum cost per side question in USD. Asides exceeding this cap are aborted before spawn. |
| `askAmcEnabled` | toggle | `true \| false` | Adds an Ask Omniscio virtual project — a friendly tutor agent pre-loaded with the Omniscio docs and live state. |
| `audienceStylePromptEnabled` | toggle | `true \| false` | Assume the reader may not be technical — plain language, no jargon, start brief — while favoring clean headers and tight bullet points so replies are easy to skim. |
| `authPathway` | select | `"managed" \| "apiKeyOnly" \| "passthrough" \| "ownLogin"` | Choose how your Claude sessions get their Anthropic credentials: your own API key, your terminal login, or managed accounts |
| `autoAccountSwitch` | toggle | `true \| false` | Switch to another account when rate-limited instead of waiting |
| `autoApproveConfigFiles` | toggle | `true \| false` | Automatically approve when Claude wants to modify its own config files (.claude/, CLAUDE.md). When off, you'll be asked to approve each change |
| `autoApprovePlans` | toggle | `true \| false` | When Claude proposes a plan before writing code, approve it automatically instead of asking you first |
| `autoCapitalizeTasks` | toggle | `true \| false` | Capitalize the first word and the start of each sentence as you type a task — skips URLs, file paths, and abbreviations. Matches the behavior of the Vault notes app. |
| `autoCapitalizeTeamChat` | toggle | `true \| false` | In Team Chat, auto-capitalize the first word, sentence starts, and new paragraphs as you type, while skipping links, file paths, and abbreviations. The same smart capitalization used in Tasks and Quick Email. |
| `autoContinueEnabled` | toggle | `true \| false` | Automatically nudges the agent to keep going when it pauses mid-task without a question. Prevents unnecessary inbox interruptions during long jobs. |
| `autoDetectProjectIcons` | toggle | `true \| false` | Scan hub folders for favicons and logos to display in the sidebar |
| `autoDetectQuestions` | toggle | `true \| false` | Spot questions in the agent's reply automatically, even when the agent doesn't explicitly ask you. |
| `autoFixBrokenCloudBase` | toggle | `true \| false` | When the cloud test-offload workspace fails to build (a dependency/toolchain break the cloud can’t self-heal on its own), Omniscio raises a loud inbox card. ON (default) ALSO launches a fixer session automatically, hands-free, so the cloud self-heals without a click. Turn it OFF for a one-click card instead — a fix session costs money, so the off switch lets you approve each one. |
| `autoFixMasterDebt` | toggle | `true \| false` | When on, Omniscio automatically spawns fix sessions for accumulated debt on master. Off (default) drops an inbox card asking you first. Requires the Master-Debt Auto-Fixer (above) to be enabled. |
| `autoFocusOnNeedsYou` | toggle | `true \| false` | Bring the app to the foreground when a session needs your attention. |
| `autoInstallWhenIdle` | toggle | `true \| false` | When an update is ready, install and restart automatically only if no sessions are running and your computer has been idle. Off by default. |
| `autoLanderEnabled` | toggle | `true \| false` | While "merge all ready branches" runs, a background worker also lands the branches that merge cleanly the moment they are tagged, so the main merge only has to stop for genuine conflicts. It never touches a branch someone is hand-resolving, only ever moves things forward (nothing can be lost), and stays entirely on your machine — it never pushes. Off by default. Only active in the Omniscio hub, where the merge tools live. |
| `autoLanderRepos` | list | `array of object { dryRun: true \| false; enabled: true \| false; integrationBranch: string (≤200); projectId: string (≤100) }` | The list of repositories the auto-lander watches. Each repo can be enabled, set to observe-only, and given an integration branch. |
| `autoLanderStaleTagHealMaxConcurrent` | number | `integer 0..50` | How many stale-tag self-heal sessions may run at the same time. These sessions automatically re-check the gate and re-tag a branch whose commits moved past its ready-to-merge tag — so the auto-lander can land it without waiting for a human. They use a separate pool from the auto-lander's conflict-rescue sessions, so raising this never slows those down. 0 = no limit (default). Set to a positive number to impose a cap. |
| `autoLanderUiVisible` | toggle | `true \| false` | Reveals the per-repo auto-lander editor: which repositories it watches, each one’s observe-only switch, and the branch it lands into. |
| `autoModelRouterEnabled` | toggle | `true \| false` | Automatically select the best model for each new session based on the task. |
| `autoModelRoutes` | list | `array of object { enabled: true \| false; id: string (≤100); keywords: array of string (≤100); label: string (≤200); target: object { model: string (≤120); provider: string (≤50) }; whenToUse: string (≤2000) }` | Configure which models handle which types of tasks. |
| `autoRemediateAlertsEnabled` | toggle | `true \| false` | When an Omniscio infrastructure alert fires (cloud fleet degraded, direct-SSH failed, auto-lander / worktree / database health, a freeze-prevention gate degraded), Omniscio auto-launches a background session into the Omniscio project to investigate and fix it (once per problem, globally capped), then archives the card. Turn it OFF for a passive card you act on yourself; a fix session costs money, so the off switch lets you approve each one. |
| `autoRespondPreviewBeforeSend` | toggle | `true \| false` | Hold an AI-written auto-reply in your inbox to approve or reject before it sends |
| `autoRestartUnresponsiveSessions` | toggle | `true \| false` | When a session gets stuck showing "thinking" with no reply — the agent's process wedged and stopped responding — Omniscio restarts the stuck turn so it continues, instead of leaving it spinning forever. |
| `autoResumeOnCrash` | toggle | `true \| false` | Automatically restart sessions that were active when the app was closed or crashed. Running sessions receive a continue nudge. Sessions waiting for your input are restored. |
| `autoSwitchToInbox` | toggle | `true \| false` | Automatically navigate to the inbox when another session needs attention, but only if you've been idle for at least 5 seconds. Won't interrupt scrolling, clicking, or typing |
| `autoTidyEnabled` | toggle | `true \| false` | When on, Omniscio moves sidebar integrations and toolbar icons you have not used in 30+ days into a quiet spot (an "Unused" group / the "…" overflow) to reduce clutter, and tells you in the inbox. Nothing is deleted — restore anything in the list below. Off by default. |
| `autoUpdateTools` | toggle | `true \| false` | Silently update Claude Code, Playwright, AgentMail, Repomix in the background; Git and GitHub CLI notify only |
| `autoWaitMinutes` | number | `integer 5..240` | How long Omniscio keeps a waiting session running on its own before it flips to your inbox, both when the agent says it is waiting on something and when it dispatches a background task. |
| `automationsEnabled` | toggle | `true \| false` | Master toggle for automatic message processing with rules or AI |
| `backgroundRunnerEnabled` | toggle | `true \| false` | Omniscio runs scheduled background jobs on its own — health checks, clean-ups, watchers. With this on, they all run inside one long-lived helper process, so a job no longer starts a whole new program every time it runs — hundreds fewer program starts an hour. Turning it off runs each job in a program of its own again from its next run; the jobs, and when they run, stay exactly the same. |
| `backupMirrorIncludeScreenRecordings` | toggle | `true \| false` | Off by default — screenshots are always backed up, but screen recordings can be very large (often 1–3 GB each), so mirrors include them only when this is on |
| `bookmarksCliEnabled` | toggle | `true \| false` | Allow external agents to list, create, update, delete, reorder, and launch bookmarks over the local CLI control server. On by default. Flip off to disable all bookmark CLI access at once. |
| `boostAmcProcessPriority` | toggle | `true \| false` | While an Omniscio window is in the foreground, raises Omniscio's own processes (main + renderer + GPU + utility) to Above-Normal priority so they win scheduler fights against Claude CLI children at Below-Normal. Keeps the Omniscio window — and other foreground apps like Chrome — snappy when many sessions are saturating the machine. No effect on macOS or Linux. |
| `bugIntakeAppendPrompt` | text | `string (≤10000)` | Extra instructions added to the investigation prompt for every bug report routed to this project (email, Sentry, in-app). Stacks after the global Bug Intake instructions. |
| `bugIntakeEnabled` | toggle | `true \| false` | Show the Bug Intake sidebar entry — collects bug reports from Sentry, GitHub, bug-report emails and in-app reports and triages them via spawned agents. When off, no report from any source starts a session. |
| `bugReportEmailEnabled` | toggle | `true \| false` | When on, clicking the bug-report icon, sending feedback, or reporting a missed question widget sends the report to the Omniscio team by email and to the report database. Off sends nothing: reports stay on this computer and go out when you turn this back on. |
| `calendarDailyAgendaEnabled` | toggle | `true \| false` | Post a 'Today's Agenda' card to your inbox each morning listing the day's events. |
| `calendarEnabled` | toggle | `true \| false` | Show upcoming calendar events and get reminders before meetings in the sidebar. |
| `calendarNotificationDelivery` | select | `"inbox" \| "toast" \| "both"` | Deliver calendar notifications as an inbox alert, a toast pop-up, or both |
| `calendarReminderMinutes` | number | `integer 0..120` | How many minutes before an event starts to send the "starting soon" reminder |
| `calendarWeekStartDay` | select | `"sunday" \| "monday"` | Choose which day the calendar week begins on. |
| `canvaMcpEnabled` | toggle | `true \| false` | Connect your Claude sessions to Canva for design creation, management, and export. Sessions can generate designs, search your library, export to various formats, and manage assets — all through conversation. |
| `chatDepth` | select | `"flat" \| "soft" \| "glass"` | How much shadow and glassy depth the chat messages have. Flat is the classic look; Glass is the most three-dimensional. |
| `cheapUtilityModel` | text | `string (≤100)` | Global model override for all cheap/background AI helpers — titles, suggestions, summaries, digests |
| `cliSpawnSpacingSeconds` | number | `integer 0..300` | How long to wait between starting brand-new sessions that an agent or automation creates in a burst (for example a script spawning many sessions in a row). Keeps rapid automated spawns from piling up all at once. Sessions you open yourself are never affected. Set to 0 to start them immediately. Takes effect immediately, no restart needed. |
| `closeToTray` | toggle | `true \| false` | When you close the window, keep the app running in the background (system tray) so sessions stay alive instead of quitting |
| `cloudControlPlaneEnabled` | toggle | `true \| false` | Reflects live cloud-session status in the app instead of the app reading it piecemeal, and starts the paid cloud machines this developer preview needs. It does not change how a session connects — a session's output still arrives over its own connection. Developer preview: the relay only runs in an unpackaged build with cloud sessions enabled, so turning this on in a packaged app starts nothing. Costs real money when it does run, so it ships off — turn it on only when you mean to spend. Takes effect the next time the app starts. |
| `cloudHardenedSessionEnabled` | toggle | `true \| false` | Runs each cloud session on its own locked-down machine: a separate VM, a firewall that blocks everything it does not need, and a short-lived key instead of your main one. This is the paid path, so it ships off — turn it on only when you mean to spend. Applies to your next cloud launch. |
| `cloudSessionReviewsEnabled` | toggle | `true \| false` | When a cloud session’s work is brought back to this computer, run the AI Code Review reviewers you configured in the Dev Pipeline panel against the returned branch, and record what they found. On by default — a reviewer only runs on this computer, so this is the first moment a cloud session’s work can be reviewed at all. The findings are delivered to you and kept with the branch; a review does not currently hold the branch back from landing. Turn it off to bring cloud work home without a review. |
| `cloudStartedSessionsEnabled` | toggle | `true \| false` | Allow a session running in the CLOUD to start helper sessions of its own, so a cloud overseer can staff its own work. Off by default, and you switch it on yourself. You approve each one from a card that names the session asking, every helper runs in the cloud and never on this computer, and one click stops a whole tree. |
| `coachingEnabled` | toggle | `true \| false` | Contextual suggestions to help you discover features and work more efficiently |
| `codebaseStatsBackgroundEnabled` | toggle | `true \| false` | When on, Omniscio quietly analyzes and caches each hub’s codebase stats (size, languages, git activity, code health) in the background, so the "Codebase Stats" view opens instantly instead of computing on the spot. It is heavily throttled — one hub at a time, only what changed, and it backs off when your computer is busy. It is designed to stay out of your way, but it is real work: on a very busy machine you may occasionally notice it. Turn it off here if you would rather not run it at all. (Dependency security scans still run only when you open a hub and refresh.) |
| `codexApprovalMode` | select | `"inherit" \| "ask" \| "ask-on-request" \| "auto"` | Choose how much access a Codex session gets and when it asks you: follow Agent Permissions (default), ask before every command, ask only when it reaches outside the project, or allow all |
| `codexProjectEnabled` | toggle | `true \| false` | Adds a dedicated Codex virtual project to the sidebar |
| `confirmUnansweredQuestions` | toggle | `true \| false` | Show a confirmation dialog when the question widget would submit a question you haven't answered. |
| `contentFreeMobilePush` | toggle | `true \| false` | Send push notifications to your phone without the sender, subject, or message text |
| `contextStallAutoRecoverEnabled` | toggle | `true \| false` | When a session fills its context window and stops mid-task without finishing, Omniscio automatically frees space and continues it — so you see a finished reply instead of a blank. |
| `contextWarning75Enabled` | toggle | `true \| false` | Post an in-chat note once a conversation is about 75% full of the model's context window. Off by default. |
| `contextWarning90Enabled` | toggle | `true \| false` | Post an in-chat note once a conversation is about 90% full — the point where Claude may start summarizing and dropping older messages. Off by default. |
| `continuousSummaryEnabled` | toggle | `true \| false` | Show a 4-line catch-up card pinned at the top of long sessions. |
| `continuousSummaryModel` | text | `string (≤200)` | Override the LLM that generates the Catch-Up Card. |
| `continuousSummaryOriginallyLengthCap` | number | `integer 50..10000` | Used only when the AI summary call fails. Caps the verbatim slice of the user's first message that gets stored as the fallback anchor for the Catch-Up Card. |
| `continuousSummaryOriginallyPromptTemplate` | text | `string (≤50000)` | AI prompt that summarizes the user's first message into a 10-30 word plain-English anchor |
| `continuousSummaryRecentTurnsVisible` | number | `integer 1..5` | How many back-and-forth turns to render on the Catch-Up Card panel. 1 = current only, 3 = current + 2 prior pairs. Range 1-5. |
| `continuousSummaryShowAgentSummary` | toggle | `true \| false` | Toggle the Did / Asks rows on the Catch-Up Card panel — what the agent did and what it is waiting on. Originally and Last asked always show. When off, the agent AI call is skipped. |
| `copyFullPaths` | toggle | `true \| false` | Copy absolute paths to clipboard instead of relative paths from agent output |
| `councilEvaluatorModel` | text | `string (≤120)` | Analyzes and compares panelist answers before synthesis. |
| `councilSynthesizerModel` | text | `string (≤120)` | Merges the panelist answers into one final answer. |
| `crashAlertEmailEnabled` | toggle | `true \| false` | When diagnostics email is on, also email the team on each crash. Turn OFF to email only the weekly digest — crashes still auto-triage inside Omniscio (via Sentry), and the on-disk crash log continues. |
| `cronFailureAlertsAlwaysFire` | toggle | `true \| false` | Bypass Focus Mode batching for cron-failure alerts |
| `cronFailureAlertsEnabled` | toggle | `true \| false` | Show a system notification and inbox card when a cron job fails permanently |
| `customFormatBlockEnabled` | toggle | `true \| false` | Silently add a short, editable formatting standard to the FIRST message of each session, right alongside the question-widget hint, so the agent shapes its responses to be easy to skim. Edit the text below; turn off to stop it reaching the model. |
| `customPromptRules` | list | `array of object { id: string (≤64); targets: array of string (≤200); text: string (≤8000) }` | Custom instructions injected into the prompts of a specific engine or model (Codex, Claude, and others) — target whole engines or specific model ids |
| `customProvidersEnabled` | toggle | `true \| false` | Master switch for your custom providers (and the built-in OpenRouter entry) in the session picker — on by default |
| `dailyDigestEnabled` | toggle | `true \| false` | Generate a daily briefing summarising AI session activity across all hubs. |
| `dailyDigestModel` | text | `string (≤100)` | Per-feature model override for daily digest generation — null inherits the global Utility AI model |
| `dailyDigestSources` | object | `object { calendar: true \| false; gmail: true \| false; pm-events: true \| false; pm-feed-digest: true \| false; rss: true \| false; sessions: true \| false; slack: true \| false; sms: true \| false; telegram: true \| false }` | Choose which data sources are included in your daily briefing |
| `dailyJournalTime` | text | `string` | Time of day your daily check-in and weekly review nudge appears |
| `dailyJournalWeeklyDay` | number | `integer 0..6` | Which day of the week your longer weekly review nudge appears |
| `dbWorkerAbForceOn` | toggle | `true \| false` | Diagnostics measurement lever, shown only in dev builds. Forces the off-thread DB worker ON right now — the same as launching with AMC_ENABLE_DB_WORKER=1, bypassing the migration safety interlock and the RAM floor — so it can be A/B-measured from the app with no terminal. Applies live (no restart); for a clean measurement window, restart Omniscio after toggling. The AMC_DISABLE_DB_WORKER kill switch still overrides this, and it is NOT the shipping default. |
| `deepSeekBalanceAlertLeadHours` | number | `number 0..720` | Get the DeepSeek balance forecast alert this many hours before the projected run-out |
| `deepSeekBalanceMonitorEnabled` | toggle | `true \| false` | Warn me before my DeepSeek API balance runs out, based on how fast it is actually being spent |
| `defaultAgentInstructionsCustom` | text | `string (≤10000)` | Free-form custom text appended to every spawned session alongside preset instructions. |
| `defaultAgentInstructionsEnabled` | toggle | `true \| false` | Inject curated instruction presets into every Claude Code session — attribution removal, cloud safety, private repos, README standards. |
| `defaultModel` | text | `string (≤100)` | Which Claude model to use for new sessions |
| `defaultProjectsFolder` | text | `string (≤1000)` | Base directory for quick-creating project folders |
| `defaultProvider` | text | `string` | Which AI engine new sessions start on, across all projects |
| `desktopIconBadgeEnabled` | toggle | `true \| false` | Show or hide the count badge on your taskbar or dock icon for sessions that need you. |
| `developerMessagesEnabled` | toggle | `true \| false` | Turning this off stops announcements, surveys, and read receipts from the Omniscio team. |
| `diagnosticTracingEnabled` | toggle | `true \| false` | When on, Omniscio records freeze/long-task and click-latency timing to local troubleshooting logs (renderer diagnostics + interaction.log). Turn it off to stop that logging and the overhead it adds to the main process — your crash reports, error logs, and the freeze recorder stay on. Nothing is sent anywhere. |
| `diffFontSize` | number | `integer 10..20` | Default font size for diff content |
| `diffMinimap` | toggle | `true \| false` | Show the VSCode-style minimap overview on the modified side of the diff |
| `diffSyntaxHighlight` | toggle | `true \| false` | Apply language-aware syntax coloring to diff content |
| `diffTabSize` | number | `integer 2..8` | How many spaces wide a tab character appears in diffs |
| `diffWordWrap` | toggle | `true \| false` | Wrap long lines instead of horizontal scrolling |
| `disableGpu` | toggle | `true \| false` | Uses your GPU for hardware-accelerated rendering. Disabling this falls back to software rendering with a significant performance cost. |
| `distributeSessionsAcrossAccounts` | toggle | `true \| false` | Spread new sessions across login accounts by usage instead of filling one first |
| `dripEnabled` | toggle | `true \| false` | Surfaces the Drip virtual project — queue mixed content (text, links, files, folders) into named queues that release into the inbox on a user-chosen cadence. |
| `dripGlobalPause` | toggle | `true \| false` | Master pause for every drip. When on, drips keep their cadence but skip every release until you turn this off. |
| `dripHtmlPreviewEnabled` | toggle | `true \| false` | When on, a drip item that is an .html file renders live in a sandboxed preview — HTML, CSS and JavaScript run, but the page is isolated (no network, no access to your app). Off shows the file as a plain chip. |
| `driveEnabled` | toggle | `true \| false` | Browse, upload, and manage Google Drive files from the sidebar. |
| `dropboxEnabled` | toggle | `true \| false` | Browse, upload, and manage Dropbox files from the sidebar. |
| `elevenlabsVoiceId` | text | `string (≤100)` | ElevenLabs voice ID for text-to-speech playback |
| `emailBlockRemoteImages` | toggle | `true \| false` | Stop email senders from loading external images when you open a message. Remote images quietly report your IP address and that you opened the email back to the sender; blocking them keeps that private. Inline and attached images still show. Off by default. |
| `emailCleanupClassicLayout` | toggle | `true \| false` | Use the original flat sender list for Email Cleanup instead of the AI-guided walkthrough. Turn on if you prefer the simpler view. |
| `emailInboundApprovedSenders` | list | `array of string (≤200)` | Allowlist of email addresses permitted to send messages to your inbox |
| `emailInboundEnabled` | toggle | `true \| false` | Receive emails via AgentMail, process them with Claude, and send replies |
| `emailInboundInboxId` | text | `string (≤200)` | AgentMail inbox identifier for receiving emails |
| `emailInboundPrescreenPrompt` | text | `string (≤16000)` | Full classifier prompt for inbound emails (default shown when empty; JSON output format always enforced) |
| `emailSummarizerArchiveEnabled` | toggle | `true \| false` | Archive in AgentMail after a successful summary |
| `emailSummarizerDailyCostCapUsd` | number | `number 0.1..20` | Combined daily spend limit for the email summarizer |
| `emailSummarizerDefaultPrompt` | text | `string (≤20000)` | Generic prompt used when no rule matches |
| `emailSummarizerEnabled` | toggle | `true \| false` | Auto-summarize forwarded emails |
| `emailSummarizerGmailEnabled` | toggle | `true \| false` | Auto-summarize Gmail threads tagged with your label |
| `emailSummarizerInboxId` | text | `string` | Inbox to watch for summarizable emails |
| `engineeringPrinciplesPromptEnabled` | toggle | `true \| false` | Adds a short note to every session so the agent follows senior-engineer habits: keep it simple, fix root causes instead of band-aids, believe your bug reports, write real tests, and watch performance and security. |
| `executionBiasPromptEnabled` | toggle | `true \| false` | Adds a short note to every session so the agent acts on an actionable request right away, pushes to a real finish instead of stopping at a plan, and backs up a completion claim with evidence. |
| `fastSessionSwitchingEnabled` | toggle | `true \| false` | Makes clicking between sessions feel snappier by skipping redundant re-rendering of the session panels you are not switching to. On by default — if you ever want the previous behavior back, flip it off and it reverts instantly. No restart, and no effect on what your sessions actually do. |
| `favoriteModels` | list | `array of string (≤100)` | Star the models you want agents to reach for first. Starring only changes what they try first — every other model stays just as usable. Each model shows what it costs per million tokens. |
| `fileViewerMinimap` | toggle | `true \| false` | Show the VSCode-style minimap overview on the right of the file viewer |
| `fileViewerWordWrap` | toggle | `true \| false` | Wrap long lines in the file viewer instead of horizontal scrolling |
| `finalMessageCliBoundaryWins` | toggle | `true \| false` | A sub-option of "Show only the final message": Claude Code tells Omniscio where an agent’s real answer begins, and with this on that wins over the marker the agent printed. Stops an agent that wrote you something — a draft email, a document, a list — and then misplaced its marker from hiding it and leaving a reply that says "see above" about text you cannot see. The trade-off is that on some replies you will also see the agent’s working notes above its report. Off by default — turn it on to try it. |
| `finalMessageMarkerAlwaysHide` | toggle | `true \| false` | A sub-option of "Show only the final message": when the final-answer marker is present, hide EVERYTHING before it, even on a plain answer with no tool steps, folding it into a collapsible row you can expand. Nothing is deleted; it stays one click away. On by default. |
| `finalMessageMarkerDebug` | toggle | `true \| false` | A sub-option of "Show only the final message": draw a distinct divider showing exactly where an agent placed the final-answer marker instead of hiding it. Nothing else changes — the same content stays folded, and it only appears on turns where the agent actually printed the marker. For debugging where agents put the marker. Off by default. |
| `finalMessageMarkerShowAllBlocks` | toggle | `true \| false` | A sub-option of "Show only the final message": when an agent marks more than one final message in a single turn (say a report, then a follow-up), show ALL of them instead of only the last, with the work between them tucked into the collapsible row. Nothing is ever deleted. On by default. |
| `finalMessageStructuralFloor` | toggle | `true \| false` | A sub-option of "Show only the final message": on a turn that used tools, never let the marker hide the answer or a live question the model wrote after its last tool step — only tool-calls and thinking collapse. Fixes non-Claude models (DeepSeek, Codex, GLM) that place the marker in the wrong spot. Single-step turns are unchanged. On by default. |
| `fleetSafetyGovernorEnforce` | toggle | `true \| false` | Enforce the fleet safety governor |
| `fleetSafetyGovernorSevereSpacingSeconds` | number | `number 0.05..60` | Controls how cautiously background agent work proceeds while Omniscio detects severe interface lag. Higher values provide stronger protection; lower values let agents progress faster. Healthy operation and work you start yourself are never delayed. Changes take effect within one second, with no restart. |
| `focusModeFeatureEnabled` | toggle | `true \| false` | Master kill-switch for Focus Mode. When off the toolbar pill is hidden and alerts always fire individually |
| `fontSize` | select | `"extra-small" \| "small" \| "medium" \| "large" \| "extra-large" \| "xx-large" \| "xxx-large"` | Adjust text size on desktop (phones use the separate Mobile text size) |
| `formatQuestionOptions` | toggle | `true \| false` | Display lettered options (A, B, C) as clean indented sub-items instead of bullet points |
| `frictionTriageCostCapUsd` | number | `number 0..∞` | The most the friction triage loop may spend in a rolling 24 hours — not a lifetime total, since spend from more than a day ago drops back out of the count. Set to 0 for no limit. This stops the next triage run from starting once the cap is reached; it cannot recall fixer sessions a triage run has already started. |
| `frozenPanelRetentionEnabled` | toggle | `true \| false` | Keep the sessions you’ve looked at recently fully built in memory (the way a browser keeps background tabs ready) so switching back to one is instant instead of rebuilding it. Only applies to sessions that aren’t actively streaming, and a small limit caps how many are held so memory stays bounded. Off by default — it trades memory for speed. |
| `geminiProjectEnabled` | toggle | `true \| false` | Adds a dedicated Gemini virtual project to the sidebar |
| `geminiTtsVoiceId` | text | `string (≤100)` | Choose a preset Google Gemini TTS voice for text-to-speech playback |
| `gitGuardrailsEnforcementLevel` | select | `"advisory" \| "required"` | Whether a blocked git action is hard-blocked or just warned about. The full git-guardrails controls also live in the Dev Pipeline panel. |
| `gitGuardrailsProtectedBranches` | list | `array of string` | Which branch names agents may not commit, push, or edit on directly. Defaults to master and main. |
| `gitGuardrailsReadyTagGateEnabled` | toggle | `true \| false` | Optionally require a ready-to-merge tag before an agent can push a feature branch. Off by default. |
| `globalAuthInviteOnly` | toggle | `true \| false` | Only invited or already-approved users can sign in; everyone else is blocked and can request access |
| `globalHotkey` | unknown | `string (≤100) \| array of string (≤100)` | System-wide shortcut to bring Omniscio to the foreground |
| `gmailAutoFocusReply` | toggle | `true \| false` | Place cursor in the reply textarea automatically when you open an email. Off (Superhuman/Gmail-style) keeps focus on the message body so triage shortcuts (E archive, S star, U unread, ! spam, X select, H snooze) work — press R to start typing a reply. |
| `gmailAutoMarkRead` | toggle | `true \| false` | Automatically mark email threads as read when you open them |
| `gmailDefaultQuery` | text | `string (≤500)` | Default Gmail search query used when loading the inbox |
| `gmailEnabled` | toggle | `true \| false` | Show Gmail in the sidebar for reading and sending email |
| `gmailInboxZeroCelebration` | toggle | `true \| false` | Show a brief animation when you clear all emails from your inbox |
| `gmailPageSize` | number | `integer 1..100` | Number of email threads to load at a time (10–100) |
| `googleCliBackend` | select | `"gws" \| "gog"` | Which command-line tool Omniscio uses for Gmail and Calendar. Defaults to gog (the backend installed and signed in on this machine today). gws is the official Google CLI — fully wired, but it needs its own separate Google sign-in before you switch to it. |
| `googleDocImportEnabled` | toggle | `true \| false` | When you paste a Google Doc or Slides URL into chat, fetch its contents instead of pasting the URL as text. Hold Shift while pasting to bypass. |
| `googleDocsDestFolderId` | text | `string` | When set (and no template is configured), new Docs are created inside this Drive folder |
| `googleDocsExportEnabled` | toggle | `true \| false` | Right-click a project doc, scratchpad, or agent message and publish its Markdown to a Google Doc |
| `googleDocsTemplateId` | text | `string` | When set, each publish appends a new tab to this Doc instead of creating a new one |
| `grandfatherExistingMobileDevices` | toggle | `true \| false` | Devices that were already connecting before approval existed keep working without you approving them |
| `grokVoiceId` | text | `string (≤100)` | Choose a preset Grok voice for text-to-speech playback |
| `guardPreScreenEnabled` | toggle | `true \| false` | When on, Omniscio skips a slow per-command security check for commands that cannot possibly trigger it, so each agent command is much cheaper. It still runs the full check, unchanged, for anything git or master related. It manages a hook in your global Claude config automatically, with a backup and an instant off switch, and does nothing on machines that do not have that heavy check installed. |
| `heardAboutUs` | text | `string (≤64)` | Tell us where you first found the app — helps us know what is working |
| `helpfulHintsEnabled` | toggle | `true \| false` | One master switch for all the optional tips, nudges, and coaching cards. Turn it off to silence every one of them at once; your real alerts are never affected. |
| `hideAsidesByDefault` | toggle | `true \| false` | Collapse side-question bubbles behind a one-line divider in the transcript by default. |
| `hideAutoWaitedUnlessFinal` | toggle | `true \| false` | Collapse repeated "⏱ Auto-waited" messages (prose waits and scheduled wake-ups) to one-line markers you can expand, keeping the latest visible. The first wait (attached to your prompt) and the live/in-flight wait always stay visible. Nothing is deleted. Off by default. |
| `hideRoutineUpdatesFromInbox` | toggle | `true \| false` | When a session finishes a turn and says its own reply was a routine update, that turn stays out of the inbox. Nothing is deleted, and a turn that asks a question is never hidden. On by default. |
| `hookHostEnabled` | toggle | `true \| false` | Every agent tool call runs a few safety and housekeeping hooks. With this on, Omniscio keeps one long-lived helper process running them, so each tool call starts one tiny native program instead of a full Node runtime — hundreds of fewer process starts a minute on a busy machine. Turning it off restores the one-process-per-hook behaviour at the next session start. Windows only for now; other systems keep the per-call behaviour regardless. |
| `hotkeyTrainingMode` | toggle | `true \| false` | When on, clicking a button that also has a keyboard shortcut is blocked the first time and shows you the key to press instead. Click the same control again right away and it goes through. Keyboard shortcuts always work, and this never applies on a touch screen. Off by default. |
| `idleSessionReleaseMinutes` | number | `integer 0..1440` | Fully releases the background Claude engine of a session that finished its turn and has been waiting on you for at least this many minutes — reclaiming all of its RAM (~250-450 MB each), not just trimming it. The conversation stays on screen; your next message reloads it in the background (a slightly longer first reply). Sessions waiting on a question or plan keep their engine. Set to 0 to disable. Works on every platform. |
| `imageBridgeMode` | select | `"off" \| "auto"` | When a selected model cannot see images, send attached images to a vision-capable model first and pass a text brief to the selected model. Uses an extra model call. Off by default. |
| `inboxAnalyticsEnabled` | toggle | `true \| false` | When on, Omniscio records how your inbox items behave — how long they wait before you clear them, how many pile up on average, how often you look without acting, and how long you spend on each — for the Stats → Inbox tab. The report stays on this device and never stores message content, phone numbers, or ids. |
| `inboxShowAutomations` | toggle | `true \| false` | Automation rule results |
| `inboxShowCalendar` | toggle | `true \| false` | Google Calendar reminders and agenda |
| `inboxShowCliPending` | toggle | `true \| false` | Pending CLI approval requests |
| `inboxShowCron` | toggle | `true \| false` | Scheduled cron job results |
| `inboxShowDigest` | toggle | `true \| false` | Daily briefing summaries |
| `inboxShowGithub` | toggle | `true \| false` | GitHub notifications, PRs, and issues |
| `inboxShowGmail` | toggle | `true \| false` | Gmail messages and threads |
| `inboxShowRecipes` | toggle | `true \| false` | Recipe orchestration results |
| `inboxShowSessions` | toggle | `true \| false` | Claude Code sessions needing attention |
| `inboxShowSms` | toggle | `true \| false` | Incoming text messages via Pushbullet |
| `inboxShowTelegram` | toggle | `true \| false` | Telegram messages via MTProto |
| `initialTitleModel` | text | `string (≤100)` | Per-feature model override for naming a session the first time — null inherits the global Utility AI model |
| `interruptionsAvoidedEnabled` | toggle | `true \| false` | Show a running tally of the interruptions Omniscio avoided in Statistics |
| `isolatedSessionViewEnabled` | toggle | `true \| false` | Render the active session in its own background process inside the main window, so it stays responsive while the rest of the app is busy. Takes effect on the next session you click. |
| `jarvisBriefingAutoOnOpen` | toggle | `true \| false` | Speak a briefing when opening a session with new messages |
| `jarvisBriefingEnabled` | toggle | `true \| false` | A spoken summary of a single session |
| `jarvisBriefingHotkey` | unknown | `string (≤100) \| array of string (≤100)` | Key combination |
| `jarvisBriefingHotkeyEnabled` | toggle | `true \| false` | Global hotkey |
| `jarvisBriefingModel` | text | `string (≤100)` | Which Claude model summarizes the session. Haiku is faster; Sonnet is more nuanced. |
| `jiraInboxEnabled` | toggle | `true \| false` | Surface your assigned, not-done Jira issues as rows in the unified Inbox, and get a row when one of them updates — so you don't have to keep checking the board. Requires the Jira board (above) to be enabled and connected. Off by default; checks Jira in the background every few minutes only while on. |
| `jlsImageStudioAppEnabled` | toggle | `true \| false` | Open the Image Studio website (jls-image-studio.web.app) inside Omniscio as a full-panel sidebar tab; sign in with your own JLS account. Desktop only. Distinct from the Image Studio image tools for AI sessions in Accounts & Providers. |
| `keepAmcResidentInMemory` | toggle | `true \| false` | Locks Omniscio's database in physical RAM (Windows) so it can't be pushed out to the disk pagefile and then re-read from a busy disk — the cause of the occasional whole-app freeze under heavy multi-agent load. On by default: it auto-sizes to your machine, caps itself so it can't crowd out other apps, and turns itself off on low-memory PCs. Only Omniscio's own engine is pinned, never your agents. No effect on macOS or Linux. |
| `keepAwakeWhileSessionsRunning` | toggle | `true \| false` | Prevents your computer from going to sleep while one or more sessions are running, so long jobs keep working when you step away. The display can still sleep to save power — only system sleep is blocked. Sleep returns to normal the moment every session finishes. Works on Windows and macOS; on Linux it depends on your desktop environment. On by default; turn it off to let your computer sleep normally while sessions run. |
| `keepDbInPrivateCache` | toggle | `true \| false` | Serves Omniscio's database from a large block of private memory instead of mapping it from the file on disk. Under heavy multi-agent disk load Windows evicts the file-mapped database from RAM and the app freezes while it re-reads from the busy disk — private memory can't be evicted that way, so the database stays resident and the freezes stop. Opt-in and fully reversible: turn it off and restart to go back. Takes effect on the next restart. No effect on macOS or Linux. |
| `keyRemindersPromptEnabled` | toggle | `true \| false` | Add a short reminders block to every turn — believe bug reports, act and prove, default to yes, fix root causes, write clean markdown. |
| `kimiBalanceMonitorEnabled` | toggle | `true \| false` | Watch your Moonshot (Kimi) API balance and raise an inbox card with a one-click Recharge button before it runs out |
| `kimiBalanceThresholdUSD` | number | `number 0..10000` | Get the Kimi low-balance alert once your Moonshot balance falls under this dollar amount |
| `kmsKeepWarmEnabled` | toggle | `true \| false` | Keeps your Vault editor loaded in the background once you’ve opened it, so switching back into The Vault is an instant flip instead of rebuilding the editor every time. Holds one editor in memory, and only after you first open The Vault. Desktop only. On by default; turn off to load The Vault fresh each time (the old behavior). |
| `kmsSummaryModel` | text | `string (≤100)` | Per-feature model override for knowledge base note summarization — null inherits the global Utility AI model |
| `landerAutoPreserveClearEnabled` | toggle | `true \| false` | When on, the auto-lander automatically preserves idle uncommitted changes in a paused checkout to a recovery ref and clears them so landing can resume — instead of pausing and asking you to clear them yourself. Nothing is discarded; you get an inbox alert with how to recover. Off by default. |
| `launchOnStartup` | toggle | `true \| false` | Automatically start when you log in to your computer |
| `leanHiddenPanels` | toggle | `true \| false` | When you have many sessions open at once, Omniscio stops the ones you can't see from doing background work every time another session sends a message. This keeps scrolling smooth and the chat landing in the right place no matter how many sessions are running. On by default; turn off to mount every hidden session in full like before. |
| `linearInboxEnabled` | toggle | `true \| false` | Surface your unread Linear notifications — mentions, replies, status changes, new assignments — as rows in the unified Inbox, and get a row when a new one arrives, so you don't have to keep checking Linear. Requires the Linear board (above) to be enabled and connected. Off by default; checks Linear in the background every few minutes only while on. |
| `liteMode` | toggle | `true \| false` | One switch to make Omniscio lighter on low-spec machines: turns on Low Power Mode, holds new sessions when memory is low, reclaims RAM from idle sessions (Windows), staggers session loading, and stops keeping extra chats pre-built in the background. Turn it off to restore your previous settings. Startup-related changes take effect on the next launch. |
| `loadBalancingNoticeEnabled` | toggle | `true \| false` | Tell me with an inbox card when one login is carrying far more running sessions than the others and is close to its limit. Turning this off keeps sessions spreading across your logins — it just hides the notice. |
| `logLevel` | select | `"error" \| "warn" \| "info" \| "verbose" \| "debug"` | Controls how much detail is written to the log file. Higher levels include all lower levels. Use "Info" for normal operation or "Verbose" when troubleshooting. |
| `lowDiskSpaceAlertEnabled` | toggle | `true \| false` | When on, you get an inbox warning if free disk space drops below the threshold below and automatic cleanup cannot free enough. Turning it off silences the warning only. The automatic cleanup that protects your disk keeps running. |
| `lowDiskSpaceFloorGb` | number | `number 5..500` | The amount of free space to keep on your working drive. Below this, finished worktrees are cleaned up automatically, and you are warned (when the warning above is on) if cleanup cannot free enough. |
| `lowPowerMode` | toggle | `true \| false` | Disables GPU-expensive visual effects (background blur, heavy animations, decorative shadows) for smoother rendering on integrated graphics and low-power laptops. Takes effect immediately — no restart required. |
| `marketplaceEnabled` | toggle | `true \| false` | Show the Marketplace sidebar entry and the marketplace browser under Settings → Plugins for discovering and installing community plugins. Off by default. |
| `marketplaceReviewEnabled` | toggle | `true \| false` | Show the Marketplace Review sidebar entry — the admin queue for approving or rejecting submitted plugins. Off by default. |
| `masterAutoSyncEnabled` | toggle | `true \| false` | Lets a background check bring your local master branch up to date with the remote on its own — about five minutes after the app starts, then every six hours. Off by default. With it off you are still TOLD when you have fallen behind, with a one-click catch-up; nothing moves your branch unless you ask. Only applies when running from source, and it never runs while the auto-lander is on (that machine's master is a branch the lander is arbitrating). The same switch is in the Dev Pipeline panel's Setup tab. |
| `masterDebtFixerModel` | select | `"default" \| "claude-worker" \| "claude-basic" \| "deepseek-v4.1-flash" \| "deepseek-v4-flash" \| "deepseek-v4-pro" \| "crofai/deepseek-v4-flash" \| "crofai/deepseek-v4-pro"` | Which model the master-debt fixers run on when they clear failures that were already red on master. DeepSeek V4.1 Flash is the default — that work is mechanical and highly repeated, so the cheapest capable engine is the right pick. If the engine you choose is not set up on this machine (no key, no access to Omniscio's shared gateway), fixers quietly fall back to the reporting project's own engine, so a fix never stalls on this choice. |
| `meetingRoomsEnabled` | toggle | `true \| false` | Show Meeting Rooms in the sidebar and enable the Ctrl+Shift+Z palette shortcut. Your saved rooms are preserved when disabled. |
| `meetingSummaryModel` | text | `string (≤100)` | Per-feature model override for meeting note enhancement — null inherits the global Utility AI model |
| `meetingsAutoDetectEnabled` | toggle | `true \| false` | Detects when a call goes live — including browser calls like Google Meet and Teams — and shows a heads-up display so you can start taking notes. |
| `meetingsLiveIndicator` | toggle | `true \| false` | Show the small floating window with the live transcript while a meeting records. |
| `meetingsSpeakerAttribution` | toggle | `true \| false` | Show who said what in the transcript by labelling each speaker. |
| `meetingsSttProvider` | select | `"deepgram" \| "elevenlabs" \| "groq" \| "grok" \| "gemini" \| "meta" \| "openrouter" \| "local"` | Which speech service writes your meeting transcripts. Separate from the voice-typing engine — you can use a different one here. Paid engines bill to your own key. |
| `meetingsSummaryLanguage` | text | `string` | The language the AI-written notes and summaries are produced in. |
| `meetingsTranscriptRetention` | select | `"off" \| "30" \| "90" \| "365"` | Automatically delete raw transcripts after this long. Your notes and summaries are always kept. |
| `meetingsTranscriptionLanguage` | text | `string` | The language spoken in your meetings — used by the live transcriber. |
| `memoryReclaimEnabled` | toggle | `true \| false` | When your computer's free memory drops and stays low, Omniscio trims the memory its own idle sessions are holding — a safe, automatic tidy-up that never touches a session mid-reply. On by default. No effect on macOS or Linux. |
| `memoryReclaimFreePercent` | number | `integer 1..90` | The trigger point. When free RAM stays below this percentage of your total memory, the automatic reclaim kicks in. Higher = reclaims sooner; lower = only under real pressure. |
| `mempalaceEnabled` | toggle | `true \| false` | Persistent cross-session memory — search past sessions and auto-recall context |
| `mergePriorityBoostEnabled` | toggle | `true \| false` | While "merge all ready branches" runs, gives that session Above-Normal CPU priority and briefly drops your other sessions to Below-Normal so the batch finishes faster on a busy machine. Other sessions keep running — they just yield. Reverts automatically when the merge ends, after a 30-minute safety timeout, or if you turn this off. On macOS it lowers your other sessions but cannot raise the merge session above normal, so the speed-up is gentler; no effect on Linux. |
| `mindmapModel` | text | `string (≤100)` | Per-feature model override for Mind Map AI features — null inherits the global Utility AI model |
| `missionControlEnabled` | toggle | `true \| false` | Show Mission Control in the sidebar: a built-in project management tool with projects, groups, items, and views. |
| `mobileDeviceLocationEnabled` | toggle | `true \| false` | Look up a rough location (city/region) from the network address a device connects from, so you can tell where a connection came from. Turn off to stop this lookup entirely. |
| `mobileFastLoadEnabled` | toggle | `true \| false` | Load the mobile web app faster by fetching feature code only when needed instead of all at startup |
| `mobileFontSize` | select | `"extra-small" \| "small" \| "medium" \| "large" \| "extra-large" \| "xx-large" \| "xxx-large"` | Text size on phones and narrow touch screens, kept separate from the desktop size |
| `mobileHeaderStyle` | select | `"current" \| "bare" \| "frosted" \| "seamless" \| "solid" \| "dawn" \| "card" \| "hairline" \| "condensed" \| "island" \| "horizon"` | How the top header looks on phones. Changes apply live. Experimental. |
| `mobileInstantShell` | toggle | `true \| false` | Opens the app instantly from the last downloaded version and fetches updates in the background (you are at most one open behind). Turn off to always wait for the newest version on every open. |
| `mobileReliabilityAlertsEnabled` | toggle | `true \| false` | Get one inbox alert if a device opens the mobile web app but never finishes loading (a sign the mobile app is broken on that device); it clears itself when the app loads again |
| `mobileRowDensity` | select | `"normal" \| "compact"` | Condense the height of session rows on phones. |
| `narrationMode` | select | `"off" \| "auto" \| "click"` | Choose how new replies are narrated: auto-play, click to play, or don’t narrate |
| `narrationPromptOverride` | text | `string (≤10000)` | Override the built-in prompt used to write the spoken script for each reply |
| `narrationShowReadView` | toggle | `true \| false` | Adds a “Narration” option to the per-message Plain Speak / Original toggle; turn off to hide the readable recap (the play button still works) |
| `narrationVoiceReplyAutoSend` | toggle | `true \| false` | Automatically send your spoken reply after you pause, instead of reviewing and tapping Send |
| `nothariOverviewEnabled` | toggle | `true \| false` | Show a searchable table of every indexed note with its title, summary, and size. On by default whenever the Vault is enabled. |
| `notificationBehavior` | select | `"always" \| "backgrounded" \| "never"` | When to show system notifications: always, backgrounded, or never |
| `notificationHistoryEnabled` | toggle | `true \| false` | Keep a log of recent chimes — which sessions triggered them, whether they played, and why they were suppressed. |
| `notionAutoSyncEnabled` | toggle | `true \| false` | Keep the open Notion board and page in sync automatically: while the board is open and this window is focused, Omniscio quietly re-checks the open page for edits and periodically refreshes the view, pausing when the window is hidden. On by default; turn off to refresh only with the refresh button. |
| `notionInboxEnabled` | toggle | `true \| false` | Surface your recently-edited Notion pages as rows in the unified Inbox, and get a row when a page changes, so you don't have to keep checking Notion. Requires the Notion board (above) to be enabled and connected. Off by default; checks Notion in the background every few minutes only while on. |
| `notionShowImages` | toggle | `true \| false` | Load image blocks when reading a Notion page. Off by default for privacy — like the rest of the integration, external media (images, avatars, covers) is not loaded unless you opt in. While off, an image shows a placeholder with a link to open the page in Notion. |
| `offThreadDbWorkerEnabled` | toggle | `true \| false` | Runs Omniscio's database reads on a background thread instead of the one that draws the window, so a slow disk cannot freeze the interface mid-query. An earlier version made multi-session use slower — reads queued behind each other — and this stayed labelled experimental long after that was fixed; the August 2026 rework of this worker cleared the failure the warning was about. It stays off by default. Takes effect immediately, on or off — no restart needed. |
| `onedriveEnabled` | toggle | `true \| false` | Browse, upload, and manage your Microsoft OneDrive files from the sidebar |
| `openPdfInAppViewer` | toggle | `true \| false` | When on, clicking a PDF opens it in the app's built-in viewer instead of your computer's default PDF app. |
| `opencodeModel` | text | `string (≤120)` | Which model OpenCode runs — Claude (default), Kimi, GPT, or a custom provider/model |
| `otherToolUpdateAlertsEnabled` | toggle | `true \| false` | Inbox card with a one-click Update now whenever one of your other tools falls behind its latest release; a tool installed by hand opens its download page instead. On by default |
| `outboundWebhooksEnabled` | toggle | `true \| false` | Master toggle that enables or pauses outbound webhook event dispatching |
| `panelKeepWarmEnabled` | toggle | `true \| false` | Keeps recently-opened panels — AI Coaching, Calendar, Drive, Sheets, Supermail, and Team Chat — loaded in the background once you’ve opened them, so switching back into one is an instant flip instead of rebuilding and re-fetching it every time. Each panel is held in memory only after its first open. Desktop only. On by default; turn off to load each panel fresh every time (the old behavior). |
| `panelMountStaggerEnabled` | toggle | `true \| false` | Spreads out the building of background session panels after the app starts or reloads, instead of building all of them at once (which can freeze the window for several seconds on launch). The session you’re looking at always loads first and immediately; the rest follow within a few seconds. Off by default while this is being evaluated — turn it on to try it, turn it off to go back to exactly the old behavior. |
| `pasteRichTextAsMarkdown` | toggle | `true \| false` | When pasting from Google Docs, Word, or web pages into the chat composer, convert the HTML formatting to Markdown. Off makes Ctrl+V behave like Ctrl+Shift+V. |
| `pauseAllTesting` | toggle | `true \| false` | Immediately stops any NEW test, typecheck, lint or build run from starting anywhere on this computer, so background testing load stops piling up. Test runs that are already going will finish normally — nothing is killed and no paid cloud run is thrown away. This is the switch to reach for when the machine feels bogged down by agent testing: pausing your sessions does not stop it, because a test run keeps going on its own after the session that started it has stopped. It turns itself back on after about an hour so you can never leave testing off by accident, and restarting Omniscio also turns it back on. Every run that waits because of this says so clearly, so nobody mistakes it for something being broken. |
| `perSessionSubscriptionIsolation` | toggle | `true \| false` | Cuts the cost of each live update when many sessions stream at once, so a busy agent only wakes its own panel instead of nudging every open one. Off by default; turn it on to try it. It re-wires instantly with no restart, and it never changes what your sessions do. |
| `personaPromptEnabled` | toggle | `true \| false` | Give every agent a warm, resourceful, get-it-done character up front — agentic, plain-spoken, and biased toward action and yes. |
| `piModel` | text | `string (≤120)` | Which model Pi runs as a coding agent, picked from your configured provider |
| `pickerToolIds` | list | `array of string` | Choose which tools appear in the new-session picker (Claude Code is always available) |
| `pikaVoiceId` | text | `string (≤100)` | Choose a preset Pika voice for text-to-speech playback |
| `pluginAutoCheckUpdates` | toggle | `true \| false` | Keeps your installed plugins up to date: an update that asks for nothing new is applied by itself, in the background, and a newer version wanting access you have not approved asks you first. |
| `pmCalendarBoardIds` | list | `array of string (≤200)` | Restrict which boards appear on the calendar overlay. Empty means all boards. |
| `pmCalendarOverlayEnabled` | toggle | `true \| false` | Show item due dates and sprint timelines from your projects as an overlay on the Calendar, color-coded by project. |
| `pmInboxBoardPreferences` | map | `map of string → "all" \| "assigned-only" \| "none"` | Control which events each board sends to the Inbox: all events, assigned to me only, or none. |
| `pmInboxDigestMode` | toggle | `true \| false` | Batch project events into a single digest notification instead of notifying for each event. Overdue items always notify immediately. |
| `pmInboxEnabled` | toggle | `true \| false` | Surface project events (assignments, status changes, due dates) as rows in the unified Inbox so you notice them without checking the project. |
| `pmInboxQuietHoursEnabled` | toggle | `true \| false` | Pause project event notifications during a daily window. Overdue items always notify immediately. |
| `pmInboxQuietHoursEnd` | text | `string` | The time each day when project event notifications resume. |
| `pmInboxQuietHoursStart` | text | `string` | The time each day when project event notifications pause. |
| `pmInboxQuietHoursTimeZone` | text | `string (≤64)` | The timezone used for quiet hours. Defaults to the system timezone when not set. |
| `pmSetupPreset` | select | `"tasks" \| "projects" \| "operations" \| "first-agent-board" \| "trello" \| "jira" \| "asana" \| "linear" \| "notion" \| "clickup" \| "airtable" \| "engineering-linear" \| "engineering-jira"` | The active PM preset (Tasks, Projects, or Operations) chosen during the setup wizard. Controls which columns, views, and features are surfaced. |
| `pomodoroAutoEnableFocusModeDefault` | toggle | `true \| false` | When on, starting a focus block silences notifications via Focus Mode; breaks release them. Manually toggling the bell icon during a run stops Pomodoro from managing it for the rest of the run. Per-preset overrides still win. |
| `pomodoroPhaseForeground` | toggle | `true \| false` | Raise the Omniscio window above other apps on each Pomodoro phase transition (focus → break and back). Off by default — most users prefer just the chime. |
| `pomodoroScheduleEnabled` | toggle | `true \| false` | Allow weekday rules to auto-start Pomodoro runs at their scheduled times (turn off to silence the scheduler without deleting rules) |
| `postSendNavigation` | list | `array of "stay" \| "next_in_project" \| "next_in_inbox" \| "waiting_room"` | What happens after sending a message: stay, next session, or clear panel |
| `prCommentAlertHandoff` | select | `"session" \| "card-only"` | If the AI session that opened the PR is still running, it also gets the comment so it can tell you and suggest a reply. It never starts a new session, and only comments from people with write access are handed over. |
| `prCommentAlertScope` | select | `"account" \| "this-computer"` | When someone comments on a pull request you opened, you get an inbox card. Choose whether this computer hears about every PR your GitHub account opened, or only the PRs opened from this computer. |
| `prInboxEnabled` | toggle | `true \| false` | Surface GitHub pull requests waiting on you — review requested from you, plus your own PRs that have changes requested — as rows in the unified Inbox. Requires the Pull Requests tab (above) to be enabled and the GitHub CLI (gh) signed in. Off by default; checks GitHub in the background every few minutes only while on. |
| `prMergeQueueAutoMergeDryRun` | toggle | `true \| false` | Log what the daemon would auto-merge each tick, but do not actually spawn Claude sessions. Useful for previewing behavior before going live. |
| `prMergeQueueAutoMergePollMinutes` | number | `number` | How often the auto-merge daemon re-checks each repo for new fast-lane PRs (1-120 minutes) |
| `prMergeQueueEnabled` | toggle | `true \| false` | Adds the PR Merge Queue sidebar entry and toolbar icon for triaging open pull requests across configured GitHub repos. |
| `prMergeQueueShardCount` | number | `number` | How many machines share the PR merge workload when splitting across machines |
| `prMergeQueueShardEnabled` | toggle | `true \| false` | Run the auto-merge daemon on two or more machines so each handles a different, non-overlapping share of the open PRs and no two machines merge the same PR |
| `prMergeQueueShardIndex` | number | `number` | The slot number for this machine in the split (each machine gets a different number, starting at 0) |
| `prSpawnerBatchSize` | number | `integer 1..50` | How many pull requests one session works through. Bigger batches are markedly cheaper: measured across 343 real sessions, 7 per session cost $11.43 per pull request against $30.94 when each got its own session, because the session’s start-up reading is paid once and shared. Pull requests being held for your review are always worked alone, whatever this says. |
| `prSpawnerMaxSessions` | number | `integer 1..100` | How many agent sessions may be working on pull requests at the same time. Lower it when you want the machine back; raise it to drain a backlog faster. Sessions already running are never cut off — the limit only decides whether a new one starts. |
| `preloadSessionsEnabled` | toggle | `true \| false` | Keeps one blank session ready in each hub so starting a new session (Ctrl+T) is instant. When off, new sessions spawn on demand — a bit slower but uses fewer resources. On by default. |
| `prerenderInboxSessionsEnabled` | toggle | `true \| false` | Pre-builds your most recent inbox (needs-you) sessions in the background so switching into them is instant. A built-in limit keeps the app fast even when the inbox is large — older inbox sessions load in about half a second when you open them. On by default; turn off to do no inbox pre-rendering at all. |
| `projectsSidebarHidden` | toggle | `true \| false` | Collapse the hubs sidebar to maximize chat area. A thin edge gutter remains clickable to re-open it. Shortcut: Ctrl+\ |
| `promoteRealMessages` | toggle | `true \| false` | Show the agent’s in-between commentary (headings, lists, longer prose) as regular message bubbles instead of folding it into the activity row. |
| `providerConfigSyncAuto` | toggle | `true \| false` | Runs a background re-sync about every 6 hours so the target tools pick up changes to your instructions and MCP servers. Off means manual sync only. |
| `providerConfigSyncEnabled` | toggle | `true \| false` | Sync your AI provider configuration (skills, instructions) to other installed AI tools. |
| `providerConfigSyncInstructions` | toggle | `true \| false` | Mirror your agent instructions into the target tools global instructions file. |
| `providerConfigSyncSkills` | toggle | `true \| false` | Install your skills (SKILL.md folders) into the target tools so you can run them there. |
| `providerConfigSyncTargets` | list | `array of string (≤100)` | Which AI tools receive your synced config — Codex, Gemini, OpenCode, Cursor. Only installed tools sync. |
| `questionWidgetEnabled` | toggle | `true \| false` | Show an interactive wizard for answering structured questions instead of typing responses manually |
| `quickChatHotkeysEnabled` | toggle | `true \| false` | When on, the per-target hotkeys you assign open the Quick Launch composer pre-aimed at that person or channel |
| `quickEmailRecipients` | list | `array of object { email: string (≤320); hotkey: string (≤100) \| array of string (≤100); id: string (≤64); name: string (≤100) }` | Up to 6 saved addresses you can reach from the Quick Email composer |
| `quickEmailSignature` | text | `string (≤1000)` | A short sign-off appended to the bottom of every quick email you send, after a blank line |
| `quickEmailUndoSeconds` | number | `integer 1..30` | After hitting send, Quick Email shows an Undo toast for this long before actually sending |
| `quickLaunchFollowCursor` | toggle | `true \| false` | Open Quick Launch on whichever monitor your mouse is on, instead of always the primary display |
| `quickLaunchHotkey` | unknown | `string (≤100) \| array of string (≤100)` | Floating composer hotkey for starting a new session from anywhere |
| `quickLaunchPreserveDraft` | toggle | `true \| false` | Keep your Quick Launch draft when you close the popup without sending, instead of starting blank |
| `quickLaunchShowHarnessPicker` | toggle | `true \| false` | Add an optional engine + model chooser to the Quick Launch Session tab so you can start a session on a different engine or model |
| `qwFormatHintInjectionEnabled` | toggle | `true \| false` | Silently appends a short formatting hint to the FIRST message you send in each new session so the agent shapes its clarifying questions to trigger the QuestionWidget parser. The hint is invisible in your chat bubble — only the outgoing prompt carries it. Turn off if you don't want the hint reaching the model. |
| `qwMissReportingEnabled` | toggle | `true \| false` | Show the "Report missed question widget" menu item on agent messages. Captures parser misses as pending fixtures so the parser team can investigate. |
| `qwRaisedChromeEnabled` | toggle | `true \| false` | Give the question widget's option buttons and Send button the same glossy, raised 3D look as the app's filled buttons — a soft top sheen and a drop shadow. On by default; turn off for flat buttons. |
| `qwRecommendedHighlightEnabled` | toggle | `true \| false` | Outline the option the agent recommends (its text ends with "(recommended)") with a soft green glow in the question widget. On by default. |
| `readLoopBreakerEnabled` | toggle | `true \| false` | When an agent gets stuck repeating the same action over and over — re-reading the same unchanged file, or running the same command again and again — Omniscio breaks the loop and re-launches it to continue, instead of letting it spin and burn through your usage. |
| `realConversationLayoutEnabled` | toggle | `true \| false` | Show just your messages and the agent’s final replies. Per-turn tool work folds into a collapsed “N actions” pill you can expand on demand. The single biggest render-cost reduction on busy sessions. Off = the legacy stream of every intermediate step. |
| `recipeApprovalTimeoutDays` | number | `integer 1..90` | Default wait time before a recipe approval gate auto-resolves. Applies only when the step does not specify its own timeout. 7 days by default. Range 1-90. |
| `redactPastedSecrets` | toggle | `true \| false` | Replaces API keys and secrets you paste into a chat with a placeholder before the message is saved, so your keys aren't stored in plain text on this computer. The agent still receives the real key to act on. |
| `reduceTerminalPopups` | toggle | `true \| false` | Stop stray terminal windows from popping up and stealing focus while agents run commands — switches the Windows default terminal to the classic Console Host (Windows only, reversible) |
| `refreshTitleModel` | text | `string (≤100)` | Per-feature model override for staleness checks and title refreshes (Journey, Latest Topic, and Custom with refresh enabled) — Automatic uses a fast, low-cost model |
| `relentlessSessionRelaunch` | toggle | `true \| false` | When a session that was running fails to launch because the machine is momentarily overloaded (a transient OS hiccup), keep retrying — with a growing gap between tries — until it comes back, instead of giving up after a few attempts. Genuine errors still stop and turn red. |
| `replySuggestionModel` | text | `string (≤100)` | Per-feature model override for email, SMS, and Telegram reply suggestions — null inherits the global Utility AI model |
| `requireApprovalForAiSessionSpawn` | toggle | `true \| false` | Off by default — trusted AI orchestration runs without friction. Turn ON if you want a human-in-the-loop checkpoint before any AI-initiated session spawns. |
| `requireApprovalForCliAdminActions` | toggle | `true \| false` | Commands an agent could otherwise take on its own: claiming the public support address, letting — or stopping — a project’s cloud box read its repository, moving live sessions between Overseers, and starting (a paid session) or deleting (irreversibly) the abandoned worktree of someone who has gone. |
| `requireApprovalForCliAiCoaching` | toggle | `true \| false` | Coaching artifact edits, and interviews (an interview spawns Claude). |
| `requireApprovalForCliAwayMode` | toggle | `true \| false` | Creating, editing or deleting auto-run rules. |
| `requireApprovalForCliCaptureAi` | toggle | `true \| false` | Auto-titling a snip or summarizing a recording via the CLI calls the paid Anthropic API. |
| `requireApprovalForCliDrip` | toggle | `true \| false` | Drip campaigns + their folder / book sources. |
| `requireApprovalForCliEmailSummarizer` | toggle | `true \| false` | Email-summarizer rule changes + setup wizard. |
| `requireApprovalForCliGmailSend` | toggle | `true \| false` | Sending, replying to, or forwarding an email via the CLI sends a real email to a recipient. |
| `requireApprovalForCliIntakeSources` | toggle | `true \| false` | Enabling a bug-intake source arms a recurring paid poll. |
| `requireApprovalForCliKmsDelete` | toggle | `true \| false` | Deleting a Vault note, tag, or image via the CLI. Notes move to the vault trash (recoverable). |
| `requireApprovalForCliKmsImageAnalysis` | toggle | `true \| false` | Analyzing Vault images via the CLI calls the paid Anthropic vision API. |
| `requireApprovalForCliKmsSummary` | toggle | `true \| false` | Generating or bulk-seeding Vault note summaries via the CLI calls the paid Anthropic API. |
| `requireApprovalForCliMeetingsAi` | toggle | `true \| false` | AI-enhancing a meeting note (Generate notes) via the CLI calls the paid Anthropic API. |
| `requireApprovalForCliMemoryArchive` | toggle | `true \| false` | Archiving, restoring, or editing a memory via the CLI (all recoverable). Hard delete is separate and always requires approval. |
| `requireApprovalForCliNightyTidyRun` | toggle | `true \| false` | Running an audit now spawns a real Claude session (costs money). |
| `requireApprovalForCliPluginToggle` | toggle | `true \| false` | Installing or enabling a plugin via the CLI activates its code (UI, backend, and any scheduled work); uninstalling deletes its files. |
| `requireApprovalForCliProjectDelete` | toggle | `true \| false` | Deleting a project (soft-delete — recoverable) or a sidebar group (its projects become ungrouped). |
| `requireApprovalForCliProjectEdits` | toggle | `true \| false` | Bug-intake settings and project doc uploads / deletes. |
| `requireApprovalForCliRecipeRun` | toggle | `true \| false` | Running a recipe spawns a real Claude session (costs money). |
| `requireApprovalForCliSessionHandoff` | toggle | `true \| false` | Handing a session off summarizes it (a paid AI call) and spawns a fresh successor session that continues its work. |
| `requireApprovalForCliSessionLifecycle` | toggle | `true \| false` | Pausing, unpausing, snoozing or archiving a session. |
| `requireApprovalForCliSessionRerun` | toggle | `true \| false` | Re-running from a message forks a new Claude session (costs money). |
| `requireApprovalForCliSettings` | toggle | `true \| false` | Changing an app setting via the CLI (Settings → any toggle). |
| `requireApprovalForCliShareSend` | toggle | `true \| false` | Delivering a share link via the CLI sends a real email / SMS / Slack message to a recipient (SMS counts against your monthly limit). |
| `requireApprovalForCliSlackSend` | toggle | `true \| false` | Posting a Slack message via the CLI puts words in front of real people in a real channel. |
| `requireApprovalForCliSmsSend` | toggle | `true \| false` | Sending a text via the CLI sends a real SMS (counts against your monthly limit). |
| `requireApprovalForCliSupermailControl` | toggle | `true \| false` | Writing sensitive Supermail settings (AI-filter rule, filter mode, master on/off) or dispatching destructive commands (send, trash, sign-out, …) from the CLI. |
| `requireApprovalForCliSupermailFilters` | toggle | `true \| false` | Creating, editing, deleting, or reordering a Supermail filter rule from the CLI changes how your incoming mail is triaged from then on. Seeds OFF: rule writes apply immediately (an agent building filters for you is the normal flow) — turn it on to review each change first. |
| `requireApprovalForCliSupermailSend` | toggle | `true \| false` | Sending or replying to an email via Supermail sends a real email; opening a thread assistant spawns a paid Claude session. One switch governs all three. |
| `requireApprovalForCliTags` | toggle | `true \| false` | Creating, renaming or deleting tags in the library. |
| `requireApprovalForCliTasksV2Ai` | toggle | `true \| false` | Tasks ranking, daily check-ins, task breakdowns, and launching a task agent — all call or spawn paid Claude. |
| `requireApprovalForCliTelegramSend` | toggle | `true \| false` | Sending, editing, deleting, or forwarding a Telegram message via the CLI is a real action a real person sees. |
| `requireMobileDeviceApproval` | toggle | `true \| false` | When on, a new phone must be approved from this desktop before it can do anything — a leaked pairing token alone cannot access your data |
| `requireSpawnSourceSession` | toggle | `true \| false` | When on, a session spawned over the command-line API is rejected unless the caller says which session requested it (the X-AMC-Source-Session-Id header — Omniscio-spawned agents have it as $AMC_SESSION_ID). Keeps every spawned session traceable to its origin. On by default — turn off to allow anonymous script or manual spawns. |
| `reserveUiCoreEnabled` | toggle | `true \| false` | Sets aside a full performance (P) core just for Omniscio's window, so a swarm of running sessions can never freeze the interface by crowding it off the CPU. Your sessions are kept off the reserved core and share the rest — they give up about 6% of the cores and keep running normally, while Omniscio always has a clear core to stay responsive. Best for heavy multi-session use on a powerful hybrid CPU (Intel 12th-gen+ Alder Lake, Raptor Lake, Core Ultra). No effect on non-hybrid CPUs or non-Windows systems, and it steps aside automatically during a CPU burst. Off by default. |
| `rssDigestEnabled` | toggle | `true \| false` | AI-curated morning briefing summarising your RSS feeds |
| `rssDigestInterests` | text | `string (≤1000)` | Personalise the digest by listing topics you care about |
| `rssDigestTime` | text | `string` | Time of day the daily digest is delivered |
| `rssEnabled` | toggle | `true \| false` | Subscribe to RSS and Atom feeds in the sidebar |
| `runningAppsEnabled` | toggle | `true \| false` | Show the Running Apps entry in the sidebar — a live list of the dev servers Omniscio launched through the bundled portless proxy at their .localhost URLs. |
| `scheduledMessagesEnabled` | toggle | `true \| false` | Surfaces the Scheduled Messages virtual project — compose a rich-markdown note to yourself and have it dropped into your inbox once or on a recurring schedule. |
| `screenRecorderEnabled` | toggle | `true \| false` | Show the Screen Recording entry in the sidebar — record your screen (webcam, multi-source, hotkeys) with an editor and library. |
| `screenshotsEnabled` | toggle | `true \| false` | Show the Screenshots entry in the sidebar — snip a region of your screen with a global hotkey, then annotate, copy, and browse them in a library. |
| `sessionAdaptiveEcoreAffinity` | toggle | `true \| false` | On hybrid CPUs (Intel 12th-gen+ Alder Lake, Raptor Lake, Core Ultra), confines Claude CLI sessions to the efficiency (E) cores when host CPU averages above 85%, releasing them back to all cores when it drops below 60%. Lets sessions keep grinding while the performance (P) cores stay available for Omniscio and Chrome. No effect on non-hybrid CPUs or non-Windows systems — the setting is safe to leave on; it stays a no-op when the host doesn't support it. |
| `sessionAdaptiveMemoryPaging` | toggle | `true \| false` | When your machine runs low on memory, Omniscio tells busy sessions (and the tests they run) to keep less in fast RAM and spill the rest to the disk pagefile. Sessions keep running — they just slow down until memory frees up. Kicks in only above ~85% RAM use and lifts automatically below ~70%. Never affects Omniscio itself, and never cancels, blocks, or kills anything. No effect on macOS or Linux. |
| `sessionAutoFocusInput` | toggle | `true \| false` | Automatically place cursor in the text box when switching sessions. When off, press R to focus the input (Gmail-style). |
| `sessionCpuCapEnabled` | toggle | `true \| false` | Soft-caps the combined CPU usage of all Omniscio Claude CLI processes (sessions, subagents, test runs, builds — everything they spawn) when the host is contended. An isolated single session can still use the full machine; the cap only kicks in when other things want CPU. Below-normal process priority is also applied so Omniscio yields to your foreground apps. No effect on macOS or Linux. |
| `sessionCpuCapPercent` | number | `integer 25..90` | Maximum percentage of total host CPU that all Omniscio Claude processes can use combined when contended. Lower = friendlier to your foreground apps, slower for batch work. Range 25-90, step 5. |
| `sessionCpuCapStrict` | toggle | `true \| false` | By default the cap is soft: it only kicks in when other apps want CPU, so a single session you are waiting on can still use the whole machine. Turn this on to make the cap a hard ceiling — Omniscio sessions can never go above the percentage above, even when nothing else is running. Guarantees the limit, but can slow a lone session. No effect on macOS or Linux. |
| `sessionForensicsAutoWeeklyEnabled` | toggle | `true \| false` | When on, the deep analysis runs on its own once a week (Monday morning). It spawns a paid session and respects the daily spend cap above. |
| `sessionForensicsDailyCostCapUsd` | number | `number 0.05..20` | Maximum the opt-in deep analysis run can spend per calendar day before it is refused (it spawns a paid session). |
| `sessionForensicsScanIntervalHours` | number | `integer 1..168` | How often the free deterministic friction scan runs (1-168 hours). |
| `sessionMaxProcessesEnabled` | toggle | `true \| false` | Puts a kernel-level ceiling on how many processes a single Omniscio session can run at once, so one misbehaving agent (a runaway loop, a fork bomb, an over-parallel command) can't flood the machine and freeze it. The ceiling is generous — far above any normal session — so it only ever stops a genuine runaway; new processes past it simply fail until some finish, and nothing already running is killed. No effect on macOS or Linux. |
| `sessionMemoryGuardEnabled` | toggle | `true \| false` | When your computer is running low on memory, pause starting NEW sessions that arrive in a burst (auto-created bug/feature sessions, recipe runs, mass restarts) until memory frees up — so a flood of sessions can't drive the machine into a freeze. A single session you open by hand is never delayed, and any held session always starts within a few seconds. Sessions resuming after an app restart are always paced this way regardless of this toggle. Works on every platform. |
| `sessionMemoryGuardPercent` | number | `integer 50..95` | Start holding new burst sessions once total system memory in use reaches this percentage. Lower = more cautious (holds sooner); higher = only holds when memory is nearly full. Range 50-95, step 5. |
| `sessionRefillAllowReopenUserClosed` | toggle | `true \| false` | Off by default, and worth understanding before you turn it on. Normally the governor never restarts a session you closed — closing one is a decision, and undoing it stays yours. With this on, sessions you closed count as restartable too. It never touches a session you stopped with Stop: a Stop holds until you restart or message that session yourself, with this switch on or off. It is the only way to reach work you closed in bulk earlier, and it is easy to under-count: on one machine 136 sessions were waiting behind this switch. The risk is the same one that keeps it off — a session parked on purpose comes back. |
| `sessionRefillBatch` | number | `integer 1..20` | How many sessions to revive at most on each 5-minute check. |
| `sessionRefillCooldownMinutes` | number | `integer 1..1440` | Do not re-poke the same session within this many minutes. |
| `sessionRefillDailySpendCapUSD` | number | `number 0..100000` | The most the governor may spend per day reviving sessions. Only pay-per-use sessions count (API keys and per-token vendors) — a session on one of your Claude Pro/Max subscription accounts costs nothing extra, so it does not count. Once today’s revives reach this, it pauses until tomorrow. Set 0 to turn the $ cap off (the daily revive-count limit still applies). |
| `sessionRefillIncludePaused` | toggle | `true \| false` | Normally only interrupted work is restarted — a session that crashed, was cut off, or failed to answer. Turn this on and a session you PAUSED counts too, and gets un-paused when its turn comes. Off by default: pausing is something you did on purpose, so undoing it stays your call. |
| `sessionRefillMaxCandidateAgeHours` | number | `integer 1..720` | A session whose last activity is older than this is skipped. Abandoned work is not restarted merely because it was interrupted. |
| `sessionRefillMaxRevivesPerSessionPerDay` | number | `integer 1..50` | How many times one session may be restarted in a single day. The cooldown above is only a delay; this is a budget, and it is what stops the governor circling back to the same session over and over. Leave it at 1 unless you specifically want repeat nudges. |
| `sessionRefillTargetCount` | number | `integer 1..500` | When fewer than this many sessions are running, the governor restarts recently-active INTERRUPTED work sessions until you are back to this number. Interrupted means the turn ended abnormally and left work unfinished — the process stopped mid-work, or the turn failed to deliver an answer. It never restarts a session that finished its turn cleanly, one that is waiting on you, one you stopped yourself, or one that recovers on its own. |
| `sessionRestartSpacingSeconds` | number | `number 0..30` | When several sessions come back at the same time (restored after an app restart, auto-recovered from a rate limit, or restarted together from Manage sessions), this is how far apart Omniscio spaces their starts, so a big batch does not storm your computer all at once — and no more than a handful of them are ever working at once. While the app is still opening it may start them sooner than this, but only once your computer has room to spare. If things get busy again it slows back down. Sessions you start or restart by hand, one at a time, are never delayed. Set to 0 to fall back to the built-in spacing. Takes effect immediately, no restart needed. |
| `sessionSelfArchiveWithoutApproval` | toggle | `true \| false` | When ON, a session that has finished its work can archive itself immediately — even if "Require approval for session pause / snooze / archive" is on — with nothing landing in your inbox. Only a session archiving itself is exempt; archiving another session over the CLI still asks. Off by default. |
| `sessionStoreV2Enabled` | toggle | `true \| false` | Runs the rebuilt session engine (V2) behind your session list, switching, and history. On by default — it behaves identically to the old engine but is built on cleaner internals. Switch it off only if you notice a problem, then restart the app to apply (the engine is chosen when the app starts). |
| `sessionStrictMcpConfig` | toggle | `true \| false` | Each session normally starts every tool server listed in your global Claude config — including ones it never uses, like the Playwright browser tool, which can take roughly 95 MB of memory each. With many sessions open those idle tool servers pile up into gigabytes of wasted memory and can slow the whole computer down. When on, each session loads only the tools Omniscio actually set up for it, so the waste can not accumulate (and sessions start a touch faster). Your Omniscio tools — memory, The Vault, Google, and custom servers — keep working exactly as before. Applies to Claude sessions; Codex, Gemini, and Cursor are unaffected. On by default. |
| `sessionTitleStyle` | select | `"brief" \| "descriptive" \| "journey" \| "latest_topic" \| "custom"` | Pick how AI-generated session titles are written — Brief, Descriptive, Journey, Latest Topic, or Custom. Journey and Latest Topic auto-refresh as the conversation evolves. |
| `sessionTreeBelowNormalPriority` | toggle | `true \| false` | Runs every Claude session — and everything it spawns (searches, git, builds, tests, subagents) — at Below-Normal priority, so it gives way to the Omniscio window and your other apps when the machine is busy. A session you are waiting on alone still uses the full machine; it only steps aside when something else needs the CPU. This is the lighter, always-safe alternative to a hard CPU cap. Works on Windows and macOS (no effect on Linux). |
| `sessionTreeLowIoPriority` | toggle | `true \| false` | The disk-and-memory sibling of the priority setting above. Runs every Claude session — and everything it spawns — at low disk priority and below-normal memory priority, so when the app needs to read from disk (or pull its own memory back in) it goes first, and Windows frees the sessions’ cached files before the app’s. This is what keeps typing and clicking responsive while many sessions hammer the disk. Sessions at full speed when the app is idle; they only queue behind it under load. Windows only. |
| `sessionsSidebarHidden` | toggle | `true \| false` | Collapse the sessions sidebar to maximize chat area. A thin edge gutter remains clickable to re-open it. Shortcut: Ctrl+Shift+\ |
| `shareCommentsCrosspostTeamChat` | toggle | `true \| false` | Automatically cross-post share comments to the linked Team Chat channel |
| `shareCommentsDefaultOn` | toggle | `true \| false` | When enabled, new shares will have commenting turned on by default |
| `shareCommentsNotifyInbox` | toggle | `true \| false` | Show an inbox notification when someone comments on your shares |
| `sharesAutoOpenOnCreate` | toggle | `true \| false` | Surface a newly created share right away — yours opens in the viewer, an agent’s raises a one-click notification |
| `sharesOpenInApp` | toggle | `true \| false` | When enabled, share links open in the built-in viewer instead of your browser |
| `sheetsEnabled` | toggle | `true \| false` | Browse and edit spreadsheets from the sidebar. |
| `shellCwdPersistNudgeEnabled` | toggle | `true \| false` | Tells each session that its command line stays in whatever folder it moved to, so the agent switches folders once instead of repeating the same switch on every command. That repetition was nearly half of all commands agents ran. |
| `showAlternateProviders` | toggle | `true \| false` | Master toggle for Codex, Gemini, Anti-Gravity, DeepSeek, Kimi, OpenCode, and Cursor in the new-session menu |
| `showBookmarksInToolbar` | toggle | `true \| false` | Show the bookmarks toolbar button + popover. Off by default. When off, the bookmark icon is hidden and the popover is unreachable. Saved bookmark rows are preserved. |
| `showCurrentBranchInHeader` | toggle | `true \| false` | Display the active git branch next to the session name. Can be disabled per hub. |
| `showRecipeLaneSessions` | toggle | `true \| false` | Reveal the per-lane sub-sessions spawned by recipe pipelines. Off by default to keep the sidebar clean — lanes auto-archive on clean completion. Notifications stay silent for lanes regardless. |
| `showSessionContextIndicator` | toggle | `true \| false` | Show the context-percent ring in the session header so you can see how full the context window is at a glance. Hidden by default to keep the header clean. |
| `showSessionVoiceButton` | toggle | `true \| false` | Show the voice/TTS speaker button in the session header for reading agent messages aloud. Hidden by default. Text-to-speech must also be enabled for the button to do anything. |
| `showSubagentActivity` | toggle | `true \| false` | Show a chip in the session UI when the agent has dispatched subagents (Task tool fan-outs) that have been running for more than ~15 seconds, AND a collapsible per-result card in the transcript when each subagent finishes (errors auto-expand, success collapsed). Off by default; both the chip and the cards are hidden. The underlying tracking that keeps the stall watchdog patient during long fan-outs runs regardless of this setting. |
| `showWorktreeCleanupToasts` | toggle | `true \| false` | When you archive a session that already has a pull request, the worktree is cleaned up automatically. This shows a brief notification when that happens. Turn it off for fully silent cleanup. |
| `sidebarPosition` | select | `"left" \| "right"` | Place project and session sidebars on the left or right side of the window |
| `silenceRecipeStepsOnSuccess` | toggle | `true \| false` | Auto-archive mainline recipe step sessions and the orchestrator when they finish cleanly with no errors, questions, or trouble markers (STEP_FAILED:, LANE_FAILED:, PREFLIGHT_FAILED:, NEEDS_ATTENTION:, RECIPE_NEEDS_ATTENTION:). Off by default — flip on to declutter the inbox after long audit runs. |
| `skillSlashAutocomplete` | toggle | `true \| false` | Type / in the composer to pick a skill from a filtering menu |
| `slackEnabled` | toggle | `true \| false` | Monitor Slack channels and DMs in the sidebar |
| `slackPersonalEnabled` | toggle | `true \| false` | Send messages as yourself using OAuth instead of as the bot (requires bot setup first) |
| `smoothLoadEnabled` | toggle | `true \| false` | When many sessions run at once, Omniscio eases up on its own background monitoring so your machine stays responsive — without changing anything your sessions produce. On by default; turn off for the older, always-on monitoring. |
| `smsEnabled` | toggle | `true \| false` | Send and receive text messages via Pushbullet |
| `smsHealthAlertsEnabled` | toggle | `true \| false` | Raise an inbox alert (and one notification) when SMS is on but not working — a missing/expired Pushbullet token or a sustained disconnect. Clears itself once SMS reconnects. |
| `smsNameInferCostCapUsdPerDay` | number | `number 0.05..5` | Maximum spend per calendar day on Haiku calls that infer a friendly name for unknown short codes (e.g. 62438 → "eBay security code"). When the cap is hit, inference pauses until the next day. Range: $0.05 – $5.00. |
| `smsProvider` | select | `"pushbullet" \| "native"` | Pushbullet routes texts through Pushbullet’s cloud. Native (my phone) sends and receives over your own phone’s real SIM via a self-hosted gateway app — no third-party cloud. |
| `snoozeNoteEnabled` | toggle | `true \| false` | Show an optional note field in the snooze palette so you can leave a reminder for future-you. |
| `sonioxVoiceId` | text | `string (≤100)` | Choose a preset Soniox voice for text-to-speech playback |
| `spamFilterAgentEmailEnabled` | toggle | `true \| false` | New email from strangers to your agent's address and your public support address. Caught mail starts no session and gets no reply. |
| `spamFilterCalendarDeleteEvent` | toggle | `true \| false` | Also delete an invite from your Google Calendar when it comes from a sender you marked as spam. Invites the automatic check catches are only hidden, never deleted. Deleted invites stay in Google Calendar's trash for 30 days. |
| `spamFilterCalendarEnabled` | toggle | `true \| false` | Invites from organizers outside your own organization. A caught invite gets no notice. |
| `spamFilterEnabled` | toggle | `true \| false` | Check messages from people you don't know and keep junk in Spam. Messages from people you know are never checked. |
| `spamFilterSmsEnabled` | toggle | `true \| false` | Texts from numbers that aren't saved as contacts and that you have never texted. Short-code senders such as bank and login codes are never checked. |
| `speechifyVoiceId` | text | `string (≤100)` | Choose which Speechify voice to use for text-to-speech playback |
| `stableQuestionPosition` | toggle | `true \| false` | When navigating between multiple questions, lock the question text at a stable position so your eyes don't need to re-track. Pills extend below the locked area. Turn off to return to the legacy behavior where each question renders at its own height. |
| `statusShapeIconsEnabled` | toggle | `true \| false` | Show a small shape icon on session status dots (a bell for needs-you, a question bubble for a question, a clipboard for approvals, an alert for problems) so status is readable without relying on color alone. Turn off for plain colored dots. |
| `stickyNotesEnabled` | toggle | `true \| false` | Enable floating sticky notes on the desktop |
| `streamingThrottleEnabled` | toggle | `true \| false` | Paints rapid streaming text at 30 frames per second instead of on every token, which makes fast Claude responses noticeably smoother and keeps the rest of the app responsive while many sessions stream at once. Default on. Turn off only if you want every keystroke painted as it arrives — costs more CPU and offers no correctness benefit. |
| `streamingThrottleHiddenMs` | number | `integer 100..5000` | How often text from sessions you are NOT currently looking at gets repainted, in milliseconds. Higher = less background work when many sessions stream at once; the session you are viewing always stays smooth. When you switch to a background session it catches up within this window. Default 500. Only applies when smooth streaming output is on. |
| `supermailAiSummaryAutoSenders` | list | `array of string (≤320)` | The senders and domains whose threads the Catch me up AI summary generates automatically on open (the “Chosen senders” mode). |
| `supermailAiSummaryModel` | text | `string (≤120)` | Which AI model writes the Catch me up summary. Leave on the default for the built-in fast, low-cost model. |
| `supermailAiSummaryPrompt` | text | `string (≤4000)` | The prompt the Catch me up AI summary uses. Leave blank for the built-in default. |
| `supermailAiSummaryTrigger` | select | `"manual" \| "auto" \| "selective"` | Whether the Catch me up AI summary runs on a button you click, automatically on every thread, or automatically only for chosen senders. |
| `supermailDensity` | select | `"tight" \| "compact" \| "comfortable" \| "spacious" \| "roomy"` | How much space between emails in the Supermail list — Compact, Comfortable, or Spacious. |
| `supermailEmailsInInbox` | toggle | `true \| false` | Surface each incoming Supermail email as a card in the Omniscio inbox, with an inline reply box so you can respond without opening Supermail. |
| `supermailEnabled` | toggle | `true \| false` | Show the Supermail panel in the sidebar — a native port of the vendored Supermail UI (folders, compose, snooze) on top of Gmail or IMAP. Off by default while the native port is in preview. |
| `supermailHeaderLayout` | select | `"current" \| "unified" \| "rail"` | Choose how the Mail/Sessions switch and mail toolbar are arranged. |
| `supermailInboxBadgeMode` | select | `"unread" \| "total"` | What the number next to Supermail in the sidebar counts — Unread (drops as you read, like Apple Mail / Gmail) or Total in inbox (drops as you archive / snooze / label, like Superhuman) |
| `supermailInboxEnabled` | toggle | `true \| false` | Unread emails from the Supermail plugin |
| `supermailSummaryModel` | text | `string (≤100)` | Per-feature model override for Supermail Catch me up, video summaries, and Archive Digest — null inherits the global Utility AI model |
| `supermailUseAmcGmail` | toggle | `true \| false` | Read your inbox through the Google account you connected in Settings — no separate Supermail sign-in. Turn off to use Supermail's own sign-in. |
| `supplyLists` | map | `map of string → array of object { onlyDuring: "deepseek-peak"; pay: "you" \| "omniscio" \| "company"; vendor: string }` | One ordered list per AI family (DeepSeek, GLM, Kimi, MiniMax, Meta, Qwen, OpenRouter): who pays (your own account or Omniscio credits) and which company serves. A session connects through the first row that can serve; the model you picked never changes. Also editable as JSON. |
| `supportChatEnabled` | toggle | `true \| false` | Show the support chat icon in the toolbar |
| `supportChatOperator` | toggle | `true \| false` | See all support conversations in the inbox (for the support team) |
| `supportChatUserName` | text | `string (≤80)` | Name shown on your support chat messages |
| `tasksEnabled` | toggle | `true \| false` | Show the Tasks entry in the sidebar — nested checklist with due dates, snoozes, and a tasks.md mirror on disk. |
| `tasksV2CatchesEnabled` | toggle | `true \| false` | When a session ends or is archived, a cheap AI pass reads its transcript for follow-up tasks and stages them in the Caught view for you to approve or dismiss. Off skips the scan entirely (no transcript read, no AI spend). |
| `tasksV2CatchesGuidance` | text | `string (≤2000)` | Optional. Tell the AI in your own words what makes a follow-up worth catching (for example "only things I still owe someone" or "skip anything about code"). It steers which suggestions are kept; the format it returns is fixed, so a wording change can never break catching. Leave it empty for the standard behavior. |
| `tasksV2CheckboxSelects` | toggle | `true \| false` | Makes task checkboxes work like email: checking a box picks the task instead of finishing it, so one stray click can never clear a task. An action bar appears as soon as one task is checked, with Done and Dropped on it. Off by default. Holding Ctrl or Shift while clicking always selects, either way. |
| `tasksV2CompactDensity` | toggle | `true \| false` | Tightens the vertical spacing of task rows for a denser list. Off by default; turn it on to fit more tasks on screen. Applies to both the All-Hubs view and each hub outliner. |
| `tasksV2HideCompleted` | toggle | `true \| false` | Hides finished tasks wherever they still show, mainly the Today plate Done section (most tasks archive out of the list when you finish them). Off by default. |
| `tasksV2KeepWarmEnabled` | toggle | `true \| false` | Keeps your Tasks panel loaded in the background once you’ve opened it, so switching back into it is an instant flip instead of rebuilding the list every time. Desktop only. On by default; turn off to load Tasks fresh each time (the old behavior). |
| `tasksV2MemoryEnabled` | toggle | `true \| false` | Journals what you planned vs. finished each day and lets the AI arrange read your real patterns — typical capacity, chronic carry-overs, tasks you keep snoozing. Free: it reads only already-stored data, no AI calls. |
| `tasksV2QuickAddPosition` | select | `"top" \| "bottom"` | Choose where a task you add with the Quick Add row appears in the list. Top puts new tasks above the others (the default); Bottom adds them to the end. |
| `tasksV2Shortcuts` | map | `map of string → array of string (≤50)` | Customize the Tasks command-mode keys — snooze, deadline, archive, done, context, launch agent, break down, command line, focus moves, and the cheat-sheet. |
| `tasksV2ShowCheckboxes` | toggle | `true \| false` | Shows the little checkbox at the start of every task. On by default; turn it off for a cleaner list with no checkboxes. You can still finish a task with the keyboard (x or e), a middle-click on the row, or the row menu. |
| `tasksV2SkipFinishConfirm` | toggle | `true \| false` | Skips the "are you sure?" step when you finish or drop tasks, so a batch clears in one click instead of two. The Undo button still appears every time, and finished tasks go to Archived rather than being deleted, so a mis-click is always recoverable. Deleting tasks always asks, no matter how this is set. Off by default. |
| `teamChatDmAutoClearNeedsReply` | toggle | `true \| false` | A direct message stops showing as needing a reply once you have looked at it. The conversation stays in your list, and a new message brings the tag back. |
| `teamChatDmInboxView` | toggle | `true \| false` | Show a "Needs Reply" section and a People/Threads toggle in the sidebar for direct messages. |
| `teamChatMessageStyle` | select | `"bubbles" \| "clean" \| "compact"` | How Team Chat lays out messages: Bubbles (3D bubbles, your messages on the right), Clean (one calm stream), or Compact (dense). |
| `teamChatNotifyReactions` | toggle | `true \| false` | Show an Inbox notice when someone reacts with an emoji to a message you wrote. Off by default. |
| `teamChatNotifyThreadReplies` | toggle | `true \| false` | Show an Inbox notice when someone replies in a thread to a message you wrote, or @-mentions you in a reply. |
| `teamChatQuoteOnSelect` | toggle | `true \| false` | In Team Chat, show a Quote button when you select text in a message, so you can quote just that passage. The Quote option in the message menu is always available. |
| `teamTimeEnabled` | toggle | `true \| false` | World clock dashboard for managing team members across timezones with live clocks, working-hours status, and a meeting planner. |
| `telegramBotAllowedGroupIds` | list | `array of string (≤32)` | Numeric Telegram group ids the bot will answer in. Empty means the bot ignores every group. |
| `telegramBotAllowedUserIds` | list | `array of string (≤32)` | Numeric Telegram user ids allowed to talk to the bot. Approving a pairing request adds one here. |
| `telegramBotDmPolicy` | select | `"pairing" \| "allowlist" \| "disabled"` | Who may message the bot directly: pairing (unknown senders get a code you approve), allowlist only, or disabled. |
| `telegramBotEnabled` | toggle | `true \| false` | Talk to your agents from Telegram through a BotFather bot. Each chat or forum topic becomes its own agent session. |
| `telegramBotGroupRequireMention` | toggle | `true \| false` | In groups, only respond when the message @mentions the bot or replies to it. |
| `telegramEnabled` | toggle | `true \| false` | View and reply to Telegram messages via MTProto |
| `telegramEngine` | select | `"mtcute" \| "gramjs"` | Choose the MTProto engine: mtcute (maintained, recommended) or legacy GramJS. Switching engines signs you out of Telegram until you reconnect. |
| `telemetryEmailEnabled` | toggle | `true \| false` | Master switch for Omniscio's diagnostic emails from this install. On = the weekly usage digest, plus each crash unless you turn off 'Email crash reports' below. Off silences both; the on-disk crash log, Sentry, and Omniscio triage keep working. |
| `textCorrectionModel` | text | `string (≤100)` | Per-feature model override for AutoHotkey text correction — null inherits the global Utility AI model |
| `theme` | select | `"dark" \| "light" \| "system"` | Dark, light, or system theme |
| `toastDisplayDurationSeconds` | number | `integer 3..30` | How long error and warning toasts stay on screen before dismissing. |
| `toolUpdateNotificationsEnabled` | toggle | `true \| false` | Periodically check your recommended tools and remind you when an update is available — one click updates it in a terminal (Claude Code, Git, GitHub CLI) or quietly in the background (Playwright, AgentMail, Repomix). Off by default |
| `trailingThinkingBoundaryV2Enabled` | toggle | `true \| false` | Fixes a rare case where a late-returning background tool added an "Extended thinking" line after the agent's real answer, which pushed that answer into the collapsed activity section and left only a short acknowledgement visible. Off by default (the clean folded view) — turn it on to recover those answers instead. |
| `treeDiagramWidgetEnabled` | toggle | `true \| false` | When an agent draws a tree with lines and branches, show it as a real tree you can fold and unfold — instead of a fixed-width block whose alignment breaks on a narrow screen. Any single diagram can still be flipped back to the exact text the agent wrote, and copying always gives you that original. |
| `trimOldSubagentOutput` | toggle | `true \| false` | When on, Omniscio clears the hidden sub-agent (Task helper) output from sessions you archived over 14 days ago. Your conversations are untouched and a full backup is taken first; you just lose the raw text of those collapsed "subagent result" cards in old archived sessions. |
| `trustedSheets` | list | `array of object { editableColumns: array of integer 0..702; label: string (≤100); spreadsheetId: string (≤256); taskView: object { categoriesCol: integer 0..702; categoriesTab: string (≤100); completionCol: integer 0..702; dueDateCol: integer 0..702; sectionCol: integer 0..702; sheetTitle: string (≤100); subjectCol: integer 0..702; urlCol: integer 0..702 } }` | Manage which spreadsheets can be edited and restrict editable columns |
| `ttsConfirmationSpeed` | number | `number 0.5..2` | Playback speed for voice command confirmations |
| `ttsEnabled` | toggle | `true \| false` | Have AI responses read aloud in a natural voice |
| `ttsMaxChars` | number | `integer 100..10000` | Limit how much of a message is read aloud (longer messages cost more) |
| `ttsProvider` | select | `"fish-audio" \| "grok" \| "elevenlabs" \| "speechify" \| "pika" \| "soniox" \| "gemini-tts"` | Choose which service reads messages aloud (Fish Audio, Grok, or ElevenLabs) |
| `ttsSpeed` | number | `number 0.5..2` | Playback speed for text-to-speech audio |
| `ttsSummarizationMode` | select | `"verbatim" \| "summarize" \| "auto"` | How long responses are read aloud: auto, always in full, or always summarized |
| `ttsSummarizationThreshold` | number | `number 100..5000` | Responses shorter than this character count are read verbatim; longer responses are summarized |
| `ttsVolume` | number | `number 0..1` | Volume level for text-to-speech playback |
| `typingInsightsEnabled` | toggle | `true \| false` | Measure your real typing speed in the message composer and show it in Statistics |
| `uiLanguage` | select | `"en" \| "en-XA" \| "es" \| "tl" \| "zh-TW" \| "ceb" \| "ilo" \| "hil" \| "war" \| "bcl" \| "pam" \| "pag" \| "id" \| "sr" \| "hi" \| "ur" \| "ro" \| "hu" \| "tr" \| "zh-CN" \| "pt-BR" \| "ja" \| "de" \| "fr" \| "ar" \| "ka" \| "ru" \| "ko" \| "vi" \| "bn" \| "it" \| "th" \| "pl" \| "pa" \| "sw" \| "fa"` | Choose the display language for the interface |
| `usageCascade` | list | `array of object { enabled: true \| false; maxParallel: integer 1..500; provider: string (≤64) }` | The ordered ladder of fallback providers used once every Claude account is at its usage limit, or when the provider a session runs on (GLM, DeepSeek, Kimi, MiniMax) runs out. Each session takes the first one that is on, set up, and not already full. |
| `usageForecastEnabled` | toggle | `true \| false` | Predicted time until your Claude rate-limit window is exhausted |
| `usageForecastWarnHoursFiveHour` | number | `number 0..5` | Notify me when the 5-hour bucket will exhaust within N hours (0 = off, max 5) |
| `usageForecastWarnHoursWeekly` | number | `number 0..168` | Notify me when the weekly limit will exhaust within N hours (0 = off, max 168) |
| `usageTrackingEnabled` | toggle | `true \| false` | When on, Omniscio records which buttons, menus, and sidebar integrations you actually use, so you can see what is used vs never used in the "UI Usage" panel below and decide what to remove or hide. The report stays on this device; anonymous click counts also ride the daily diagnostics digest when Error Reporting is on. |
| `usageWidgetShowFiveHour` | toggle | `true \| false` | Show the 5-hour rolling usage meter inside the usage widget on the toolbar. |
| `usageWidgetShowResets` | toggle | `true \| false` | Show the countdown to the next usage-window reset inside the usage widget on the toolbar. |
| `usageWidgetShowWeekly` | toggle | `true \| false` | Show the weekly usage meter inside the usage widget on the toolbar. |
| `visualTheme` | unknown | `"glassmorphism" \| "linear" \| "warm-charcoal" \| "aurora" \| "soft-depth" \| "neon" \| "spotify" \| "luxury" \| "gradient-sidebar" \| "neumorphic" \| "frosted-tiers" \| "vercel" \| "liquid-glass" \| any` | Choose a dark-mode skin for panels and accents |
| `voiceDictationDelivery` | select | `"auto-send" \| "review-first"` | Whether dictated speech is sent immediately or placed in the composer to review |
| `voiceEnabled` | toggle | `true \| false` | Speak to dictate messages or run hands-free voice commands |
| `voiceL3Enabled` | toggle | `true \| false` | Ask Omniscio about a session by voice: hear a summary or ask a question, hands-free. |
| `voiceL4Enabled` | toggle | `true \| false` | Queue a spoken question to a running session and get notified when its agent answers. |
| `voiceLanguage` | text | `string (≤10)` | Language for speech recognition |
| `voiceReportBackEnabled` | toggle | `true \| false` | Speak the AI response aloud after each voice command result |
| `voiceReportBackMaxChars` | number | `integer 50..10000` | Limit how many characters of the AI response are spoken |
| `voiceSttProvider` | select | `"deepgram" \| "elevenlabs" \| "groq" \| "grok" \| "gemini" \| "meta" \| "openrouter" \| "local"` | Service that converts speech into text (Deepgram, ElevenLabs, Groq Whisper, or the free Built-in engine) |
| `waitConfirmEnabled` | toggle | `true \| false` | When an agent ends on unclear "am I waiting?" wording, quietly ask it to confirm instead of flipping straight to your inbox — the hidden check runs at most once per wait |
| `wakeWordActionMode` | select | `"dictation" \| "command"` | Dictate the transcript into the active session, or run it as an in-app command |
| `wakeWordEnabled` | toggle | `true \| false` | Say “Hey Omniscio” or “Computer” to activate voice commands hands-free |
| `wakeWordEngine` | select | `"openwakeword" \| "picovoice"` | Choose between the free built-in option (the default, no account) and Picovoice (needs a paid access key) |
| `watchingRunningAgentNudgeEnabled` | toggle | `true \| false` | Show a small hint inside a session when you have been watching a running agent for a while, reminding you it will come to your inbox when it is done. Desktop only. |
| `watchingTimeRecapCardEnabled` | toggle | `true \| false` | On a day you spend a lot of time watching agents work, add an inbox card at most once a week with the time and a nudge to run more agents in parallel. |
| `webAccessBindHost` | select | `"0.0.0.0" \| "127.0.0.1"` | Which network interface the mobile-access server listens on |
| `webhooksEnabled` | toggle | `true \| false` | Receive messages from external services like CI/CD pipelines, monitoring tools, or custom apps by giving them a URL to send data to. |
| `weeklySummaryDailyCostCapUsd` | number | `number 0.05..5` | Maximum spend per day on weekly summary Haiku calls before generation pauses. |
| `weeklySummaryEnabled` | toggle | `true \| false` | Generates a summary every Monday at the scheduled hour. Disable to pause future runs; existing summaries stay visible. |
| `weeklySummaryModel` | text | `string (≤100)` | Per-feature model override for the weekly summary analysis phases — null inherits the global Utility AI model |
| `weeklySummaryScheduleHour` | number | `integer 0..23` | Hour-of-day (local time, Monday only) when the weekly summary generates. |
| `wheresMyWorkEnabled` | toggle | `true \| false` | One screen showing what actually happened to your changes: landed on the shared repo, waiting on review, turned down, or stranded with no pull request. |
| `wokenWakeSelfIdentifyEnabled` | toggle | `true \| false` | When on, Omniscio's automatic "keep going" nudges identify themselves as coming from the app (not you), and agents are told any message without that marker is really from you, so a short message like "add this" is not mistaken for a background nudge and brushed off with "Nothing to do here." Off by default. |
| `wordExportEnabled` | toggle | `true \| false` | Show an "Export to Word" option in the export menus (session ⋯ Exports submenu + the Export… button on docs, scratchpads, and messages). Markdown and PDF stay available. Off by default. |
| `worktreeCleanupEnabled` | toggle | `true \| false` | Turns on automatic Worktree Cleanup: a scheduled, load-gated cleanup that reclaims disk by retiring finished git worktrees. It also shows the in-app dashboard with run history, a grid explaining why each worktree is kept or reaped, one-click recovery of a mistakenly-removed worktree, and a "run cleanup now" button. Windows only; off by default. |
| `wsOffloadEnabled` | toggle | `true \| false` | Keeps your phone connected while the app is briefly frozen, by answering your device from a separate thread. Falls back automatically if it cannot start. Takes effect after a restart. |
| `wsTrimIdleMinutes` | number | `integer 0..1440` | Periodically asks Windows to evict the working set of Claude CLI child processes that have been idle for at least this many minutes. Reclaims physical RAM without killing the session — pages re-load on next use (~80 ms). Set to 0 to disable. No effect on macOS or Linux. |
| `zapierEnabled` | toggle | `true \| false` | Connect your Claude sessions to 8,000+ apps via Zapier. Create your MCP server at mcp.zapier.app, then paste the server URL below. |

## CLI / advanced settings (1365)

Settable programmatically via `PATCH /settings/:key` but with no Settings-UI control -- CLI/agent-facing options plus internal remembered state (migration markers, cached values). Listed so every settable key is discoverable.

| Setting | Type | Accepted values | What it does |
| --- | --- | --- | --- |
| `abortedResponseRecoveryEnabled` | toggle | `true \| false` |  |
| `absoluteTurnCapSeconds` | number | `integer 600..86400` | Hard ceiling, in seconds, on how long a SINGLE turn may run before the watchdog ends it. This is the backstop for a turn that keeps producing output but never finishes — the one failure the silence-based `stallThresholdSeconds` can never catch, because every chunk of output resets that timer. Default 14400 (4 hours). Raise it if you run long autonomous audits that legitimately run past 4 hours. It measures ONE turn, not the whole session, and is re-anchored each time a new turn starts (including a recovery respawn). |
| `accountTierModelDefaultsEnabled` | toggle | `true \| false` | Opt-in, default OFF. When on, a Claude session spawned with no explicit model gets a default model stamped from the picked account's plan tier (Max to Opus, Pro to Sonnet, and so on). Off means no behaviour change. Affects which model — and therefore what a turn costs — when you do not choose one. Synonyms: account tier model defaults, pick model from my plan, default model per account, max account uses opus. |
| `activeLayoutModBySurface` | map | `map of string → string` | Which layout mod is active on each app surface — a map of surface to mod id (e.g. sidebar to compact-rail), set by the Appearance "Layouts" toggles. Empty means every surface uses its standard built-in layout. Related: layout mods, Compact Rail, sidebar layout. |
| `admissionBrokerV2Enabled` | toggle | `true \| false` |  |
| `agentChannelKnockPolicies` | map | `map of string → object { knockMode: "all" \| "mentions" \| "none"; maxPerHour: integer 1..60 }` | Per-Team-Chat-channel rules for how often a subscribed agent session is told messages are waiting — knock mode (all messages, mentions only, or none) plus a max knocks per hour, keyed by channel id. Agents are told only the count, never the message text. Empty (the default) uses no special rule. Set from a channel's "Interrupting your agents" control; gated behind the agent-channels feature. |
| `agentChannelsEnabled` | toggle | `true \| false` | In-development: a session can subscribe to a Team Chat channel and be told, at a natural stopping point rather than mid-task, that messages are waiting there. The notice carries only the channel name and how many messages — never the message text — so the agent reads them only when it deliberately chooses to. Each channel sets its own rule (all messages, only mentions, or none) and how often it may interrupt. Off by default and completely inert until switched on. |
| `agentCrewRegistryEnabled` | toggle | `true \| false` | Any session can register a role — overseer or member — into a mission crew, and the app does the rest: a numbered title, seeded heartbeats, who it reports to, and one board for the crew. A member finishing a routine turn checks in with its lead instead of your inbox; only a reply addressed to you ever reaches it. On by default; registering costs nothing, and the toggle stays live so you can turn it off with one setting flip. |
| `agentDeviceEnabled` | toggle | `true \| false` | In-development: your agents on two computers signed into the same account can message each other. Each conversation is a named thread you route to its own session on each computer, so several can run at once; messages arrive framed as another machine's words, never as your own instructions. Every conversation starts muted and out of the way — unmute any of them to read along — and a turn budget stops two agents talking to each other forever. Off by default. |
| `agentDmEnabled` | toggle | `true \| false` | In-development: when you turn this on for a specific person whose connection you have accepted, their agent can send messages directly into one of your local sessions. You choose per person; no one gets access without a deliberate connection. Incoming messages are budgeted and can be cut off instantly. Off by default and completely inert until switched on. |
| `agentEmailAddress` | text | `string (≤320)` |  |
| `agentEmailApprovedSenders` | list | `array of string (≤200)` |  |
| `agentEmailEnabled` | toggle | `true \| false` | In-development: give your agent its own email address. It receives mail (which starts or continues a session) and can reply — powered by the Cloudflare email service Omniscio runs. Ships dark until the email domain is live. |
| `agentEmailReceivingEnabled` | toggle | `true \| false` |  |
| `agentEmailSenderPolicy` | select | `"owner" \| "approved" \| "anyone"` |  |
| `agentEmailSessionProjectPath` | text | `string (≤500)` |  |
| `agentEmailSidebarEnabled` | toggle | `true \| false` |  |
| `agentEmailSupportAddress` | text | `string (≤320)` | The support address for this install — mail addressed TO exactly this address is accepted from ANY sender, because a support desk has to take mail from people who are not on your approved list. Blank (the default) means support is not configured. Every other address keeps your normal approved-sender policy, so turning support on never opens your personal address to strangers; setting it back to blank returns the install to its previous behaviour. Synonyms: support email address, help desk address, which address accepts outside mail, open a support inbox, public support address. |
| `agentEmailSupportReplyFromAddress` | text | `string (≤320)` |  |
| `agentFirewallEnabled` | toggle | `true \| false` | Screen the content tools return (files, web pages, command output) for prompt injection before an agent trusts it. Off by default. |
| `agentFirewallEnforcementLevel` | select | `"advisory" \| "ask" \| "enforce"` | How the Agent Firewall handles content it flags as a possible prompt injection in a tool's output (a file, web page, or command result). "advisory" = warn the agent to treat it as untrusted but continue; "ask" (default) = warn the agent AND raise an inbox alert for you to review; "enforce" = tell the agent the content is blocked. Only applies when the Agent Firewall feature is on and the session is externally-spawned or its project opted in. Synonyms: firewall enforcement level, injection flag handling, advisory vs ask vs enforce, what happens when the firewall flags something. |
| `agentFirewallOptInProjectIds` | list | `array of string` | The list of project ids that opted their sessions into the Agent Firewall injection screening ("available for users"). Externally-spawned/automated sessions are screened regardless of this list; adding a project id here also screens that project's own interactive sessions. Empty by default. Synonyms: firewall opt-in projects, which projects use the agent firewall, enable injection screening for a project. |
| `agentFirewallScreenInteractive` | toggle | `true \| false` | When on, the Agent Firewall ALSO screens your OWN interactive sessions for prompt injection in tool output — not just externally-spawned/automated sessions and per-project opt-ins ("protect everywhere"). Off by default. Only takes effect when the Agent Firewall feature is on; it widens which sessions are screened, it does not turn the firewall on. Synonyms: protect everywhere, screen my own sessions, firewall all sessions, screen interactive sessions. |
| `agentForegroundAlertEnabled` | toggle | `true \| false` |  |
| `agentFrictionPlainLanguage` | toggle | `true \| false` |  |
| `agentFrictionReportsEnabled` | toggle | `true \| false` | In-development: a developer-tools panel showing what keeps costing your agents time — the problems they hit, collapsed so that forty agents hitting one wall read as ONE problem with a count of forty, ranked by measured cost and how often it fires. Shows each cluster's severity, time lost, how many reports came from an agent's judgement versus passive telemetry, and the command and output behind the first sighting, with a Plain English / Technical switch so the list is readable without knowing the jargon. SPENDS MONEY: turning this on also starts the triage loop, which every two hours may start a Claude session to verify the costliest problems and dispatch sessions to fix them — real sessions at real cost. A spending limit (default $25 a day, "Friction triage spending limit") stops new triage runs once it is reached; it cannot recall fixers a running triage session has already started. Turning it off stops all of it — collection, the automatic capture, and the triage loop. Closing a problem out still stays on the CLI. Hidden until shipped. |
| `agentFrictionSidebarEnabled` | toggle | `true \| false` | Whether the Agent Friction item appears in the sidebar (default on). A visibility toggle only — hiding the entry does not turn the feature off and does not stop anything being collected; agentFrictionReportsEnabled is the switch that does both. Settings → Sidebar. Synonyms: hide agent friction from the sidebar, show agent friction, sidebar agent friction item, remove the friction panel from the sidebar, agent friction sidebar visibility. |
| `agentGitThrottleEnabled` | toggle | `true \| false` |  |
| `agentInstallThrottleEnabled` | toggle | `true \| false` |  |
| `agentLanesAnyTeammate` | toggle | `true \| false` |  |
| `agentLanesDailyLimit` | number | `integer 1..10000` |  |
| `agentLanesEnabled` | toggle | `true \| false` | In-development: a direct message with a teammate gains a second tab where your agents talk to each other, kept apart from your own conversation. Neither of you is notified — no push, no unread badge, just a quiet dot on the tab when they have been talking — and either of you can open it and read the whole thing at any time. Once a day you get a single summary of what they worked out. Nothing is sent until both people switch the lane on, and a turn budget stops two agents talking to each other forever. Off by default and completely inert until switched on. |
| `agentLanesGeneralProjectPath` | text | `string (≤500)` |  |
| `agentLanesMessageLimit` | number | `integer 1..10000` |  |
| `agentMarkdownFormattingEnabled` | toggle | `true \| false` | On by default: an agent formats a reply the way it already writes on GitHub — callouts, centred text, sized images, collapsible sections, keyboard keys — and any shape outside that fixed list still prints as literal text, exactly as before. The toggle stays live, so turning it off renders every message as it did before this existed. |
| `agentMessageCardsEnabled` | toggle | `true \| false` | In-development: when an answer carries a lot of information, an agent can split it into cards you page through inside the one message instead of reading one long wall. A card may also carry its own question, and answering one is recorded without starting a new agent turn, so what you answer there comes back as ONE reply. It is for breaking up heavy content — never a substitute for asking several questions in one question widget. Off by default; hidden until shipped. |
| `agentMessagesEnabled` | toggle | `true \| false` | In-development: one place to watch your agents talk to each other — who messaged whom, when, what they said, and whether it arrived. Includes the messages that never arrived, which are recorded but have never been visible anywhere in the app. Read-only: it shows the traffic, it never sends, retries or interrupts you. Off by default; hidden until shipped. |
| `agentPermissionAllowRules` | list | `array of object { commandPrefix: string (≤200); createdAt: string (≤40); id: string (≤100); projectId: string (≤200); toolName: string (≤100) }` | Human-authored allow-rules that pre-approve specific agent actions. Consulted BELOW the dangerous-path denylist, the Clean Room fence, and the email lockdown — a rule can never relax those. Always read `settings.agentPermissionAllowRules ?? []`: an existing config predates the field and getSettings does not merge defaults. Never writable from the CLI control server. |
| `agentScreenCaptureEnabled` | toggle | `true \| false` |  |
| `agentSearchThrottleEnabled` | toggle | `true \| false` |  |
| `agentShellThrottleEnabled` | toggle | `true \| false` |  |
| `agentToolsCollapsed` | toggle | `true \| false` |  |
| `aiBrowserActiveSpaceId` | text | `string (≤256)` |  |
| `aiBrowserAgentControl` | select | `"auto" \| "allowlist" \| "off"` |  |
| `aiBrowserCoDriveEnabled` | toggle | `true \| false` |  |
| `aiBrowserEnabled` | toggle | `true \| false` | Let an Omniscio session drive the in-app Browser panel — the browser you can see — to navigate, read, click, type and screenshot. Reads are always allowed; acting requires the Browser panel open and Omniscio focused, so an agent only ever acts while you are watching. For your own signed-in Chrome instead, use My Real Chrome. |
| `aiBrowserHistoryRetentionDays` | number | `integer 0..3650` |  |
| `aiBrowserKeepWarm` | toggle | `true \| false` |  |
| `aiBrowserMemoryIngestEnabled` | toggle | `true \| false` |  |
| `aiBrowserOriginAllowlist` | list | `array of string` |  |
| `aiBrowserPaused` | toggle | `true \| false` |  |
| `aiBrowserSideChatWidth` | number | `number` |  |
| `aiBrowserSupervisedAgentWrites` | toggle | `true \| false` |  |
| `aiBrowserSupervisedSensitiveWrites` | toggle | `true \| false` |  |
| `aiBrowserTabArchiveAfterHours` | number | `number` |  |
| `aiBrowserTabDiscardAfterMinutes` | number | `number` |  |
| `aiBrowserTabLifecycleEnabled` | toggle | `true \| false` |  |
| `aiBrowserTabSleepAfterMinutes` | number | `number` |  |
| `aiBrowserTabStripOrientation` | select | `"horizontal" \| "vertical"` |  |
| `aiCoachingEnabled` | toggle | `true \| false` | Personalized coaching sessions with structured interviews, artifacts, and progress tracking. |
| `aiCoachingFeedbackDismissed` | toggle | `true \| false` |  |
| `aiCoachingPromptVariant` | select | `"A" \| "B" \| "C"` |  |
| `aiCouncilLaunchSidebarEnabled` | toggle | `true \| false` | Show the AI Council one-click launcher row under Prompt Tools (default true, feature-gated by `multi-model-council`). Mirrors `bakeoffSidebarEnabled`. |
| `aiExperienceLevel` | select | `"new" \| "ai-chat" \| "ai-coding" \| "power-user"` | Your AI-experience level captured once during the Setup v2 onboarding intake ("new", "ai-chat", "ai-coding", or "power-user"). It steers the onboarding flow only — advanced users get the optional extra-engine step and a leaner path; newcomers get a Claude-only, more-guided path. Optional: undefined until answered, treated as the more-guided "new" default. Synonyms: AI experience, skill level, how experienced I am with AI. |
| `aiManager` | object | `object { aiRouterDefaultOnForNewSessions: true \| false; aiRouterDryRunByDefault: true \| false; allowApiKey: true \| false; dailyCapUsd: number 0..100; inboxPilotEvaluatorFallbackEnabled: true \| false; inboxPilotEvaluatorFallbackModel: string (≤200); inboxPilotEvaluatorModel: string (≤200); inboxPilotEvaluatorProvider: "groq" \| "together" \| "deepseek" \| "openrouter" \| "openai" \| "anthropic"; overlay: object { enabled: true \| false; prompt: string (≤75000) }; overlayAllowApiKey: true \| false; overlayDailyCapUsd: number 0..100; overlayDefaultOnMigrated: true \| false; overlayDefaultToPlainSpeak: true \| false; overlayForcedOffMigratedV2: true \| false; overlayInlineAgentGenerated: true \| false; overlayInlineDefaultMigrated: true \| false; overlayPauseRetirementMigratedV1: true \| false; overlayPaused: true \| false; overlayPromptMigratedV8: true \| false; overlayPromptPreV8Backup: string (≤75000); overlayResetBannerPending: true \| false; overlayShipOnMigratedV1: true \| false; overlaySkipPatterns: array of string (≤200); paused: true \| false; plainSpeakIntroSeeded: true \| false; router: object { enabled: true \| false; prompt: string (≤75000) }; routerAllowApiKey: true \| false; routerAutoRespondEnabled: true \| false; routerDailyCapUsd: number 0..100; routerPaused: true \| false; routerScheduleRespondEnabled: true \| false; splitMigrationApplied: true \| false }` |  |
| `aiProjectIconsEnabled` | toggle | `true \| false` | In-development: adds a "Suggest with AI" button to the project icon picker and a "Fill missing icons with AI" batch action. For a project that only shows a generic type badge (no favicon/logo was detected), a quick AI call picks the single most relevant Lucide icon from the full free icon library and applies it. On-demand only, never automatic; each use is a cheap AI call. Off by default; hidden until shipped. |
| `aiSuggestionsEnabled` | toggle | `true \| false` |  |
| `aiSuggestionsEnabledAt` | text | `string (≤100)` |  |
| `aiTeamChatEnabled` | toggle | `true \| false` | In-development: AI-powered features for Team Chat including semantic search, channel summarization, and AI-assisted message composition. |
| `aiTextCorrectionEnabled` | toggle | `true \| false` | Proofread or expand the text you have selected, straight from the Omniscio quick launcher — the corrected text comes back ready to copy. Fully native; it needs no AutoHotkey script. |
| `aiToolsCollapsed` | toggle | `true \| false` |  |
| `aiWriterEnabled` | toggle | `true \| false` | In-development: a standalone writing editor with saved documents, writing guidance, and (in later updates) inline AI editing, options, autocomplete, and a chat assistant. |
| `airtableEnabled` | toggle | `true \| false` | Adds an "Airtable" sidebar tab to view and manage your Airtable bases, tables, and records without leaving Omniscio. Connect with your Personal Access Token in Settings. In development. |
| `airtableInboxEnabled` | toggle | `true \| false` |  |
| `airtableSelectedBaseId` | text | `string (≤200)` |  |
| `airtableSelectedTableId` | text | `string (≤200)` |  |
| `airtableSelectedTableName` | text | `string (≤200)` |  |
| `alertTypeMutes` | map | `map of string → true \| false` | Which individual alert types you have turned off, one dedupKey per muted type (true = muted). Only types you explicitly turn off appear here — an absent key always means that alert still fires, and this is never pre-populated with the full alert catalog. Read once, at the moment an alert is about to be raised, so a type you turned off never comes back no matter which script, cron job, or producer tried to raise it; turning a type back on just removes its key. Controlled from Settings → Notifications → Alert types, and from the quiet mute button on each alert card. Synonyms: alert types, mute an alert, unmute an alert, turn off an alert, disable a notification type, silence this alert, stop this alert, per-alert-type switch, alert off switches, notification type toggle. |
| `alertsSidebarEnabled` | toggle | `true \| false` |  |
| `allowApiKeySessionSpawn` | toggle | `true \| false` | The API-key session-spawn guard. When OFF (the default), API-key accounts can power AI features but CANNOT start sessions — a spawn falls through to a login account, or surfaces the all-exhausted banner if no login account has capacity. Turn it ON to let sessions run on the API key, which means Anthropic bills you per token for that session. Off by default precisely so a pasted key cannot silently start costing money. Enforced in three layers at spawn time. Synonyms: let api keys run sessions, allow api key spawn, run sessions on my api key, api key session guard, stop api keys starting sessions. |
| `allowCrofaiSessionSpawn` | toggle | `true \| false` | Retired: the CrofAI reseller lane. CrofAI is shutting down, so the provider is hidden from every model picker and from Settings → Accounts & Providers. Its catalog entry, models and pricing stay in place so existing sessions and recorded spend still resolve. |
| `allowDeepinfraSessionSpawn` | toggle | `true \| false` |  |
| `allowGeminiccSessionSpawn` | toggle | `true \| false` |  |
| `allowHighRiskCredentialKinds` | toggle | `true \| false` | The high-risk credential gate. When OFF (the default), Omniscio refuses to hand agents the credential kinds with broad access or outbound-abuse potential. Turn it ON only if you deliberately want those credential kinds available. Default false — this one is a security posture setting, not a convenience toggle. Synonyms: allow high risk credentials, broad access credentials, dangerous credential kinds, let agents use risky keys. |
| `allowInferxSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose InferX as a session provider in the new-session menu / spawn ladder. InferX serves DeepSeek V4 Flash — a serverless, pay-per-token OpenAI-compatible endpoint — inside the Claude Code harness, configured via its own API key. Off by default: no InferX sessions can be started until this is enabled. Synonyms: inferx, allow inferx sessions, inferx provider, enable inferx, allow inferx spawn. |
| `allowRuninfraSessionSpawn` | toggle | `true \| false` | Opt-in toggle to expose RunInfra as a session provider in the new-session menu / spawn ladder. RunInfra serves full-precision (BF16) open models — DeepSeek V4 Flash/Pro, Qwen, Nemotron — inside the Claude Code harness at pay-per-token prices (NOT quantized), configured via its own API key. Off by default: no RunInfra sessions can be started until this is enabled. Synonyms: runinfra, allow runinfra sessions, runinfra provider, enable runinfra, allow runinfra spawn. |
| `alreadyUsingAgents` | toggle | `true \| false` | Whether you already run AI agents on this computer, captured once during the Setup v2 onboarding intake (yes/no, default "no"). It steers the onboarding flow only: a "yes" unlocks the preferred-harness pick (and may install + enable Codex); a "no" (the safe default) follows the pure Claude Code path. Optional: undefined until you answer. Synonyms: already using AI agents, run agents on this computer, agent usage. |
| `amcBugReportOperator` | toggle | `true \| false` |  |
| `anthropicStatusMonitorEnabled` | toggle | `true \| false` |  |
| `apiKeysSidebarEnabled` | toggle | `true \| false` |  |
| `appTourCompleted` | toggle | `true \| false` |  |
| `appWorkspaceSwitcherEnabled` | toggle | `true \| false` | In-development: a compact workspace switcher at the top of the Hubs sidebar. It lists every workspace you belong to (Personal first, then your organizations and chat workspaces) and switches which one the app is scoped to, which filters the sidebar to that workspace. Switch-only (no create or join); off by default; hidden until shipped. |
| `approvalsSidebarEnabled` | toggle | `true \| false` |  |
| `arabicPilotEnabled` | toggle | `true \| false` | Adds Arabic (العربية) to the language picker as a machine-translated pilot catalog. Arabic is right-to-left; any untranslated text falls back to English. |
| `archiveCompactionStartedAt` | text | `string (≤64)` | Internal bookkeeping: ISO time the last archive compaction STARTED. An interrupted rewrite leaves the archive un-compacted, so the automatic request waits a week after this before it asks again. Not user-facing. |
| `archiveDigestEnabled` | toggle | `true \| false` | Supermail "Archive Insights" AI digest. When on, Supermail suggests cleanup actions for the senders you archive without reading; to make specific suggestions, the sender and subject of the emails you archive are sent to the AI provider. Off by default. Synonyms: archive insights, AI cleanup digest, archived-sender suggestions. |
| `archiveDigestPreview` | toggle | `true \| false` | In-development: a periodic AI digest of your recently-archived Supermail emails — a daily or weekly summary of what landed in your archive, spotting patterns, recurring senders, and anything worth revisiting. Off by default, and cost-capped. |
| `archivedBundledSkills` | list | `array of string (≤128)` |  |
| `arijEnabled` | toggle | `true \| false` |  |
| `arijProjectFolders` | map | `map of string → string (≤1024)` | Arij backend project id → local working folder. Arij projects live on the amc-back backend and carry no local path, but spawning an agent on an issue needs a folder to work in — this map supplies it (set via the pick-folder prompt on first agent start per project). |
| `asanaBoardEnabled` | toggle | `true \| false` | Adds an "Asana" sidebar tab to view and work your Asana projects — sections as columns, task detail, comments, assignment — without leaving Omniscio. Connect with an Asana personal access token in Settings. In development. |
| `asanaInboxEnabled` | toggle | `true \| false` |  |
| `asanaWorkspaceGid` | text | `string (≤64)` |  |
| `askAboutPageEnabled` | toggle | `true \| false` | A floating button + Ctrl+J open a popover that asks Claude about whatever is on screen. Reveals the keybinding, the corner button, and the popover mount. |
| `askAmcUseCompanyModel` | toggle | `true \| false` |  |
| `askAmcUseLuna` | toggle | `true \| false` |  |
| `askOmniscioPinBackfilled` | toggle | `true \| false` |  |
| `askOmniscioPlacementBackfilled` | toggle | `true \| false` |  |
| `askPageConsentGiven` | toggle | `true \| false` |  |
| `autoApproveAgentReadyOverrides` | toggle | `true \| false` | Auto-approve the ready mint's human-override card instead of waiting for a click (paved-road P19, owner-authorised 2026-09-10). Default OFF — byte-identical to before. WHAT IT CHANGES. When an agent runs `/ready --human-override "<reason>"` on a branch whose EVIDENCE gate is red, the mint raises a `worktree.ready_override` card and refuses `403` until a person clicks Approve. That click is P19's whole mechanism: a credential says who HOLDS it, never who CLICKED, so the inbox row is the one thing an agent cannot forge. ON, the mint approves that card itself and stamps the tag — the lever really does pass to the agent, and that is the point of the setting, not an oversight. WHY IT EXISTS. Measured on this box: 28 cards in one day (2026-09-09), 32 in another 24h, 6 more pending when this shipped — every one approved, none refused. A gate a human clears by hand at a 0% refusal rate is not a gate, it is a queue in front of a person. The owner's standing wish is quoted verbatim in ready-park.ts: "I don't want to have to approve sessions manually tagging their wt for landing." WHAT SURVIVES IT, and these are the design rather than decoration: - The card is still RAISED, still bound to branch + full head sha + the exact checks being waived, still consumed exactly once. The tag still carries `override-approval: [<id>]` and `override-approval-land-veto` still verifies it, so the land path is untouched. - A card the operator REJECTED is still refused. A settings toggle never overturns an explicit human "no" (it binds to that commit only — see the contract's P19 amendment). - The auto-approval is VISIBLE: the card's preview text is stamped and an `ops-ready-override-auto-approved` ledger event names the id, so nothing in the audit trail reads as a human click. - It waives only what a human override already waived — the mint's evidence + corroboration arms. Every LAND-time veto (secret scan, mass-deletion, dependency change, pipeline completion) is unaffected. - FAIL-CLOSED toward the click: an unreadable settings read refuses and raises the card, so a settings fault can never START auto-approving. (Deliberately the opposite direction from gateProofPresenceChecks()'s fail-open, where a fault must never start refusing.) HOW IT IS ARMED. It stays on `PIPELINE_ARMING_SETTING_KEYS` (RT-F021), so BOTH broad remote transports still refuse it: `PATCH /settings/:key` and the mobile/web WS bridge. Turning it on in the app is Dev Pipeline -> Setup -> Auto-lander. There is ALSO one dedicated action — `PATCH /auto-lander/ready-override-arming` (owner-authorised 2026-09-13) — which admits only the machine's own full-trust cli-token and refuses the scoped per-session agent token and an in-app key, exactly like `PATCH /auto-lander/arming` does for `autoLanderEnabled`. The denylist is not bypassed; the arming CHECK moves to `isArmingActionAllowed`, the predicate built for it. Why that is not the hole P19 closed: the global token already reaches the LANDER's arming route, and arming the lander is strictly more powerful than auto-approving a ready override — one puts code on master unattended, the other only lets a tag be stamped over a red evidence lane that the lander still judges. Leaving the weaker lever harder to reach than the stronger one bought no safety, only a click. Read live per mint — flipping it needs no restart. See agent-git-paved-road-invariants-contract.md P19. |
| `autoArchiveOnLand` | toggle | `true \| false` | When on (default), a session whose branch successfully lands (is merged to master by the auto-lander) is automatically archived off your board — with a safety guard that leaves a session alone if it still needs you. Off: a landed session stays visible until you archive it. It's the "landed sessions clear themselves" backstop. |
| `autoBackupDir` | text | `string (≤1024)` | Absolute path to a custom auto-backup directory on a DIFFERENT volume from the primary database. Empty string = use the default `<userData>/backups/auto/` (same-volume). When set to a valid absolute path, the auto-backup ring writes there instead, so a single-disk failure cannot destroy both the DB and the backups (audit F001). The getter validates `isAbsolute()` at runtime — a relative or empty string silently falls through to the default. |
| `autoCapitalizeQuickEmail` | toggle | `true \| false` | Auto-capitalize the Quick Email body as you type — the first word, sentence starts (after . ! ?), and the start of each new paragraph/line — while skipping URLs, paths, and abbreviations. Reuses the shared smart-capitalize system (the same one the Tasks input + KMS notes use). FREE local transform, never spends. Default ON (opt-out). Synonyms: quick email auto-capitalize, smart capitalization, capitalize sentences/paragraphs in the quick email body. |
| `autoColorMatchProject` | toggle | `true \| false` |  |
| `autoColorRules` | list | `array of object { color: string; id: string; keyword: string }` |  |
| `autoContinueMaxConsecutive` | number | `integer 1..20` |  |
| `autoDeployFirestoreIndexes` | toggle | `true \| false` | When on (default), after a branch that changed the Firestore indexes lands on master, Omniscio automatically deploys the new indexes (firebase deploy --only firestore:indexes) so a committed index change never sits undeployed and breaks a query with FAILED_PRECONDITION. SAFETY: it only auto-deploys purely-additive changes (new indexes); a change that would remove or alter a live index is never auto-deployed — you get an inbox alert to deploy it by hand. Off: the ~6-hourly drift check still alerts you but nothing deploys automatically. Kill-switch env var AMC_DISABLE_INDEXES_AUTODEPLOY_ON_LAND=1. |
| `autoDeployFirestoreRules` | toggle | `true \| false` |  |
| `autoDeployFunctions` | toggle | `true \| false` | When on, after a branch that changed the Cloud Functions lands on master, Omniscio runs the Cloud Functions drift CHECK — a read-only comparison of the committed functions against the live deployed set — and raises its card when the two disagree, so a committed function change never sits undeployed behind the repo with nobody told. That matters most on the local flow, where functions otherwise only deploy via GitHub Actions on a push the auto-lander never makes. OFF by default. The name is legacy and does not describe what it does: this setting never deploys anything, and it cannot — the checker is run without its --auto-deploy flag, so this hook can never race the production deploy. It also runs only on the machine designated as the cloud-fleet operator, because a disagreement between the repo and a shared Firebase project is a fleet-wide question rather than one person's. With it off you still get exactly the same read on the checker's own schedule (roughly every 6 hours); turning it on adds one extra run right after each land. Kill-switch env var AMC_DISABLE_FUNCTIONS_AUTODEPLOY_ON_LAND=1. |
| `autoFixCloudChain` | toggle | `true \| false` |  |
| `autoFixCorruptSeed` | toggle | `true \| false` |  |
| `autoFixFleetDeploy` | toggle | `true \| false` |  |
| `autoLanderBatchLandingEnabled` | toggle | `true \| false` | BATCH LANDING — the daemon lands several ready branches per master swap (one constructed tip, one CAS, per-member receipts) while the next candidates are prepared concurrently. **ON by default (unset = on);** set it to `false` to restore one-branch-per-swap landing byte-for-byte, or use the env kill switch `AMC_DISABLE_LANDER_BATCH_TIP=1`, which always wins. Deliberately absent from `SYSTEM_DEFAULTS` (the same shape as `autoLanderLoadTriageEnabled`), so the read is the only authority: `getSettings().autoLanderBatchLandingEnabled !== false` in `land-batch.ts`. Contract: auto-lander-batch-landing-contract.md (`bounded-and-default-on`). |
| `autoLanderDeadGateDeferEnabled` | toggle | `true \| false` |  |
| `autoLanderLoadTriageEnabled` | toggle | `true \| false` | Hand off STUCK CONFLICTS even while the box is too busy to land, so a conflicting branch isn't left un-handed-off for hours behind the load gate. Cheap, rate-limited, and it NEVER lands under load — it only hands back. **ON by default (unset = on);** set it to `false` to disable, or use the env kill switch `AMC_DISABLE_LANDER_LOAD_TRIAGE=1`, which always wins. The key is deliberately absent from `SYSTEM_DEFAULTS`, so the read is the only authority: `getSettings().autoLanderLoadTriageEnabled !== false` in `supervisor-under-load-triage.ts`. See land-triage.ts. |
| `autoLanderMaxConcurrentRemediations` | number | `integer 1..12` | Max concurrent auto-lander remediation sessions (the paid rescue sessions that rebase + re-gate + re-tag a stranded branch). Higher = the stranded backlog drains several-at-a-time instead of ~2 per 30 min; bounded so a churn storm can't spawn a swarm and load the box, and the spawn-admission pacer still paces the actual starts. Default 4. auto-lander-escalation-contract.md E46. |
| `autoLanderPrChecklistMode` | select | `"off" \| "advisory" \| "enforce"` | What the auto-lander does when a branch it is about to merge never went through the pre-merge PR checklist. "off" (the default) — the checklist is not consulted, so nothing is ever held on its account. "advisory" — it works out and records what it would have refused, but blocks nothing, which is how you measure the real cost before arming it. "enforce" — it refuses the branch and hands it back to you to finish. Kill switch AMC_DISABLE_LANDER_PR_CHECKLIST_VETO=1. Synonyms: pr checklist veto, auto-lander checklist, pre-merge checklist mode, why was my branch handed back, checklist advisory versus enforce. |
| `autoLanderReadyParkEnabled` | toggle | `true \| false` |  |
| `autoLanderRemediationModel` | select | `"default" \| "claude-worker" \| "claude-basic" \| "deepseek-v4.1-flash" \| "deepseek-v4-flash" \| "deepseek-v4-pro" \| "crofai/deepseek-v4-flash" \| "crofai/deepseek-v4-pro"` | Which AI model the auto-lander's PAID rescue sessions run on — the sessions that rebase, re-gate and re-tag a stranded branch. Blank (the default) uses the standard model. A cheaper tier drains the same backlog for less money; a stronger one is more likely to succeed on a genuinely hard conflict, so it may cost more per attempt while producing fewer attempts. Read at spawn, with a Claude fallback if the chosen tier is unavailable. Synonyms: auto-lander rescue model, which model fixes stranded branches, remediation model, rescue session cost, cheap model for rescues. |
| `autoNudgeEnabled` | toggle | `true \| false` |  |
| `autoRunEnabled` | toggle | `true \| false` | Master switch for Away Mode — when on, the away-mode engine automatically fires your away-mode rules (auto-reply, start a session, retitle, archive, add an inbox note, and so on) against sessions that need you, so Omniscio keeps working while you are away. Off by default (opt-in). The billable actions (auto-reply and start-session) are spend-capped per rule per day and by your budget caps. The engine reads this live, so toggling it takes effect without a restart. Synonyms: away mode, auto run, auto-respond, hands-free automation, run rules while away. |
| `autoTidyDemoted` | list | `array of string (≤200)` |  |
| `autoTidyFirstSeen` | map | `map of string → string (≤40)` |  |
| `autoTidyFirstSeenRepaired` | toggle | `true \| false` |  |
| `autoTidyKept` | list | `array of string (≤200)` |  |
| `autoTidyLastSweep` | text | `string (≤40)` |  |
| `autoTidyUnusedCollapsed` | toggle | `true \| false` |  |
| `autohotkeyBuiltinMigrated` | toggle | `true \| false` |  |
| `automationAiConditionDailyCostCapUsd` | number | `number 0..1000` |  |
| `automationDigestEnabled` | toggle | `true \| false` | Automation Helper — the weekly, cost-free health DIGEST (on by default). Once a week it raises ONE inbox card summarizing every registered automation's health (healthy / paused / needs attention), so you can see at a glance which of your automations are working and which need a look — with no paid AI spawn to produce it. Turn it off to stop the weekly card; gated overall by automationHelperEnabled. Synonyms: automation health digest, weekly automation summary, automation status card, which automations are healthy. |
| `automationDiscoveryEnabled` | toggle | `true \| false` | In-development: watches your own session history for work you repeat by hand on a schedule (a digest or report you keep asking for) and raises ONE dismissible "want me to automate this?" card that seeds an Automation Builder session pre-briefed on the pattern. Detection is 100% local and cost-free — only accepting a suggestion ever spends. Off until shipped; at release it flips to on-by-default with this as the off switch. |
| `automationGroupCollapsed` | toggle | `true \| false` |  |
| `automationHelperEnabled` | toggle | `true \| false` |  |
| `automationHelperUseCompanyApiKey` | toggle | `true \| false` | Route the Automation Helper's AI calls through the COMPANY account instead of the user's own key. Ships OFF — an opt-in operator toggle, because turning it on moves that spend onto the company. Synonyms: automation helper company key, who pays for automation helper, route automations to the company account. |
| `automationRepairDailyCapUSD` | number | `number 0..1000` | Automation Helper — the per-automation daily repair-spend cap in US dollars (0 = repair spending is uncapped for a single automation; default $5). Bounds what a single runaway automation can spend on AI repair attempts in one day, on top of the fleet-wide global daily cap, so one broken automation can never burn through your budget while the repair loop tries to fix it. Set it over the CLI. Synonyms: automation repair cap, per-automation spend cap, runaway automation limit, auto-fix daily budget. |
| `automationsFolder` | text | `string (≤1000)` |  |
| `backupArchiveUserHarmGateEnabled` | toggle | `true \| false` |  |
| `backupEnabled` | toggle | `true \| false` |  |
| `backupIntervalHours` | number | `integer 1..24` |  |
| `backupMirrorAutoSyncIntervalMinutes` | number | `integer 60..1440` | Interval (minutes) for `scheduled` mode. Floor 60 — a full mirror is ~1–3 GB, so sub-hourly auto-writes are intentionally disallowed. Default 3 h. |
| `backupMirrorAutoSyncMode` | select | `"off" \| "session" \| "scheduled"` | Automatic-sync mode. `off` = manual "Sync now" button only (default). `session` = pull on app launch + pull-then-push on shutdown (once per session). `scheduled` = also pull-then-push on a timer every `…IntervalMinutes`. A full snapshot is ~1–3 GB, so the cadence is deliberately coarse. |
| `backupMirrorChunkedFormatEnabled` | toggle | `true \| false` | In-development: a content-addressed, chunked incremental on-disk format for the Backup Mirror so a sync ships only the few MB that changed instead of re-uploading the whole archive. Inert until shipped — the mirror keeps writing today’s streamed format, and your existing backups are unaffected. Do NOT enable on a real backup folder until a full backup+restore round-trip has been validated. |
| `backupMirrorEnabled` | toggle | `true \| false` | Backup-mirror feature flag. Default: false. |
| `backupMirrorPath` | text | `string (≤1024)` | Absolute path to the user's chosen sync folder (must be writable). Empty string = not configured (UI shows "Pick folder…" affordance). |
| `backupMirrorRetentionCount` | number | `integer 1..50` | Number of historical mirror bundles to keep on disk. Older ones are pruned after each successful write. Default: 5. |
| `backupMirrorRetentionMaxAgeDays` | number | `integer 0..3650` | Optional AGE bound (in days) on retained mirror bundles (F059/RT-F015 — privacy/erasure). A full-DB mirror is an immutable copy of ALL PII; deletion/ erasure on the live DB never propagates into a prior snapshot, so on a low-cadence device the newest-N snapshots kept by `backupMirrorRetentionCount` can be arbitrarily old — older than any erasure SLA. When > 0, a snapshot older than this many days is ALSO pruned (additive to the count prune — deleted if beyond-count OR too-old), still honoring `cross-device-safe-prune` (never deletes a foreign host's single newest snapshot). **DEFAULT 0 = disabled / count-only, so existing behavior is UNCHANGED by default** — this is a destructive prune of the user's own backups and MUST be opt-in. |
| `backupOffMachineSetupOfferDismissed` | toggle | `true \| false` | True once the user has dismissed (or acted on) the first-run "set up an off-machine backup" prompt — never shown again after. A DEFAULT install has no off-machine backup that survives losing the machine (F015/F054/RT-F080): the only default-ON backup is the same-volume local ring, and every off-box copy (setup-to-Gmail / mirror / portable) is opt-in + default-OFF. This one-time, consent-first prompt invites the user to configure one; it changes NO backup default on its own (it routes to the hardened config). Default: false. See OffMachineBackupOffer.tsx + off-machine-backup-offer.ts. |
| `backupRetentionCount` | number | `integer 3..50` |  |
| `bakeoffSidebarEnabled` | toggle | `true \| false` | Shows or hides the Bake-Off entry in the sidebar — a prompt-tools feature that runs a prompt across options and compares the results side by side. One of the per-section sidebar visibility toggles; on by default, turn it off to remove Bake-Off from the sidebar. Synonyms: bakeoff sidebar, bake-off, compare prompts or models side by side. |
| `bashSessionShell` | toggle | `true \| false` | Windows only. When on, each agent session keeps ONE shell alive for its whole life and runs every Bash tool command in a copy of it, instead of starting a brand-new shell for each command and re-loading the session setup every time (thousands of file lookups and up to a few hundred ms per command, far more when the machine is busy). Nothing an agent can see changes: same output, same exit code, same clean slate between commands, and any command the resident shell cannot answer runs exactly as before. On by default (Windows). Takes effect on the NEXT session you start; to stop an ALREADY-running session using it, set AMC_DISABLE_BASH_SESSION_SHELL=1 for that session. Fail-open: if anything is wrong the call just runs the old way and it is recorded. No effect on macOS or Linux. Synonyms: persistent shell, resident shell, one shell per session, faster bash tool calls, session shell. |
| `beautifySiteSkillEnabled` | toggle | `true \| false` |  |
| `bengaliPilotEnabled` | toggle | `true \| false` | Adds Bengali (বাংলা) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `bikolPilotEnabled` | toggle | `true \| false` | Adds Bikol (Central Bicolano) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `boardsSidebarEnabled` | toggle | `true \| false` | When on (the default), the sidebar shows the Boards row — the read-only window onto the shared agent board, where Overseers, swarms and ordinary agent-to-agent messages all write. Turn it off to hide that row. It is deliberately its own switch rather than part of the Overseer feature: the board keeps collecting work from those other sources, so the row stays reachable even with Overseers switched off. Synonyms: boards sidebar row, show the agent board, hide the boards row, shared board in sidebar, sidebar boards toggle. |
| `botCreationModeEnabled` | toggle | `true \| false` | In-development: describe a job in plain language and a guided interview builds you a ready-to-use bot — its own hub, pre-loaded with a persona, the knowledge it needs, and the right skills. Off by default; hidden until shipped. |
| `brazilianPortuguesePilotEnabled` | toggle | `true \| false` | Adds Brazilian Portuguese (Português do Brasil) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `broadcastEmbedEnabled` | toggle | `true \| false` | In-development: a broadcast card can embed a full live web page (a Shares-hosted page with forms + JavaScript) rendered inline in an isolated sandbox, made to look native. A new security surface, so it rolls out deliberately. Hidden until shipped. |
| `broadcastFormsEnabled` | toggle | `true \| false` | An inbox alert can carry a short inline FORM (a few questions) that you answer right on the card and submit back to whoever sent it. |
| `broadcastReceiptsEnabled` | toggle | `true \| false` | When you receive a targeted broadcast, your app confirms back to the sender that it was received, shown in your inbox, and opened — so the operator can see per-recipient delivery. Honors your "developer messages" opt-out; nothing is reported when that is off. |
| `broadcastTargetingEnabled` | toggle | `true \| false` | In-development: target a broadcast at specific signed-in people, organizations, or custom groups (in addition to the platform / plan / version filters), and manage reusable recipient groups. Hidden until shipped. |
| `browserEnabled` | toggle | `true \| false` |  |
| `browserLoginAutoExpireDays` | number | `integer 0..365` |  |
| `browserLoginsEnabled` | toggle | `true \| false` | Log into a website once and every agent you run can use that login automatically — many at the same time — until the site signs you out. Local-only; no passwords are stored. |
| `browserLoginsSidebarEnabled` | toggle | `true \| false` |  |
| `budgetCapHardUSD` | number | `number 0..10000` | PER-SESSION HARD cap, in US dollars: a session is force-KILLED when its own accumulated cost crosses this. Default $100. This is the per-session stop; budgetCapSoftUSD only warns. It does NOT bound a fan-out of many sessions — that is what dailyBudgetCapHardUSD is for. Nighty Tidy AUDIT sessions are exempt (an audit legitimately outspends a normal session and carries its own ceiling), but they remain subject to the daily caps. null or 0 disables it. Synonyms: per session hard cap, kill a session that costs too much, max dollars per session, session spend limit, stop a runaway session. |
| `budgetCapSoftUSD` | number | `number 0..10000` | PER-SESSION SOFT cap, in US dollars: when one session's own accumulated cost crosses this, Omniscio shows a ONE-TIME warning for that session and keeps going — nothing is stopped. Default $20, on. This is the early signal that fires well before the $100 hard kill. Not the same as budgetCapHardUSD (which stops the session) and not the same as the dailyBudgetCap* pair (which measure a whole DAY across all sessions on an account). null or 0 disables it. Synonyms: per session soft cap, warn me when a session costs, session spend warning, soft budget limit, session cost warning threshold. |
| `bugIntakeDailyCap` | number | `integer 1..1000` |  |
| `bugIntakeEmailLiaisonEnabled` | toggle | `true \| false` | In-development: when in-app feedback includes a reporter email, auto-send a friendly acknowledgement and run a separate email-correspondence thread alongside the bug-fixing thread (reporter replies route back to it). |
| `bugIntakeLiaisonAckBody` | text | `string (≤10000)` |  |
| `bugIntakeLiaisonFromAddress` | text | `string (≤200)` | The brand "from" address the bug-report email liaison sends the reporter from — the acknowledgement and the warm progress updates come from here (default support@omniscio.com). Sent via the Omniscio Agent Email / Cloudflare transport, not third-party AgentMail. The recipient is always the original reporter, bound on the server, so this only sets who the mail appears to come FROM. Internal-only (devOnly); blank disables the liaison send. Synonyms: liaison from address, bug report email sender, support from address, reporter email from, who bug-report emails come from. |
| `bugIntakeLiaisonGuidance` | text | `string (≤10000)` |  |
| `bugIntakeLiaisonReplyToAddress` | text | `string (≤200)` | The Reply-To address on bug-report liaison emails — when a reporter replies, their message goes here and routes back to the same fixing session (default support@omnisciomail.com, a Cloudflare-received address). The brand "from" domain is send-only, so replies are directed here to continue the conversation. Internal-only (devOnly). Synonyms: liaison reply-to address, bug report reply address, where reporter replies go, support reply-to, reporter reply routing address. |
| `bugIntakeRouterEnabled` | toggle | `true \| false` | In-development: forwards an incoming bug report to the matching intake destination based on routing rules. Hidden until shipped. |
| `bugIntakeSessionsEnabled` | toggle | `true \| false` | In-development: shows the fix sessions Bug Intake spawned inside the Bug Intake panel, and opens a session chat beside the list instead of sending you off to hunt for it in the sidebar. Hidden until shipped. |
| `bugIntakeSplitWidth` | number | `number 200..4000` |  |
| `bugReportTransport` | select | `"both" \| "email" \| "firebase"` |  |
| `bundledPluginsDefaultOnBackfilled` | toggle | `true \| false` |  |
| `burstAllUntil` | number | `integer 0..9007199254740991` |  |
| `calendarChangeNotificationsEnabled` | toggle | `true \| false` |  |
| `calendarDailyAgendaHour` | number | `integer 0..23` | The hour (0-23, local time; default 7) each morning's "Today's Agenda" inbox card is posted. Settings → Calendar → "Agenda delivery time" (paired with calendarDailyAgendaMinute). |
| `calendarDailyAgendaMinute` | number | `integer 0..59` | The minute (0-59, local time; default 0) each morning's "Today's Agenda" inbox card is posted. Settings → Calendar → "Agenda delivery time" (paired with calendarDailyAgendaHour). |
| `calendarHiddenIds` | list | `array of string (≤200)` |  |
| `calendarNotificationsEnabled` | toggle | `true \| false` |  |
| `calendarQuickAddBackfilledAt` | text | `string (≤64)` |  |
| `calendarQuickAddDefaultCalendarId` | text | `string (≤200)` |  |
| `calendarSyncEnabled` | toggle | `true \| false` |  |
| `capacityLedgerPlacement` | toggle | `true \| false` | In-development, default OFF, and NOT yet switchable: nothing writes it today — there is no Settings control and no CLI seed — so the only value any install can reach is off. When it IS wired up, turning it on will make the load-balancing picker rank and refuse accounts using the capacity ledger's LIVE projected utilization rather than the stale usage poll, adding proactive refusal and soft affinity; it stays off until shadow-validated. NOTE: AMC_DISABLE_CAPACITY_LEDGER=1 is NOT an off-ramp for it — that env var is read trough the settings-gated shape, so it can only ever disable a feature that this still-off setting has already disabled. Synonyms: capacity ledger placement, live capacity placement, smarter account picking, projected utilization routing. |
| `capsLockSendsMessage` | toggle | `true \| false` |  |
| `cebuanoPilotEnabled` | toggle | `true \| false` | Adds Cebuano (Bisaya) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `channelInvitationsEnabled` | toggle | `true \| false` | Invite workspace members to specific channels with per-channel roles (owner, member, read-only), and control who can post (everyone, or owners only). |
| `checkoutDeferredNoticeEnabled` | toggle | `true \| false` |  |
| `checkoutKeeperReportedAt` | text | `string` | ISO timestamp the main-checkout keeper stamps after its ONE report-only cycle — the run that reports what it WOULD put back without changing a file. Null means that cycle has not happened yet and the next tick is a dry run. Persisted rather than held in memory so it happens once ever, not once per app restart. Job-written bookkeeping; the job's own off switch is the env kill switch AMC_DISABLE_CHECKOUT_KEEPER=1. See worktree/checkout-keeper.ts. |
| `chromeExtensionDevEnabled` | toggle | `true \| false` | Chrome extension dev (Autopilot) |
| `chromeExtensionDevNudgeSeen` | toggle | `true \| false` |  |
| `claudeCodeBinaryPath` | text | `string (≤1000)` | Full path of the Claude Code CLI used to launch sessions. Leave empty to auto-detect. A leading `~` is expanded to your home folder, so the path a terminal prints works as-is. |
| `cleanRoomSidebarEnabled` | toggle | `true \| false` | Shows or hides the Clean Room entry in the sidebar — a prompt-tools action that spawns a fresh, isolated session. One of the per-section sidebar visibility toggles; on by default, turn it off to remove Clean Room from the sidebar. Synonyms: clean room sidebar, fresh isolated session, clean session. |
| `cliProxyHealthUserHarmGateEnabled` | toggle | `true \| false` |  |
| `cliSpawnPacerUserHarmGateEnabled` | toggle | `true \| false` |  |
| `cliToolsSidebarEnabled` | toggle | `true \| false` |  |
| `clickupEnabled` | toggle | `true \| false` | Adds a "ClickUp" sidebar tab to view and manage your ClickUp tasks — board columns, task detail, comments, checklists — without leaving Omniscio. Connect with your Personal API Token in Settings. In development. |
| `clickupInboxEnabled` | toggle | `true \| false` |  |
| `clipboardHistoryAutoPaste` | toggle | `true \| false` | When you pick an item in the Win+V picker, auto-paste it into the app that had focus (best-effort: writes the clipboard ALWAYS, then synthesizes Ctrl+V only when it can safely target the prior foreign window). Default true; off = copy-to-clipboard only (you press Ctrl+V). Windows-only. Read as `?? true`. |
| `clipboardHistoryEnabled` | toggle | `true \| false` | A clipboard-history button in the chat composer that keeps your recent copies (text + images) so you can re-insert them. Captured in memory and cleared when Omniscio restarts — unless you opt into keeping it across restarts (saved encrypted on this PC). |
| `clipboardHistoryHotkey` | list | `array of string` | Global hotkey (Electron accelerator) that summons the standalone clipboard picker window from anywhere. Default 'CommandOrControl+Alt+V' (= Ctrl+Alt+V) — NOT Win+V, which Windows reserves for its own clipboard history so Electron's globalShortcut.register always fails on it; Ctrl+Alt+V registers cleanly and coexists with the OS Win+V. Only auto-registers on Windows and only while the clipboard-history feature is visible; the picker window + auto-paste are Windows-only in v1. Read as `settings.clipboardHistoryHotkey ?? 'CommandOrControl+Alt+V'`. Existing installs are rebound off the stale Win+V default once by migrate-clipboard-history-hotkey-default-for-existing-users. See global-hotkeys.ts. |
| `clipboardHistoryHotkeyEnabled` | toggle | `true \| false` | Per-hotkey on/off for the clipboard picker global hotkey. Default true (so turning the feature on gives you the Ctrl+Alt+V picker). Read as `?? true`. |
| `clipboardHistoryPersist` | toggle | `true \| false` | Keep the clipboard history across app restarts. Default TRUE — once the clipboard feature is on, the full history (text + images + pins) is saved to disk ENCRYPTED at rest (safeStorage / DPAPI, machine-bound) and reloaded on the next launch; turning it off — or turning the whole clipboard feature off — deletes the saved file, and each launch drops anything older than the 14-day memory (I31). Sensitive copies are never captured, so they are never persisted either. Desktop-only. Read as `settings.clipboardHistoryPersist ?? true`. See clipboard-history-contract.md `keep-across-restarts`. |
| `clipboardHistoryShowInComposer` | toggle | `true \| false` | Show the clipboard-history icon in the chat composer. Default false. When false, the composer button is hidden but the feature still works via the Win+V picker window. Read as `settings.clipboardHistoryShowInComposer ?? false`. |
| `cloudFlakeRegistryEnabled` | toggle | `true \| false` | Persists the per-test flake identity the cloud gate already computes into a durable cross-run registry, and adds a flakiness-rate view (`npm run cloud:flakes` + a cloud-dashboard section) plus a quarantine list of chronically-flaky tests. Operator-only dev infra — no sidebar surface. On by default; turn it off in Settings → Lab. The ledger writer that runs outside the app, from the command line, has its own separate off-switch. |
| `cloudFleetOperator` | toggle | `true \| false` |  |
| `cloudFleetOperatorMachineId` | text | `string` | The hardware fingerprint of the ONE machine that is CLAIMED as this install's cloud-fleet operator. Operator status (which box surfaces the cloud-fleet, master-build, and ops alerts) requires BOTH the cloudFleetOperator setting AND this stored id matching the current machine's live fingerprint — so a copied config/repo clone, which carries this id but runs on different hardware, never becomes an operator and never gets those alerts. Managed automatically: run POST /cloud-operator/claim on the box that should be the operator (it stamps its own fingerprint here); null means not yet claimed. Not a normal on/off setting. Synonyms: operator machine id, operator binding, which machine is the operator, bind operator to this computer, cloud fleet operator fingerprint, only my machine gets the alerts, claim operator machine. |
| `cloudMachineSharingEnabled` | toggle | `true \| false` | May several of this person's agents share ONE cloud machine? DEFAULT ON, and that is the owner's decision rather than a default anyone drifted into. Asked on 2026-09-29 whether the app should place agents together or a person should choose per project, he answered: *"Start with a but I want to test doing b to measure the tradeoffs"* — option A being "2 sessions per large machine and 4 per extra-large". The app places, and it places by default. WHY THIS EXISTS BESIDE `AMC_DISABLE_MACHINE_SHARING`. That env var is the OPERATOR's emergency lever and stays exactly as it is. But the owner runs `npm run dev` and sets no environment variables, so an env var is not a switch he can reach — this is the switch he can. Both are honoured, and off means off either way. WHAT OFF MEANS, precisely: every session gets its own machine, exactly as it did before this feature existed. It does NOT strand sessions already on a shared machine — those keep working, because the machines and their links already exist. It only stops NEW joins. NOTE ON REACH today: nothing turns joins on yet — no production caller supplies the placement session id while a joined directory still lacks a git baseline — so flipping this changes nothing observable until that lands. It is honoured by the placement seam, not merely stored, which is the half that makes it a switch rather than dead config. |
| `cloudReturnedWorkAutoLand` | toggle | `true \| false` | A cloud session that ends with changes brings them home as a branch. With this on, the app lands that branch on its own — for this project, by testing it and marking it ready to merge; for any other project, by running that project’s own test command on the cloud machine and merging the result into that project’s main branch here on this computer. Nobody has to run ready-to-merge on a returned branch by hand. A branch whose files could not be checked for secrets is refused rather than landed, and a returned branch for a project with no test command is left for you. On by default; turn it off in the Dev Pipeline panel. |
| `cloudSessionHomeSetupEnabled` | toggle | `true \| false` | Copy the owner's OWN Claude setup — the global rules file and every skill that exists only on this machine — to a cloud box at bring-up. ON by default, and the owner's rule is why that is not a question: a feature ships switched on in code with an explicit off switch, never behind an environment variable. OFF is not a degraded mode — it restores today's behaviour exactly, with the same argv and the same bring-up rungs, so a user who wants the previous behaviour gets it byte-for-byte, and the session's one-line notice says the setup is not on the box. A preference, not a gate: cloud sessions themselves are still off until released, and nothing here reaches the user before that. The copy never carries a file holding a credential (see `cloud-session-home-setup-contract.md`), and it is inert while cloud sessions are off. |
| `cloudSessionTemplatesEnabled` | toggle | `true \| false` | Start a cloud session from a copy of the project saved once with its dependencies already installed, so a launch sends only what changed instead of the whole tree. ON by default — the owner's rule is that a feature ships switched on in code with an explicit off switch, never behind an environment variable. OFF is not a degraded mode: it restores today's full ship exactly, with the same argv, the same ship plan and the same baseline command, so a user who wants the previous behaviour gets it byte-for-byte. This is a preference, not a gate: cloud sessions themselves are still off until released, and nothing here reaches the user before that (`cloud-session-project-templates-contract.md`, `templates-are-on-by-default-and-switchable`). |
| `cloudSessionsEnabled` | toggle | `true \| false` | In-development: optionally run an agent session on a cloud VM instead of locally, so your machine stays light and you can run more at once. Off by default; local is unaffected. |
| `cloudSessionsSpendConfirmed` | toggle | `true \| false` | The ONE-TIME acknowledgement that cloud sessions cost money — set by the user's own click on the confirm dialog the Run-location picker raises on the first Cloud pick, and never written by anything else. This is the memory of consent, not a feature gate: `cloudSessionsEnabled` decides whether the option EXISTS, this decides whether the user has agreed to PAY. Every cloud provision reads it (launch-steps' bringUpCloudVmIfRequested), so a launch arriving from anywhere the dialog cannot reach — `POST /fanout` with `location:'cloud'`, a direct `session:launch` — is refused rather than quietly spending the user's money on a machine they never agreed to rent. Deliberately NOT a field on the launch payload: a caller that could set it would make the whole gate decorative. MUST be listed here: a field absent from this shape is silently stripped on update, so the ack would never persist and the notice would re-show on every single cloud launch (the same failure the sibling ack below was added for). |
| `cloudStartedMaxChildrenPerParent` | number | `integer 0..10` | How many live helper sessions ONE cloud session may have at the same time. Default 3, the same ceiling an agent-started session already has on your desktop. A request past it is refused by name, so the agent is told to wait rather than left retrying. Synonyms: cloud helper limit, max helpers per session, cloud children cap. |
| `cloudStartedMaxDailyDollars` | number | `number 0..500` | The US-dollar ceiling for ALL cloud-started helper sessions in one day, across every tree — default $20. This is the backstop the per-tree ceiling cannot give you, and it is what stops a day of many small trees adding up. Past it, no further cloud-started session runs until tomorrow. Synonyms: cloud daily budget, daily cloud helper cap, cloud session spend per day. |
| `cloudStartedMaxTreeDepth` | number | `integer 0..5` | How deep a tree of cloud-started sessions may go. Default 2, which means a cloud session and its direct helpers — a helper cannot start a further session. This is the setting that stops a fan-out, and it is enforced by the app, never by asking the agent to behave. Synonyms: cloud session tree depth, nesting limit, how deep can cloud helpers go. |
| `cloudStartedMaxTreeDollars` | number | `number 0..100` | The US-dollar ceiling for the helper sessions ONE tree starts, in total — default $5. It counts what the sessions the tree STARTED spend, never the session that started them (that one is yours, and it alone runs far more than this). Past the ceiling, further helpers in that tree are refused by name. Synonyms: cloud tree budget, cloud helper spend cap, how much can cloud helpers cost. |
| `coachingBridgeDigestEnabled` | toggle | `true \| false` |  |
| `coachingCategories` | map | `map of string → true \| false` |  |
| `coachingDailyMessageStyle` | select | `"motivational" \| "coaching" \| "mindfulness" \| "stoic" \| "humor" \| "gratitude" \| "challenge"` | Which category of rotating quote shows in the AI Coaching dashboard's daily greeting banner: motivational, coaching, mindfulness, stoic, humor, gratitude, or challenge (default motivational). Chosen from the style picker beside the dashboard's daily greeting. |
| `coachingVaultMirror` | toggle | `true \| false` | AI Coaching — when on, coaching artifacts are mirrored as markdown notes in your KMS vault (the knowledge base panel), so each session's coaching output lands in your notes. Opt-in and off by default; requires KMS enabled and a vault configured. Synonyms: coaching notes to vault, mirror coaching artifacts, save coaching to KMS, coaching output as markdown. |
| `cofferAssistantEnabled` | toggle | `true \| false` | Opt-in consent for Coffer's natural-language money assistant: ask plain-English questions about your finances ("how much did I spend on restaurants last month?") and get answers grounded in your ledger. Off by default — each question is a small PAID Anthropic round-trip using YOUR OWN API key, and only your question plus small summary figures (totals, budget status) are sent — never your individual transactions. Enabled only by the explicit consent card in the Coffer assistant panel. Synonyms: money assistant, ask about my finances, ledger chat, natural-language finance questions, coffer ai assistant. |
| `cofferBudgetMode` | select | `"tracking" \| "envelope"` | Which budgeting style the Coffer Budgets view uses: "tracking" (default) shows classic per-category budgets and spending bars; "envelope" switches to YNAB-style allocation-first budgeting where every dollar is assigned to an envelope and leftovers/overspending carry month to month. Switching modes never deletes data — the other mode's numbers stay saved and reappear if you switch back. Set from the Budgets view's mode switch, not a Settings toggle. |
| `cofferEnabled` | toggle | `true \| false` | Adds a "Coffer" sidebar tab — a personal-finance tracker (accounts, transactions, auto-categorization, budgets, net worth) inspired by Mint.com, fully local to Omniscio. Import bank CSV/OFX files or add transactions by hand. In development. |
| `cofferQuotesEnabled` | toggle | `true \| false` | Opt-in consent for Coffer's Investments feature to fetch daily closing stock prices from stooq.com (a free quote service) so it can value your manually-tracked holdings and chart them against the S&P 500 benchmark. Off by default; nothing about your balances is ever sent. Set from the Investments view's consent card, not a Settings toggle. |
| `coldStorageUserHarmHoldEnabled` | toggle | `true \| false` |  |
| `collapsedInboxGroups` | list | `array of string (≤64)` |  |
| `collapsedQuickReplyFolders` | list | `array of string (≤64)` |  |
| `commandPaletteRecents` | list | `array of string (≤64)` | Most-recently-used command ids for the Command Palette, front = most recent, capped at 10. Persisted so your recents survive restarts. Written automatically as you run commands — remembered usage state, not a setting you configure. Synonyms: recent commands, command palette recents, MRU, recently used. |
| `communicationCollapsed` | toggle | `true \| false` |  |
| `communicationsRetentionDays` | number | `integer` |  |
| `communicationsRetentionEnabledAt` | text | `string (≤40)` |  |
| `compactArchiveOnNextStartup` | toggle | `true \| false` | When true, the next app launch compacts ONLY the cold-storage archive file (behind the splash screen), leaving the main database alone. Armed automatically, once, when the archive tool-output sweep has freed a large amount of space inside a never-compacted archive; cleared and flushed to disk BEFORE the rewrite starts so it can never boot-loop. See database-maintenance-contract.md. |
| `compactOnNextStartup` | toggle | `true \| false` | When true, the next app launch runs an in-place VACUUM to compact the database file — and the cold-storage archive too, when it holds enough free space to be worth rewriting. Set by the "Reclaim disk space" action; cleared unconditionally after the attempt (success OR failure) so a VACUUM that errors can never boot-loop. Runs behind the splash screen (exclusive lock). |
| `composedSessionViewsEnabled` | toggle | `true \| false` | In-development: a List / Board / Grid picker above the session list, with board (status columns) and grid views composed from the new session-view primitives. No visible change when off. Hidden by default; enable it in Settings to preview. |
| `composerListContinuation` | toggle | `true \| false` |  |
| `composioConnectedToolkits` | list | `array of string (≤100)` | The list of Composio toolkit slugs currently connected for your account — a local cache of Composio's own server-side connection state, refreshed automatically. Not user-editable; at least one entry is required before the Composio MCP server is added to a session. |
| `composioEnabled` | toggle | `true \| false` | Adds a "Composio" sidebar tab to connect your external apps (Gmail, Slack, GitHub, Notion, and 1000+ more) through Composio, then hands those tools to every AI session automatically. Bring your own free Composio API key. In development. |
| `composioUserId` | text | `string (≤200)` | Your auto-generated Composio user id (an opaque "omniscio-<uuid>" string), minted once and reused for every Composio API call. Internal identifier, not user-set and not a credential. |
| `conciergeCustomInstructions` | text | `string (≤10000)` | Your own free-text notes for the Simple Mode concierge — its "steering knob". Appended to the concierge's instructions at the start of every chat, ON TOP of the built-in persona (never replacing it, and the concierge's safety rules always win). Empty (the default) means no custom notes. Up to 10,000 characters. Synonyms: concierge instructions, simple mode notes, concierge steering, my custom concierge notes, guide the concierge. |
| `confirmQuickReplyOnBlankSession` | toggle | `true \| false` |  |
| `consentLedger` | map | `map of string → object { granted: true \| false; purpose: "crash-autosend" \| "cloud-intake" \| "email-remote-images" \| "voice-stt" \| "web-bridge-message-transit" \| "wake-word-listening" \| "sync" \| "voiceprint-training" \| "flowvoice-dictation" \| "behavioral-profiling" \| "ai-browser-memory" \| "pipeline-cloud-offload" \| "pipeline-fleet-identity" \| "share-publish" \| "marketing-attribution"; recordedAt: string (≤40); source: "backfill" \| "settings-change" \| "user-acceptance"; version: integer 0..∞ }` |  |
| `contextDockBgRefreshEnabled` | toggle | `true \| false` |  |
| `contextWindowDepth` | number | `integer 1..500` |  |
| `contextdockEnabled` | toggle | `true \| false` | In-development: a cloud knowledge library that feeds compressed context (bundles, lists, docs) into any project’s sessions — agents see linked material in their first message. Off by default; hidden until shipped. |
| `contextdockNativeEnabled` | toggle | `true \| false` | In-development: the local-first native ContextDock library UI reading Omniscio's own store; off by default; hidden until shipped. |
| `continuousSummaryAgentPromptTemplate` | text | `string (≤50000)` |  |
| `continuousSummaryDailyCostCapUsd` | number | `number 0..100` |  |
| `continuousSummaryLastAskedPromptTemplate` | text | `string (≤50000)` |  |
| `conversionHoldUserHarmGateEnabled` | toggle | `true \| false` |  |
| `costAlertsEnabled` | toggle | `true \| false` |  |
| `costControlSidebarEnabled` | toggle | `true \| false` | Whether the Cost Control section is shown in the sidebar — one of the per-section sidebar visibility toggles. On by default; turn off to hide the Cost Control entry from the sidebar. Synonyms: show/hide cost control in the sidebar, cost control sidebar visibility. |
| `councilDailyDollarCap` | number | `number 0.05..50` |  |
| `councilDefaultModels` | text | `string (≤500)` |  |
| `councilSidebarEnabled` | toggle | `true \| false` |  |
| `councilWizardCompleted` | toggle | `true \| false` |  |
| `councilWizardShowWelcome` | toggle | `true \| false` |  |
| `councilsSidebarHubIds` | list | `array of string` | Hub (project) ids the user has opted into showing the "Councils" section in their sessions sidebar. Default []: the section otherwise renders ONLY in the standalone AI Council hub or a hub that already has council sessions. Toggled via the hub right-click "Show AI Council" menu item. |
| `crashAutoSendEnabled` | toggle | `true \| false` |  |
| `creativeCollapsed` | toggle | `true \| false` |  |
| `credentialBannerDismissed` | toggle | `true \| false` |  |
| `cronDispatchUserHarmGateEnabled` | toggle | `true \| false` |  |
| `cronGroupLabels` | map | `map of string → string (≤80)` |  |
| `crossDeviceSyncEnabled` | toggle | `true \| false` | Cross-Device Sync |
| `crossDeviceSyncMirrorMigrationDismissed` | toggle | `true \| false` | True once the user has dismissed (or acted on) the one-time "switch from folder Backup Mirror to Cross-Device Sync" migration offer — never shown again after. Governs BOTH the pre-enroll offer (sync section + the Data Transfer nudge) AND the post-enroll "turn folder Backup Mirror off" hint (they are mutually exclusive by enrollment state). Purely a UI bookkeeping flag — it changes no sync/mirror behavior. Default: false. See mirror-migration.ts + MirrorMigrationCard.tsx. |
| `customColors` | list | `array of string` |  |
| `customFormatBlock` | text | `string (≤10000)` | The editable text of the Standard Formatting Block — the formatting standard Omniscio injects into the first message of each session so the agent formats its responses to be easy to skim. Leave blank to use the built-in default; edit it in Settings → Questions → Developer. Turn the block on or off with customFormatBlockEnabled. Synonyms: response formatting, formatting standard, scannable output, custom format instructions. |
| `customHooksEnabled` | toggle | `true \| false` | In-development: a Hooks panel (under Agent Tools) to manage the hooks Omniscio runs in your spawned sessions — the built-in ones (Git Guardrails, Secret Paste Guard, Write-Time Lint, Agent Firewall) plus your own custom hooks (run a command at a lifecycle event such as before/after a tool, on stop, or on prompt), global with per-project overrides. Desktop-only; creating or editing hooks is human-only. Off by default; hidden until shipped. |
| `customRenderRules` | list | `array of object { enabled: true \| false; flags: string (≤8); icon: "tag" \| "check-circle" \| "x-circle" \| "alert-circle" \| "alert-triangle" \| "info" \| "git-pull-request" \| "git-merge" \| "git-branch" \| "rocket" \| "flag" \| "star" \| "zap" \| "bug" \| "clock" \| "shield" \| "link" \| "circle-dot"; id: string; labelTemplate: string (≤200); linkTemplate: string (≤500); name: string (≤100); pattern: string (≤500); tone: "neutral" \| "accent" \| "success" \| "warning" \| "danger" \| "info" }` | Your list of Custom Render Rules — each a regex whose matches render as an inline badge in conversation messages, with a color/tone, an optional icon, an optional label built from the match, and an optional clickable http/https link. Add, edit, reorder (first match wins), and delete them in Settings → Sessions → Custom Render Rules. Synonyms: regex render rules, message badges, custom badges, status pill, PR badge. |
| `customRenderRulesEnabled` | toggle | `true \| false` | Master switch for Custom Render Rules — your own regex rules that render matching text in conversation messages (both agent output and your own) as inline badges. On (default): your enabled rules render. Off: all custom badge rendering is disabled without deleting your rules. Manage the rules in Settings → Sessions → Custom Render Rules. |
| `customShareUrlEnabled` | toggle | `true \| false` | Custom share URL name |
| `customSnoozeShortcuts` | list | `array of object { enabled: true \| false; id: string (≤64); pattern: string (≤200); replacement: string (≤200) }` |  |
| `dailyBriefEnabled` | toggle | `true \| false` | One calm summary a day of what the agents shipped, what is still moving, and what is waiting on you. A quiet day sends nothing. |
| `dailyBudgetCapHardUSD` | number | `number 0..10000` | PER-ACCOUNT DAILY HARD cap, in US dollars: once TODAY's spend on an account crosses this, Omniscio STOPS the running session AND blocks new spawns on that account until tomorrow. Default $25, on. This is the aggregate backstop the per-session cap cannot provide against a fan-out of many sessions. Applies ONLY to pay-per-use API-key sessions (Anthropic apikey accounts + anthropic-compat vendor keys) — never flat-fee subscription (login) sessions. If someone asks to "lower my spending limit" and means a per-day ceiling, this is usually the one. null or 0 disables it. Synonyms: daily hard cap, stop spending after, max per day, daily spend limit, block new sessions when I hit my daily budget. |
| `dailyBudgetCapSoftUSD` | number | `number 0..10000` | PER-ACCOUNT DAILY SOFT cap, in US dollars: when TODAY's spend on an account crosses this, Omniscio warns once per session and keeps going. Default $10, on. Applies ONLY to pay-per-use API-key sessions (Anthropic apikey accounts + anthropic-compat vendor keys) — never to flat-fee subscription (login) sessions, which cost nothing extra per turn. Note the axis: this measures a whole DAY across all sessions on the account, where budgetCapSoftUSD measures ONE session. null or 0 disables it. Synonyms: daily soft cap, warn me at a daily spend, per day spend warning, account daily budget warning. |
| `dailyDigestDailyCostCapUsd` | number | `number 0.05..5` |  |
| `dailyDigestDeliverEmail` | toggle | `true \| false` | When on, your generated Daily Digest is also emailed to you, in addition to posting as an in-app inbox card. Off by default. No Settings-UI control yet; set via CLI/PATCH. |
| `dailyDigestExcludedProjectIds` | list | `array of string (≤200)` |  |
| `dailyDigestExcludedSectionIds` | list | `array of "greeting" \| "stats" \| "alerts" \| "projects" \| "communications" \| "calendar" \| "feeds" \| "actionItems" \| "suggestions" \| "featureIdeas" \| "todaySchedule"` |  |
| `dailyDigestScheduleHour` | number | `integer 0..23` |  |
| `dailyDigestScheduleMinute` | number | `integer 0..59` |  |
| `dailyJournalEnabled` | toggle | `true \| false` | A daily inbox nudge to run a short journaling check-in (and a weekly review) with your AI coach. Entries stay private to coaching and never leak into your other sessions. Requires AI Coaching. |
| `dailyJournalGraceDays` | number | `integer 0..7` |  |
| `dailyJournalTimeZone` | text | `string` | The IANA time zone (e.g. "America/New_York") your Daily Journal check-in / weekly review time is resolved against. Captured automatically the first time the check-in scanner runs (your current host zone) so the nudge keeps firing at the intended wall-clock even after you change your computer’s time zone or travel. Null until captured, then stable. Synonyms: journal reminder time zone, check-in fire zone. |
| `dailyMeteredCompatCapUSD` | number | `number 0..10000` | PER-PROVIDER DAILY HARD cap, in US dollars, for the metered anthropic-compat vendors (Kimi/Moonshot, DeepSeek, GLM, MiniMax, Meta). Once today's recorded spend for ONE of those vendors crosses this, NEW spawns on that vendor are blocked until tomorrow (a pre-spawn gate). Each vendor is capped separately. It exists because those vendors authenticate with their own vendor key and record no account id, so the per-account daily cap above cannot attribute their spend — this meters by provider instead. Opt-in and OFF by default; null or 0 disables. Synonyms: kimi daily cap, deepseek spend limit, glm daily cap, per vendor daily limit, metered vendor cap, compat vendor spend limit. |
| `dailySpendDigestEnabled` | toggle | `true \| false` |  |
| `dataRetentionDays` | number | `integer 1..365` |  |
| `dbPrivateCacheAutoArmed` | toggle | `true \| false` |  |
| `decksBuiltinMigrated` | toggle | `true \| false` |  |
| `decksContextTokenBudget` | number | `integer 1000..150000` |  |
| `decksDailyCostCapUsd` | number | `number 0..1000` |  |
| `decksDefaultTheme` | text | `string (≤100)` |  |
| `decksEnabled` | toggle | `true \| false` |  |
| `decksPremiumModel` | toggle | `true \| false` |  |
| `decksWebviewEnabled` | toggle | `true \| false` | In-development: Decks renders from the standalone sandboxed webview island (the detach) rather than the native panel. This is on by default — the island is now the primary Decks surface. Turn it off to go straight back to the native panel, which stays in the app. |
| `dedicateUiCoreEnabled` | toggle | `true \| false` |  |
| `deepTargetHighlightEnabled` | toggle | `true \| false` | In-development: let an agent or a shareable link navigate you to any page AND spotlight a specific control on it in one step (e.g. jump to a Settings section and point at the exact toggle). Off by default; navigate-only, so it never spawns a session. |
| `defaultAgentInstructionsOverrides` | map | `map of string → true \| false` |  |
| `defaultScreenCapturePresetId` | unknown | `catch` |  |
| `defaultThinkingLevel` | select | `"auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `depPropagationUserHarmGateEnabled` | toggle | `true \| false` | Whether a dependency change may propagate while the machine is measurably hurting you — one of the family of load gates that defer heavy work while something on the box is being harmed. Ships OFF (dark): no disagreement tape has been gathered for this site yet, so it preserves the existing calm-hold until the data exists, rather than guessing. Turn it on to apply the user-harm verdict at this site. Synonyms: dependency propagation harm gate, user harm gate for dep updates, hold dep propagation while hurt, load gate for dependency propagation. |
| `depSecurityScanEnabled` | toggle | `true \| false` | Dependency Security Scan |
| `desktopNotificationOptOutTipSeen` | toggle | `true \| false` |  |
| `devPipelineAiReviewEnabled` | toggle | `true \| false` |  |
| `devPipelineArchiveGuardEnabled` | toggle | `true \| false` | When on, Omniscio refuses to archive a session whose worktree branch still has unshipped work — not tagged ready-to-merge, not landed on master, and with no open PR. The session stays fully alive instead, so a branch of finished-but-unlanded work cannot be closed away by accident. Fail-open: if the git check itself errors, the archive is allowed. Ships OFF (opt-in). Toggled from the Dev Pipeline panel's Setup tab, and mirrored in Settings → Features → Advanced. Synonyms: archive guard, block archiving unshipped work, stop me archiving a session with unmerged changes, dev pipeline archive protection, prevent archive with an unlanded branch. |
| `devPipelineAutoRepliesEnabled` | toggle | `true \| false` |  |
| `devPipelineCustomPhasesEnabled` | toggle | `true \| false` | Turns on the Dev Pipeline's custom-phase editor: you can add phases of your own (and their approval gates) at the point in the flow where they belong, alongside the built-in ones, and each custom gate then gets its own auto-approve switch at its true position rather than being appended after the built-in five. Your phases live in ~/.claude/dev-pipeline/phases.json, the one file both Omniscio and the Claude skill read, so a phase you define is visible to the run it configures — a normal setting would be invisible to it. Off by default; the Dev Pipeline panel's Setup tab. Synonyms: custom phases, enable custom phases, add my own pipeline phase, phase manifest, phases.json, custom gate, extra pipeline step. |
| `devPipelineDailyMaintenanceEnabled` | toggle | `true \| false` | When on (the default), Omniscio runs its dev-pipeline maintenance once a day on its own: housekeeping across your worktrees and ready-to-merge branches, so the fleet stays tidy without you asking. It runs the Claude Code housekeeping skills, so it is a real (paying) session — turn it off to keep maintenance entirely manual. Its model and provider are chosen by devPipelineDailyMaintenanceModel / devPipelineDailyMaintenanceProvider / devPipelineDailyMaintenanceThinkingLevel. Synonyms: daily maintenance, dev pipeline housekeeping, automatic maintenance job, nightly cleanup, who cleans up my worktrees. |
| `devPipelineDailyMaintenanceModel` | text | `string (≤100)` | Daily-maintenance MODEL override. `null` ⇒ the cheap default model (Sonnet, MAINTENANCE_MODEL). |
| `devPipelineDailyMaintenanceProvider` | text | `string (≤100)` | Daily-maintenance ENGINE override — the harness/provider its background session runs on. `null` ⇒ the built-in cheap default (Claude). The Setup-tab picker only offers Claude-binary engines (native Claude + the anthropic-compat vendors), since maintenance runs the Claude Code housekeeping skills. Resolved with the model by resolveMaintenanceSpawnConfig. |
| `devPipelineDailyMaintenanceThinkingLevel` | select | `"auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` | How much the daily dev-pipeline maintenance job is allowed to think before it acts — a thinking level (for example low, medium or high) rather than a model name. Blank means the default for the model it runs on. Higher thinks harder about what is safe to tidy, and costs more per run; lower is cheaper and quicker. Only used when devPipelineDailyMaintenanceEnabled is on. Synonyms: maintenance thinking level, how hard should maintenance think, maintenance reasoning depth, daily maintenance cost. |
| `devPipelineFileNoteEnabled` | toggle | `true \| false` |  |
| `devPipelinePanelEnabled` | toggle | `true \| false` | Dev Pipeline |
| `devPipelineQuickRepliesEnabled` | toggle | `true \| false` |  |
| `devPipelineQuickRepliesSeeded` | list | `array of string (≤200)` |  |
| `devPipelineReminderEnabled` | toggle | `true \| false` |  |
| `devPipelineRepos` | list | `array of object { enabled: true \| false; projectId: string (≤100) }` | Which repositories the Dev Pipeline - and through it the auto-lander - is on for, one entry per project as { projectId, enabled }. An EMPTY list is not "off": it means the list is DERIVED for you from the projects the Dev Pipeline is already set up for, and the moment you add a repository by hand your list is used verbatim instead, so nothing ever needs to be written on your behalf and there is nothing to undo. Edited from the Dev Pipeline panel Setup tab. Synonyms: dev pipeline repos, which repos is the dev pipeline on, watched repositories, auto lander repos, add a repo to the dev pipeline, per-repo enable. |
| `devPipelineSidebarEnabled` | toggle | `true \| false` | Whether the Dev Pipeline panel's row appears in the sidebar (default on). A visibility toggle only - hiding the row does not turn off the controls inside the panel and does not stop the background jobs behind it (the auto-lander, daily maintenance). Settings - Sidebar. Synonyms: dev pipeline sidebar, hide the dev pipeline panel from the sidebar, show dev pipeline, sidebar dev pipeline item, pipeline panel visibility. |
| `devPipelineSkillEnabled` | toggle | `true \| false` |  |
| `developerGuardrailsEnabled` | toggle | `true \| false` | Machine-wide git safety: installs ONE master-safety guard hook into your GLOBAL ~/.claude/settings.json, so EVERY Claude Code session on this machine is guarded — including ones Omniscio never spawned. Blocks direct commits/pushes to a protected branch (master/main), a destructive git stash, and edits while on a protected branch (reusing the git-guardrails engine + its per-repo exclusion + time-boxed approval escape hatches). Cross-platform; OFF by default (opt-in), it edits your global config so it stays opt-in. Turn it on in Settings → Features. |
| `developerModelSubsidyEnabled` | toggle | `true \| false` |  |
| `developerToolsGroupCollapsed` | toggle | `true \| false` |  |
| `devinOrgId` | text | `string (≤200)` |  |
| `devinProviderEnabled` | toggle | `true \| false` | Run Cognition's Devin cloud coding agent as a session provider alongside Claude. Devin runs remotely and is billed in ACUs on your own Devin account, so you add a Devin API key to use it. |
| `diffDefaultViewMode` | select | `"unified" \| "side-by-side"` |  |
| `diffIgnoreWhitespace` | toggle | `true \| false` |  |
| `discordImportEnabled` | toggle | `true \| false` | In-development: import channels, messages, threads, reactions, pins, and files from a Discord server into Team Chat. Runs as a guided wizard that maps Discord users to existing accounts and writes to your active workspace via a secure Cloud Function. |
| `dismissedDecryptFailureAccountIds` | list | `array of string` |  |
| `dismissedPluginCapabilityCards` | list | `array of string (≤256)` | Plugin ids whose read-only Plugin Capability Card the user has permanently dismissed. The card (a one-line "this plugin can act with AI" disclosure that rides on plugin-ai-native-cli) shows once per plugin until its id lands here. Default []. Read as `settings.dismissedPluginCapabilityCards ?? []`. |
| `emailArrivalNotificationsEnabled` | toggle | `true \| false` | Agent Email — raise a quiet inbox row when a new incoming email either starts OR continues a session. On by default. It is an inbox row, NOT an OS toast (it survives Focus Mode as the durable record). Bug-intake triage emails ([BUG]/[FR]/…) take the separate bug-report path and never raise it. Turn off to stop arrival notices for new agent-email sessions. Synonyms: email arrival notifications, incoming email notice, agent email inbox row, notify on new email. |
| `emailCleanupSidebarEnabled` | toggle | `true \| false` |  |
| `emailSummarizerDefaultModel` | text | `string (≤100)` |  |
| `emailSummarizerOnboardingComplete` | toggle | `true \| false` |  |
| `emptyInboxTipSeen` | toggle | `true \| false` |  |
| `enableBundledApiKeys` | toggle | `true \| false` | When on, Omniscio-hosted ("bundled") keys proxy OpenAI, Gemini and Perplexity so those features work without you pasting your own key. Feature-flagged OFF by default. ElevenLabs and Deepgram are deliberately NOT covered — their SDKs ignore the base-URL env var the proxy relies on, so they would need CLI wrappers. Synonyms: bundled api keys, use omniscio hosted keys, built-in api keys, do I need my own openai key. |
| `enableCronJobs` | toggle | `true \| false` |  |
| `enableRecipes` | toggle | `true \| false` |  |
| `enableSkillsIntegration` | toggle | `true \| false` |  |
| `enabledPlugins` | list | `array of string (≤100)` |  |
| `extensionsPromptSnoozedUntil` | text | `string` |  |
| `extensionsSidebarEnabled` | toggle | `true \| false` |  |
| `externalAgentGovernorUserHarmGateEnabled` | toggle | `true \| false` |  |
| `fanoutEnabled` | toggle | `true \| false` | Bake-Off |
| `fanoutPresets` | list | `array of object { id: string (≤100); name: string (≤80); peerAwareness: true \| false; projectIds: array of string (≤200); prompt: string (≤200000); setups: array of object { customProviderId: string (≤100); location: "local" \| "cloud"; mcpOverrides: map of string → true \| false; model: string (≤100); provider: string (≤64); route: string (≤64); thinkingLevel: string (≤32) }; updatedAt: string (≤40) }` | Your saved Bake-Off (fan-out) presets — named configurations for the Bake-Off launcher, each remembering the selected projects, the harness/model setups, and optionally a prompt, so you can reload a whole comparison in one click instead of rebuilding it. Managed from the Bake-Off dialog's Presets bar (Save, load from the dropdown, delete with undo), not a Settings toggle; stored locally and readable over the CLI. Loading a preset restores its projects and setups and, if it saved a prompt, fills the prompt box — a preset saved WITHOUT a prompt never overwrites what you have already typed. Synonyms: bake-off presets, fanout presets, saved bake off setups, save a bake-off configuration, reload my contestants, saved model comparison, preset lineups, bake off save preset. |
| `featureDiscoveryNudgeEnabled` | toggle | `true \| false` | Retired: a daily inbox nudge that pitched an Omniscio feature you had not used yet. Off and hidden for everyone; the code is kept, and only the env reveal turns it back on for testing. |
| `featureRoadmapAutoActivityEnabled` | toggle | `true \| false` |  |
| `featureRoadmapAutoActivityLastRunDate` | text | `string` | 'YYYY-MM-DD' (local) of the last date the activity append ran. Its OWN marker, not the check-in's: the two halves are independently gated, so one marker could not say which had run. Written AFTER the append, so a failed write retries on the next tick instead of writing off the day (the check-in's marker is written BEFORE its spawn for the opposite reason — a crashed session must not re-trigger). |
| `featureRoadmapAutoAddEnabled` | toggle | `true \| false` |  |
| `featureRoadmapAutoSyncEnabled` | toggle | `true \| false` |  |
| `featureRoadmapDriftWatchdogEnabled` | toggle | `true \| false` |  |
| `featureRoadmapEodCheckInEnabled` | toggle | `true \| false` | In-development: at the end of a day you actually landed work, reads your own commits and opens a short session that PROPOSES roadmap updates for the features you own. It only ever proposes — nothing it finds reaches the board unattended, it never overwrites your words, and it never moves a feature's phase without you. Routing a commit to a feature is a separate, automatic record (the autoActivity field); this half is the part that asks. Silent on a day with nothing to report. Off by default. |
| `featureRoadmapEodCheckInLastRunDate` | text | `string` | 'YYYY-MM-DD' (local) of the last date the end-of-day check-in successfully ran. Prevents a second trigger on the same calendar day. Written BEFORE the session is spawned so a crashed session does not re-trigger — but CLEARED when the spawn is observed to fail, so a day the check-in knows it did not deliver is retried on the next hourly tick rather than written off. |
| `featureRoadmapHealthWatchdogEnabled` | toggle | `true \| false` |  |
| `featureRoadmapNudgeDevelopersEnabled` | toggle | `true \| false` |  |
| `fileConverterEnabled` | toggle | `true \| false` | In-development: a standalone file converter — drag or pick a file, choose a target format, and convert it on-device (documents, images, audio/video). Free, local, nothing uploaded. Works on desktop and mobile. |
| `fileConverterSidebarEnabled` | toggle | `true \| false` |  |
| `fileExplorerWidth` | number | `integer 180..500` |  |
| `fileViewerFontSize` | number | `integer 10..20` |  |
| `finalMessageMarkerEnabled` | toggle | `true \| false` |  |
| `finalMessageShapePromptEnabled` | toggle | `true \| false` | When on (default), every regular agent session gets a system-prompt note describing what its final turn message must contain — the outcome first, evidence, any deliverable inline, and the next move. Skipped on Ask-Omniscio / Ask-about-this-page helper sessions. No Settings-UI control; set via CLI/PATCH. |
| `firebaseHostingDomain` | text | `string (≤200)` |  |
| `firstMissionCompleted` | toggle | `true \| false` |  |
| `firstMissionDismissed` | toggle | `true \| false` |  |
| `fleetGovernorBirthLoopEnabled` | toggle | `true \| false` |  |
| `fleetGovernorUserInteractiveEnabled` | toggle | `true \| false` |  |
| `fleetSafetyGovernorEnabled` | toggle | `true \| false` |  |
| `flowchartEnabled` | toggle | `true \| false` | In-development: a standalone visual flowchart editor — shapes and connectors, swimlanes, auto-layout, a saved library, and AI sessions that can read and draw on the board. |
| `flowchartSidebarEnabled` | toggle | `true \| false` |  |
| `focusGuardEnabled` | toggle | `true \| false` |  |
| `focusModeState` | object | `object { enabled: true \| false; perProjectLastBatchAt: map of string → string; startedAt: string; whitelistedSessions: array of string (≤64) }` |  |
| `foldAutoWaitNoticesEnabled` | toggle | `true \| false` |  |
| `forceOffFeaturesMigrationDone` | toggle | `true \| false` |  |
| `foregroundAppPriorityFloorEnabled` | toggle | `true \| false` | Keeps the app you are using from being slowed down by your agents. Omniscio holds its agents at below-normal CPU priority; if the app you are working in (Chrome, say) ever starts at that same level — which can happen after a restart — it has to share the CPU equally with every agent and feels sluggish. When on (the default), Omniscio notices that and raises the app, plus its own helper processes, back to normal priority. It never raises anything above normal, never touches an app you set to Efficiency mode, and never touches an agent. Windows only. Kill switch AMC_DISABLE_FOREGROUND_APP_PRIORITY_FLOOR. Synonyms: foreground app priority, Chrome slow when agents run, protect my browser, computer slow outside Omniscio, below normal priority app, raise my app priority. |
| `foundryBuiltinMigrated` | toggle | `true \| false` |  |
| `frenchPilotEnabled` | toggle | `true \| false` | Adds French (Français) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `gateWholeRepoTypeLintRequired` | toggle | `true \| false` | Whether the merge gate (npm run gate) runs the whole-repo typecheck and the whole-repo lint. OFF by default, because together they took about 22 of the gate's 23 minutes while nothing blocks on them: the ready-to-merge step already typechecks and lints each branch's own changed files. While off, the gate skips both and says why; the typecheck still runs whenever landerTypecheckReceiptRequired is on, because the auto-lander then needs its receipt - and even then it is NOT the whole repo: it covers only the projects your branch's changed files belong to, so a branch touching one file under src/main compiles the main program alone. Running npm run typecheck or npm run lint by name is unaffected - naming either one still checks the whole project. Turn it on to have every gate run both again; it is read live, so no restart is needed. Synonyms: whole repo typecheck in the gate, full lint in the merge gate, why did the gate skip typecheck, slow merge gate, gate typecheck lint required, make the gate check the whole repo. |
| `gauntletLoopEnabled` | toggle | `true \| false` | In-development: run a goal through the Gauntlet, where several builder agents each write an attempt, fresh blind critic agents score every attempt against a concrete bar, and it loops until a builder passes or hits the round or cost ceiling. v1 handles text goals (a written artifact); it spawns paid sessions and is cost-capped per run. Off by default; hidden until shipped. |
| `geminiSttEnabled` | toggle | `true \| false` | In development: transcribe your voice with Google's Gemini 3.5 Transcribe Live. When it is on, the voice settings gain a "Google Gemini 3.5" speech option AND FlowVoice (OS-wide dictation) gains a speech-engine choice. It uses your own Gemini API key if you have added one; without one, dictation runs on ours instead, which needs you to be signed in. |
| `georgianPilotEnabled` | toggle | `true \| false` | Adds Georgian (ქართული) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `germanPilotEnabled` | toggle | `true \| false` | Adds German (Deutsch) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `gitGuardrailsEnabled` | toggle | `true \| false` | Omniscio-enforced git safety for agent sessions — blocks an agent from committing or pushing to a protected branch (master/main), a destructive git stash, and edits while on a protected branch, with a per-repo exclusion list + a time-boxed pause. On by default; turn it off in Settings → Features or the Dev Pipeline panel. |
| `gitGuardrailsSelfPauseEnabled` | toggle | `true \| false` | When on (default), an agent blocked by a git guardrail may open a brief, bounded self-pause window (up to 10 minutes, limited to 3 per hour) to unblock itself, with an inbox notice. Off: only a human can lift the block. Settings → Features → "Let an agent unblock itself briefly". |
| `gitPollLimiterUserHarmGateEnabled` | toggle | `true \| false` |  |
| `gitReadCacheEnabled` | toggle | `true \| false` |  |
| `gitStoreMaintenanceUserHarmGateEnabled` | toggle | `true \| false` |  |
| `gitWriteBrokerEnabled` | toggle | `true \| false` |  |
| `githubCodeSearchEnabled` | toggle | `true \| false` | Adds a "Code Search" sidebar tab to search code across your GitHub repositories and open matches in the file viewer. |
| `githubCommitLinkingEnabled` | toggle | `true \| false` | Automatically links git commits that reference Mission Control items (e.g. MC-42) to those items, showing commit activity on the item card. |
| `githubIssueCreateEnabled` | toggle | `true \| false` | Adds a "New issue" button to the GitHub Issues tab so you can create issues (with labels and assignees) without leaving Omniscio. |
| `githubIssuesEnabled` | toggle | `true \| false` | Adds a "GitHub Issues" sidebar tab to browse, comment on, and close or reopen GitHub issues across all your repos. |
| `githubMcBranchCreationEnabled` | toggle | `true \| false` | In-development: create a GitHub branch directly from a Mission Control board item and auto-link it back. Off by default. |
| `githubMcReviewNotificationsEnabled` | toggle | `true \| false` | In-development: surfaces GitHub PR review requests (pending, approved, changes requested) on linked Mission Control item cards. Polls review state for PRs linked via cross-entity links and raises inbox alerts on changes. Off by default. |
| `githubPrAutoCloseEnabled` | toggle | `true \| false` | When on (default), a PM board item auto-moves to its board's Done group once every GitHub PR linked to it has merged. Also gated behind the github-pr-linking feature. No Settings-UI control yet; set via CLI/PATCH. |
| `githubPrLinkingEnabled` | toggle | `true \| false` | Automatically links GitHub PRs that reference Mission Control items (e.g. MC-42 in the PR title) and shows live PR status badges on the board. |
| `githubReleasesEnabled` | toggle | `true \| false` | Adds a "GitHub Releases" sidebar tab to view a repository's releases and create a release (draft by default) without leaving Omniscio. |
| `glmActiveAccountId` | text | `string` |  |
| `globalAuthGateActivated` | toggle | `true \| false` | Whether the Global Auth sign-in gate is ACTIVATED — the lever that arms the hosted Firebase-backed sign-in gate. When on (and a baked Firebase web config is present) the app seeds the gate and requires sign-in before use; when off the gate stays inert. Managed by the app's gate provisioning, not a per-user preference. Synonyms: auth gate activated, sign-in gate armed, global sign-in enabled, hosted auth. |
| `globalMemoryEnabled` | toggle | `true \| false` | In-development: a progressive-disclosure, agent-written memory tree on the Context Dock store; agents browse + load memory across sessions; off by default; hidden until shipped. |
| `googleCliFallbackEnabled` | toggle | `true \| false` |  |
| `googleMeetEnabled` | toggle | `true \| false` | In-development: pull your Google Meet history, cloud recordings, speaker-attributed transcripts, and participant lists from the Google Meet REST API. Requires Google Workspace Business Standard or higher. Off by default. |
| `granolaAuthMode` | select | `"apiKey" \| "localSession"` | How Omniscio authenticates to Granola: "apiKey" (the default) uses the Granola API key you paste against Granola's public REST API, while "localSession" is the free-plan path that reads the login of the Granola desktop app already installed on this PC, storing no key. localSession is Windows-only. Synonyms: granola auth mode, granola api key vs local, use granola without a key, granola free plan login. |
| `granolaEnabled` | toggle | `true \| false` | Adds a "Granola" sidebar tab to browse your Granola meeting notes — recent meetings, summaries, and full transcripts — and use a transcript as context for a new Claude session, without leaving Omniscio. Connect with a Granola API key in Settings. In development. |
| `granolaInboxEnabled` | toggle | `true \| false` |  |
| `grokSttEnabled` | toggle | `true \| false` | In development: transcribe your voice with xAI's Grok speech-to-text. When it is on, the voice settings gain a "Grok (xAI)" speech option. It reuses your existing xAI API key (the SAME key as Grok voice output) and bills to your own key. |
| `guardLaneRequired` | toggle | `true \| false` | Whether the long cross-cutting guard check (npm run test:guard) must run before a branch can be marked ready and landed. OFF by default, because that check takes a long time: while off, the merge gate and npm run build:verify skip it and say so, and neither the ready-to-merge step nor the auto-lander refuses a branch just because the guard check never ran. Every other check is unchanged, and a branch that does run the guard check is still held if it adds new guard failures. Turn it on to require the guard check again; it is read live, so no restart is needed. Synonyms: guard lane required, require guard tests, skip the guard lane, test:guard, turn the guard lane back on, why did my branch skip the guard check. |
| `habitsEnabled` | toggle | `true \| false` | Adds a "Habit Tracker" sidebar tab — a personal habit / daily-routine tracker (define habits by category, log each day, see streaks, a calendar grid, and trends), fully local to Omniscio. Optional daily reminders. In development. |
| `habitsRemindersEnabled` | toggle | `true \| false` | When the Habit Tracker is enabled, whether its daily reminder nudge fires. On by default, so an enabled habit with a reminder time gets its nudge; turn off to keep habits without any reminder nudges. Synonyms: habit reminders, daily habit nudge, habit tracker notifications. |
| `handoffNoticeAuto` | toggle | `true \| false` |  |
| `handoffNoticeEnabled` | toggle | `true \| false` |  |
| `handoffNoticeTokens` | number | `integer 20000..∞` | The operator's PINNED absolute context-in-use token threshold, used ONLY when `handoffNoticeAuto` is false ("Custom"). Absolute, not a percentage, because quality drift tracks context LENGTH. Floor 20_000; set it very high to effectively mute the notice. Retained but IGNORED while Automatic is on (the derived per-model threshold governs). Default 150_000 — the legacy flat value, and exactly 0.75 × 200k. |
| `hardcoreModeEnabled` | toggle | `true \| false` |  |
| `hardcoreModeForcePastPhrase` | text | `string (≤200)` |  |
| `hardcoreModeForcePastRequirePhrase` | toggle | `true \| false` |  |
| `hardcoreModeLabRevealed` | toggle | `true \| false` | In-development: an app-wide discipline mode (the opposite of Focus Mode). Caps how many times you can look at a session or inbox item before it locks. No snooze; you must respond, archive, convert it to a scheduled follow-up, or get AI help. Hidden until shipped. |
| `hardcoreModeLooksBeforeLock` | number | `integer 0..10` |  |
| `hardcoreModeScope` | select | `"all" \| "selected"` |  |
| `hardcoreModeSelectedProjectIds` | list | `array of string (≤200)` |  |
| `hardcoreModeSnoozesBeforeLock` | number | `integer 0..10` |  |
| `harnessDefaultThinkingLevels` | map | `map of string → "auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `headerBlockOrder` | list | `array of string (≤50)` | Ordered block ids for the header's right-side drag-to-reorder row (for example account, hardcore, shortcuts). Controls which header blocks appear in that row and their order; written automatically when you drag the blocks into a new arrangement. Synonyms: toolbar block order, header arrangement, reorder header icons, toolbar layout. |
| `heardAboutUsSyncedAt` | text | `string (≤40)` |  |
| `heavyJobBrokerEnabled` | toggle | `true \| false` |  |
| `helpdeskAvailability` | select | `"online" \| "offline"` |  |
| `helpdeskAvailabilityOfflineUntil` | text | `string` | The TIMED-offline deadline paired with `helpdeskAvailability: 'offline'` — an ISO timestamp ("put me back online at this time"), or null/absent for a plain indefinite offline. Written by the availability menu's "Offline for 30 minutes / 1 hour / 4 hours" choices; read ONLY through `resolveHelpdeskAvailability` (shared/helpdesk-types.ts — the single rule that decides effectiveness and expiry). Once the deadline passes, the developer is effectively online immediately, and the main-process presence heartbeat self-heals these fields back to plain online so every surface agrees. Meaningless while availability is 'online'. |
| `helpdeskConsoleListWidth` | number | `integer 240..560` | How wide the Help Desk's left-hand conversation queue column is, in pixels — the width you last dragged it to, remembered so the console comes back the way you left it. The two console columns each store their own width, so dragging one never moves the other, and the defaults match the fixed widths the console used before it became resizable. Synonyms: help desk queue width, ticket list column width, resize the help desk list, conversation queue width, support console column size. |
| `helpdeskConsoleRailWidth` | number | `integer 240..480` | How wide the Help Desk's right-hand details rail is, in pixels — the panel showing the selected conversation's details, remembered at the width you dragged it to. It is stored separately from the left queue column, so the two drags never leak into one another, and it defaults to the fixed width the rail used before the console became resizable. Synonyms: help desk details rail width, ticket details panel width, resize the help desk rail, support console rail size, right panel width in help desk. |
| `helpdeskDevConsoleEnabled` | toggle | `true \| false` | Developer-only: its own sidebar row for the admin console that lists user-escalated questions, so the developer can reply from inside Omniscio. Separate from the customer Get Help seat — either can be on without the other — and it also needs the admin entitlement. Stays in development even after Helpdesk ships. |
| `helpdeskEmailTicketIntakeEnabled` | toggle | `true \| false` | Turns a plain-English inbound support email (no [BUG:]/[FR:] subject marker) into a real Help Desk ticket with its own lifecycle and a two-way email binding, instead of only answering it. Its own switch — separate from the "Get Help" panel above. Claude only ever drafts a reply; a human presses send. |
| `helpdeskEmailTicketIntakeInvestigationModelTier` | select | `"genius" \| "smart" \| "worker" \| "basic"` |  |
| `helpdeskEnabled` | toggle | `true \| false` | In-app "Get Help" panel: ask a question in plain English and get an AI answer grounded in the app docs. |
| `helpdeskWidgetPosition` | select | `"left" \| "right"` |  |
| `hiddenToolbarItems` | list | `array of string (≤50)` |  |
| `hideBackgroundAckEnabled` | toggle | `true \| false` |  |
| `hiligaynonPilotEnabled` | toggle | `true \| false` | Adds Hiligaynon (Ilonggo) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `hindiPilotEnabled` | toggle | `true \| false` | Adds Hindi (हिन्दी) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `hubDescriptions` | map | `map of string → string (≤240)` | Your own custom description for a hub — a built-in tool/integration, a sidebar category, or a project — keyed by hub id, overriding the AI-written default your Chief of Staff and agents otherwise read. Empty (the default) uses the baked-in descriptions. Settings → Hub Descriptions (edit, regenerate with AI, or reset to default per hub). |
| `hubDescriptionsEnabled` | toggle | `true \| false` | A Settings section where you can read and edit the short description of every hub — each built-in tool/integration, each sidebar category, and each of your projects. Your Chief of Staff and agents read these to know what each part of Omniscio is and when it’s relevant; each has an AI-written default you can regenerate or override. On by default; the toggle stays live so you can turn it off with one setting flip. |
| `hungarianPilotEnabled` | toggle | `true \| false` | Adds Hungarian (Magyar) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `ilocanoPilotEnabled` | toggle | `true \| false` | Adds Ilocano (Ilokano) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `imageStudioNativeEnabled` | toggle | `true \| false` | Native image generation panel (replaces the embedded website). Off by default; hidden until shipped. |
| `imeHotkeyConflictWarningEnabled` | toggle | `true \| false` |  |
| `inboxAutoCheckInEnabled` | toggle | `true \| false` |  |
| `inboxAutoCheckInMultiple` | number | `integer 1..10` | The multiple of the waiting period (autoWaitMinutes) a surfaced session must sit UNTOUCHED in your inbox before `inboxAutoCheckInEnabled` auto-checks-in. Effective dwell = this × autoWaitMinutes (e.g. 2 × 30 = 60 min). Range 1–10, default 2. Read as `inboxAutoCheckInMultiple ?? 2` via resolveInboxCheckInMultiple. See waiting-detector-contract.md. |
| `inboxBacklogNudgeEnabled` | toggle | `true \| false` | When on (default), Omniscio drops a gentle inbox card at most once a day when your session inbox has piled up — at least 15 sessions that have been waiting 3+ days for you — while you are actively working but not archiving, nudging you to archive what you are done with so your inbox does not grow to hundreds of stale items. It never fires on a busy day of fresh items (the trigger is quantity AND age), runs entirely on your machine with no AI, and clears itself once the backlog clears. Turn it off in Settings under Notifications or with the card's "Turn off these nudges" button. Synonyms: inbox backlog nudge, archive reminder, clear your inbox, too many sessions, stale sessions piling up, backlog nudges. |
| `inboxKeepListFocusEnabled` | toggle | `true \| false` | In-development: the inverted bulk snooze, for an intentional focus block. Today you select what to HIDE, so the work scales with how noisy your inbox is - exactly backwards when you are trying to focus. This adds 'Snooze everything else...' to the inbox right-click menu and a 'Snooze others' button on a project hub's header: you pick the few things worth keeping, choose a duration, and everything else leaves in one action and comes back on its own. It sweeps everything, including task reminders and pending approvals, so it asks once and states the real count - and the whole sweep is undoable. Off by default. |
| `inboxPilotEnabled` | toggle | `true \| false` |  |
| `inboxPilotRetireMigrationDone` | toggle | `true \| false` |  |
| `inboxPostSendBehavior` | select | `"stay" \| "return_to_inbox"` |  |
| `inboxRulesEnabled` | toggle | `true \| false` | In-development: define plain-language rules that automatically suppress, archive, or snooze new inbox alerts the moment they arrive — no manual triage needed. Off by default. |
| `inbuiltTerminalBlocksEnabled` | toggle | `true \| false` | Show visual command boundaries (check / cross per exit code) with fold, copy, and re-run per block. Requires the inbuilt terminal to be on. |
| `indonesianPilotEnabled` | toggle | `true \| false` | Adds Indonesian (Bahasa Indonesia) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `insightsGroupCollapsed` | toggle | `true \| false` |  |
| `installReaperAlertEnabled` | toggle | `true \| false` |  |
| `intakeDedupEnabled` | toggle | `true \| false` |  |
| `intakeGloballyPaused` | toggle | `true \| false` |  |
| `integrationSidebarHidden` | toggle | `true \| false` |  |
| `ioSweepTimeBudgetEnabled` | toggle | `true \| false` |  |
| `isolatedComposerEnabled` | toggle | `true \| false` |  |
| `isolationDefault` | toggle | `true \| false` | Whether a NEW session starts isolated by default — running against its own copy of the project on its own branch instead of the shared project folder, so two sessions running at once cannot overwrite one another. Off by default. This is the app-wide default only: a project can carry its own (Edit Project, More options, Isolate new sessions), and any single session can override it at launch by holding the + button and toggling Isolate. It applies to the sessions you start next, never to the ones already running. See the Session isolation page for where that copy lives and how the work comes back. |
| `isolationFallbackDir` | text | `string (≤500)` | Absolute path to a fallback folder used only when requireWorktreeIsolation is on AND creating a git worktree fails. Instead of erroring or touching your main repo, the session runs from a plain source copy at <fallbackDir>/<sessionName>-<sessionId>/. Empty (the default) means there is no fallback — the session simply errors when a worktree cannot be made. Synonyms: isolation fallback directory, worktree fallback path, scratch copy folder, safe place to run when worktree creation fails. |
| `italianPilotEnabled` | toggle | `true \| false` | Adds Italian (Italiano) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `japanesePilotEnabled` | toggle | `true \| false` | Adds Japanese (日本語) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `jarvisBriefingPromptOverride` | text | `string (≤10000)` |  |
| `jiraBoardEnabled` | toggle | `true \| false` | Adds a "Jira" sidebar tab to view and work your Jira boards — columns, issue detail, transitions, comments — without leaving Omniscio. Connect with your Atlassian email + API token in Settings. In development. |
| `jiraDefaultProject` | text | `string (≤200)` |  |
| `jiraEmail` | text | `string (≤320)` |  |
| `jiraSiteUrl` | text | `string (≤2000)` |  |
| `jlsMcpGatewayRoutingEnabled` | toggle | `true \| false` | In-development: routes JLS Image Studio MCP image calls through the Omniscio unified-billing gateway (billed to your gateway_users credits) instead of calling JLS directly with your personal jls_ak_ key. Falls back to the personal key safely on any forwarding failure, so enabling it carries no breakage risk. Off by default; hidden until shipped. |
| `jobMonitorEnabled` | toggle | `true \| false` |  |
| `journalEnabled` | toggle | `true \| false` | A personal journal with freeform writing and guided AI reflection modes. Write freely or use templates (gratitude, daily reflection, problem-solving, emotional processing) with an AI mentor for Socratic self-discovery. Entries are synced, searchable, and taggable. |
| `kapampanganPilotEnabled` | toggle | `true \| false` | Adds Kapampangan (Pampango) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `keepWaitingMinutes` | number | `integer 5..240` | SEPARATE window (minutes) for the inbox "Keep waiting" button — how long one deliberate press re-arms the silent wait AFTER a wait_timeout surfaced the session. Its OWN knob, distinct from `autoWaitMinutes` (the initial wait + background-task hold + auto-nudge cadence): default 60 (the agent has already had one full window), range 5–240. The button label and the armed window both read this, so they can't disagree. Read as `keepWaitingMinutes ?? 60` (see resolveKeepWaitingMinutes). See waiting-detector-contract.md. |
| `keybindings` | map | `map of string → array of string (≤50)` |  |
| `keyboardDemoTourEnabled` | toggle | `true \| false` | In-development: a keystroke-driven copy of the Interactive Demo. Each step shows a key to press (the app’s real shortcuts), so the walkthrough doubles as hands-on keyboard practice on safe sample data. Reveals a "Keyboard Demo" card in Settings → Setup Wizards. |
| `kmsQuickFindHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `kmsQuickFindHotkeyEnabled` | toggle | `true \| false` |  |
| `kmsWindowHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `kmsWindowHotkeyEnabled` | toggle | `true \| false` |  |
| `kmsWizardAlertSeen` | toggle | `true \| false` |  |
| `koreanPilotEnabled` | toggle | `true \| false` | Adds Korean (한국어) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `labsBadgeEnabled` | toggle | `true \| false` | Example in-development feature: shows a small "🧪 Labs" badge in the app so the gating mechanism can be proven end to end. |
| `labsNotifiedFeatureIds` | list | `array of string (≤200)` |  |
| `landStandardModes` | map | `map of string → "block" \| "advisory" \| "off"` | Per-standard MODE overrides for the auto-lander's land standards — the catalogue in `src/shared/land-core/land-standards-catalog.ts`. `block` refuses the land, `advisory` runs the check and only logs its reason, `off` never runs it. Unset = every standard at its catalogue default (the lander exactly as before). Keys are validated against the catalogue, so a typo is refused rather than kept. An env kill switch (`AMC_DISABLE_…=1`) still forces a standard OFF over any value here — env can only turn off. Refused to a scoped agent token over the CLI; the owner's global token and the desktop may set it. Supersedes `autoLanderPrChecklistMode` for the `pr-checklist` row (the legacy key is still honoured when this map says nothing about it). Read the effective modes with `GET /auto-lander/standards`; flip one with `PATCH /auto-lander/standards/:id`. |
| `landedArchiveRefPruneReportedAt` | text | `string` | ISO timestamp the landed-branch archive-ref prune stamps after its ONE report-only cycle — the run that reports which `refs/auto-lander-archive/*` it WOULD retire without deleting one. Null means that cycle has not happened yet and the next pass is a dry run. Persisted rather than held in memory so it happens once ever, not once per app restart. Job-written bookkeeping; the on/off lever is the `lander-archive-ref-prune` switch, never this field. See auto-lander/landed-archive-ref-prune.ts. |
| `landerConvoyYieldEnabled` | toggle | `true \| false` | Re-arm the convoy-window yield: let a SATURATED worktree disk drop the lander back into the bounded slow lane even while `landerOutranksAgents` is on. Default OFF (owner decision 2026-09-12) — the lander yields to the USER, not to load the agents themselves created. WHY IT FLIPPED. The yield keyed on `diskConfirmedSaturated`, which on the owner's box is not an event but a constant: measured 2026-09-12, packStorm ON 100% of a 30-min window, CPU 100%, kernel-bound 95%. So the "convoy window" never closed, the lander never left the slow lane, and it managed 4 lands/hour against 20 ready branches — a queue that grows faster than it drains (sampled 15 -> 24 -> 26 -> 29 in ~70 min, oldest wait 71 min). The signal it yields on measures AGENT BUSYNESS, not user harm. Over the same window the user-facing numbers were main thread stalled 0.5%, 3 stalls, and ZERO felt slow interactions — so the lander was standing down for a freeze that was not happening to anybody. That is precisely inverted from tier 1 (user-experience-inviolable): the lander outranks all agent work and yields only to the user. ON restores the pre-2026-09-12 behaviour exactly, with no rebuild — flip it the moment a real freeze is attributable to landing, which is the case this switch exists for. The boot-settle defer, the post-land cooldown and the lander's own capped git pools (read-poll 6 + snapshot 3 + mutation 4) are untouched either way and still bound concurrency. Env kill switch AMC_DISABLE_LANDER_OUTRANK_YIELD=1 continues to force full-tilt. |
| `landerGateProofTestsEnforced` | toggle | `true \| false` | When on, the auto-lander refuses to merge a branch unless that exact version of it has a recorded tests run â and refuses just as firmly when the answer is MISSING, STALE, or "the cloud could not say". The point is that no answer is not a pass. It does NOT refuse a branch whose tests are red only because master itself is red; it refuses the ones nobody checked. OFF by default (warn-only): while off it still works out what it would have refused and writes that down, so you can see the real cost before switching it on â measured at roughly 1 land in 6. Turn it on once that number looks acceptable. Takes effect on the next land with no restart. This is the land-time check and is deliberately separate from the tag-time one (landerTestsReceiptRequired), which runs once when a branch is first marked ready and never again. |
| `landerGitExecUserHarmGateEnabled` | toggle | `true \| false` | Whether the helper that watches for git itself failing on this machine may REPAIR it on its own, instead of only reporting. OFF by default, and it stays off until there is real evidence of how often its judgement would have been right — because the repair can touch every other agent's git at once, so a wrong call is felt across the whole machine and not just by the session it was watching. While off it still notices, and raises an inbox card describing what it saw. Synonyms: git exec user harm gate, arm the git auto-repair, git is broken helper, who repairs git automatically. |
| `landerMasterBuildFreezeEnforced` | toggle | `true \| false` | When on, a CONFIRMED broken master actually stops merging — on every route, not just the in-app one. After each merge the app builds master's own code; if that build genuinely fails, landing pauses until a build of master passes again. A red-master pause does not time out: it lifts on a passing build and on nothing else, because a check that stops answering is not evidence the break went away. A branch whose own build has already passed may land through it, which is how the repair gets in, and the scripts that REPAIR master by pulling from the remote are never blocked — blocking those would trap you. OFF by default, and that default is the owner's deliberate decision rather than a shortfall: he does not want a broken master to stop the merger. Be aware that what the two positions do today differs — with it off, the landers running outside the app do not refuse a land, but the in-app lander's own tick still holds on the freeze record, so landing on this machine is not yet fully continuing through a red master. That last part is a known defect owned elsewhere, not the intended behaviour; the auto-lander master-build-freeze postmortem records it in full. Takes effect on the next pause with no restart. |
| `landerOutranksAgents` | toggle | `true \| false` | When on (the default), the auto-lander gets priority over agent sessions for git capacity, so landing keeps flowing on a busy machine: it skips the load-gate defer while agents yield. Turn it off to go back to the original behaviour, where landing defers behind load exactly like everything else. This does not affect the boot-settle defer, which still applies either way. Kill switch AMC_DISABLE_LANDER_OUTRANK=1. Synonyms: lander outranks agents, landing priority, why does landing skip the load gate, prioritize landing over agents. |
| `landerRepairUnderLoadEnabled` | toggle | `true \| false` | When on (the default), the auto-lander still runs its PAID repair session — the one that rebases and re-tags a stranded branch — even when the machine reads as loaded. Normally that repair is deferred so it cannot pile more work onto a busy box, but on a machine that reads busy most of the day the defer becomes a permanent stall: measured 2026-09-19, 40 deferrals against 2 real repairs over 3.5 hours, with stranded branches waiting 60-100 minutes on a veto only a repair clears. Since a repair is the only thing that clears most vetoes, letting it through is worth the load it adds. Turn it OFF to restore the old defer-under-load pacing. Synonyms: repair under load, let the lander repair while busy, deferred repair session, stranded branch repair under load, auto-lander repair throttling. |
| `landerTestsPresenceRequired` | toggle | `true \| false` | The PRESENCE half of the tests-receipt rule, on its own lever (on by default). Turn it off and a branch with NO tests receipt at all is allowed through — for the window where the system that produces receipts cannot run, so absence stops being treated as something a person has to wave through by hand. A receipt that records a real regression is still refused, because that half keeps reading landerTestsReceiptRequired. Synonyms: require a tests receipt to exist, missing receipt, no answer is not a pass, disable the presence check. |
| `landerTestsReceiptRequired` | toggle | `true \| false` | When on (the default), a branch must carry proof that its tests ran at the exact commit it is about to be tagged from, or its ready-to-merge tag is not believed and the branch is held. It is a PRESENCE rule: the receipt has to exist and cover that commit — it does not have to be green (a red that is already on your main branch is not the branch's fault). Read live on every land, so suspending it needs no restart, and AMC_DISABLE_LANDER_GATE_PROOF_VETO=1 overrides it outright. Synonyms: require a tests receipt before landing, tests receipt, test proof before tag, why is my branch held, no receipt no tag. |
| `landerTypecheckReceiptRequired` | toggle | `true \| false` | When on (the default), the auto-lander refuses to merge a branch unless that exact version of it has a recorded PASSING typecheck — proof the code compiles, rather than a promise that it does. Since 2026-09-27 that typecheck is SCOPE-TO-YOUR-DELTA rather than the whole repository: it compiles the projects your changed files belong to, so it is a proof about what you touched. A change to a shared type or a config file still widens it back to every project that could be affected, and a branch that changes no TypeScript at all records the check as skipped rather than compiling anything. Turn it OFF only when the system that produces those receipts is broken, because then no branch can earn one and the auto-lander quietly stops merging EVERYTHING: your work still reaches master by other routes, but sessions stop getting their "Auto-landed" note and stop auto-archiving, which looks like the auto-lander forgetting to stamp finished sessions. Turning it off suspends ONLY this one check — the translation, guard-baseline and PR-checklist checks keep blocking, so a branch is never merged unchecked. Takes effect on the next land with no restart. Turn it back on as soon as typechecks are healthy again, or you lose the guarantee that landed code compiles. |
| `languageSettingEnabled` | toggle | `true \| false` | Choose the display language for the interface. Omniscio offers English plus its machine-translated pilot catalogs (Spanish, Tagalog, Japanese, German, Hindi and more); further languages appear as their translations complete. |
| `lastActiveProjectId` | text | `string (≤200)` |  |
| `lastActiveSessionId` | text | `string (≤200)` |  |
| `lastAutoSyncPulledMirrorId` | text | `string (≤256)` | Internal bookkeeping: the mirror-archive id most recently PULLED by auto-sync. Lets the pull short-circuit skip the expensive decrypt when the newest foreign archive is unchanged. Not user-facing. |
| `lastBackupMirrorAt` | text | `string (≤64)` | ISO timestamp of the last successful mirror write. Empty string = never. |
| `lastBackupMirrorAutoSyncAt` | text | `string (≤64)` | ISO timestamp of the last successful automatic sync. Empty = never. |
| `lastBackupMirrorError` | text | `string (≤2000)` | Last mirror-write error message (for diagnostics). Empty = no failure. |
| `lastGitRepackAt` | text | `string (≤64)` | ISO timestamp of the last startup git compaction that CHANGED a store. Empty = never ran usefully. Distinct from the results clock below on purpose: it answers "when was this store last actually compacted", which a run that found nothing to do cannot answer. |
| `lastGitRepackResults` | list | `array of object { afterBytes: number; afterPacks: number; beforeBytes: number; beforePacks: number; reason: string; repoPath: string; status: "compacted" \| "skipped" \| "failed" }` | Internal bookkeeping: the outcome of the most recent startup git compaction, surfaced by the Git storage card so the user learns what was reclaimed (or why nothing was). Not user-facing input. |
| `lastGitRepackResultsAt` | text | `string (≤64)` | ISO timestamp of the RUN that produced `lastGitRepackResults`, written on every run. It exists because those two facts came apart: `lastGitRepackAt` moves only when a run really compacted something, so after a skipped run the card would have shown results from moments ago under a header naming a run days old. The card renders THIS beside the results. |
| `lastIntegrityCheckAt` | text | `string (≤64)` | ISO timestamp of the last successful PRAGMA quick_check. Empty = never. Gates the deferred startup integrity check to at most once per week (quick_check scales with DB size: ~4.4s on a 950 MB DB). |
| `lastPushedMirrorChangeMarker` | text | `string (≤128)` | Internal bookkeeping: a cheap content token of the DB (message/session counts + max message timestamp) captured at the last auto-PUSH. Lets the push short-circuit skip re-writing a ~1–3 GB archive when nothing changed. Not user-facing. |
| `lastReleaseNotesVersion` | text | `string (≤50)` | Internal marker (not a user setting, no UI): the app version the post-update "What's new" inbox card was last evaluated for. Compared against the running version at launch — only an UPGRADE posts a card. Starts null (a fresh install records the baseline with no card). See services/app/release-notes-inbox.ts. |
| `lastSetupBackupAt` | text | `string (≤64)` | ISO timestamp of the last successful backup send. Empty string = never sent. |
| `lastSetupBackupContentHash` | text | `string (≤128)` | SHA-256 content hash of the last successfully sent bundle. Used for dedup. |
| `lastSetupBackupFailureAt` | text | `string (≤64)` | ISO timestamp of the last failed backup attempt (for diagnostics). Empty string = no failure. |
| `lastSetupBackupFailureMessage` | text | `string (≤2000)` | Last failure error message (for diagnostics in Settings UI). Empty string = no failure. |
| `lastWhatsNewSeenVersion` | text | `string (≤50)` | Internal marker (not a user setting, no UI): the app version the first-launch-after- update "What's new" TOAST was last shown for. Independent of lastReleaseNotesVersion (the inbox card's marker) because the two surfaces are dismissed independently. Starts null (a fresh install baselines silently, no toast). See renderer features/app-update/WhatsNewAutoSurface.tsx. |
| `layoutOverridesBySurface` | map | `map of string → unknown` | Your own fine-tuning on top of an active layout mod, keyed by app surface (e.g. sidebar, session list). Empty (the default) means no extra tuning beyond the mod's own preset. Set from the Appearance → Layout Mods card; auto-cleared with a warning if a mod errors. |
| `lifeInventoryEnabled` | toggle | `true \| false` | A structured self-assessment inside AI Coaching — rate yourself across two inventories (Symptoms and Strengths) and Omniscio quietly folds a summary into your coaching profile, with full detail your coach can open on request. Stored only on your computer. |
| `linearBoardEnabled` | toggle | `true \| false` | Adds a "Linear" sidebar tab to view and work your Linear teams — workflow-state columns, issue detail, comments, assignment — without leaving Omniscio. Connect with a Linear personal API key in Settings. In development. |
| `liteModeOfferSeen` | toggle | `true \| false` |  |
| `liteModeSnapshot` | map | `map of string → true \| false \| number` |  |
| `localChatEnabled` | toggle | `true \| false` | In-development: chat with a local AI model running on your own PC via Ollama — free, private, offline. Includes a guided setup that detects Ollama, recommends a model for your machine, and downloads it. |
| `localSttEnabled` | toggle | `true \| false` | In development: speak to Omniscio with no API key. A small speech model runs on your own computer, free. When it is on, the voice settings gain a "Built-in (free)" speech option, and speaking works out of the box even before you add any key. |
| `localTitleModel` | text | `string (≤100)` | Ollama model that names sessions ON THIS MACHINE, ahead of the cloud cascade. `''` = off (cloud only). Defaults to the fine-tuned title model rather than off, because the model name IS the switch: a machine that does not have this model installed fails the availability probe and takes the byte-identical cloud path, so shipping it on costs nothing and saves the one person who DOES have it from a setup step. A local title never leaves the machine and never bills. Local output is validated against the built-in prompt's own rules and falls through to the cloud cascade on ANY miss. |
| `logTimeBasedRetentionEnabled` | toggle | `true \| false` |  |
| `lowSpecWarningSeen` | toggle | `true \| false` |  |
| `managedProvidersEnabled` | toggle | `true \| false` | Paid-plan users run non-Anthropic sessions on Omniscio's own gateway keys, drawing down prepaid credits — no personal provider key needed. The gateway 402s at zero. DeepSeek is live; GLM is coming. |
| `managedSessionKeysOptIn` | toggle | `true \| false` | In development: run native Claude coding sessions on Omniscio's pooled API key via the gateway — draining your prepaid credits instead of bringing your own key. Hidden until the gateway Anthropic key is live. |
| `marketplaceAdminRole` | select | `"admin" \| "developer"` |  |
| `marketplaceReEnabledDone` | toggle | `true \| false` |  |
| `masterDebtAutoFixerEnabled` | toggle | `true \| false` | In-development: watches the master branch for accumulated debt (failing checks, flagged findings) and either drops an inbox card asking you to fix it, or — when you turn auto-fix on — spawns fix sessions for you. Hidden until shipped. |
| `masterSyncCoordinatorModel` | text | `string` | Which model the master-sync escalator buys for the COORDINATOR — the single session that actually resolves the conflicts, commits, and lands the merge onto your local master. Leave blank (the default) to use what the script ships with, deepseek-v4.1-flash. This is the half of a sync that does the real work, so it is the one to change if you want the judgment better or cheaper. Set it with PATCH /settings/masterSyncCoordinatorModel; it takes effect on the next hourly tick with no restart, and a model the spawn refuses falls back to the built-in default rather than stalling the sync. Does not change HOW MANY sessions are bought — that is the escalation cap. Synonyms: master sync model, sync coordinator model, which model resolves sync conflicts, change the sync model, master sync engine, sync resolver model, conflict resolver model. |
| `masterSyncEscalateEnabled` | toggle | `true \| false` |  |
| `masterSyncProvider` | text | `string` | Which engine the master-sync coordinator and its analysis workers run on. Leave blank (the default) to use what the script ships with, deepseek. Change it only if you want the whole sync on a different provider — the model keys beside it must then name models that provider actually serves, or the spawn is refused and the built-in defaults are used instead. Set it with PATCH /settings/masterSyncProvider. Synonyms: master sync provider, sync engine, which provider runs the sync, change sync engine, sync vendor, master sync backend. |
| `masterSyncWorkerModel` | text | `string` | Which model the master-sync escalator buys for its ANALYSIS WORKERS — the up-to-ten read-only helpers that each study one packet of conflicted files and report proposed resolutions back to the coordinator. They never edit, commit, or land, so a cheaper model is the normal choice. Leave blank (the default) to use what the script ships with, deepseek-v4.1-flash. Set it with PATCH /settings/masterSyncWorkerModel; it takes effect on the next hourly tick with no restart. Synonyms: sync worker model, master sync helper model, analysis worker model, cheap model for sync workers, sync fan-out model, conflict analysis model. |
| `maxSessionsPerProject` | number | `integer 1..1000` |  |
| `mcApprovalColumnEnabled` | toggle | `true \| false` | In-development: an approval column type for Mission Control boards. Items can be approved or rejected by team members, with configurable thresholds and rejection modes. Hidden until shipped. |
| `mcChatBotChannelId` | text | `string (≤128)` | The Team Chat channel id the Mission Control bot posts into. Empty means no target channel is set, so the bot stays silent until one is chosen. Set it over the CLI (/mc/team-chat/bot/config). Synonyms: bot channel, MC bot target channel, where the bot posts. |
| `mcChatBotEnabled` | toggle | `true \| false` | Master switch for the Mission Control team-chat bot — when on (and Mission Control is enabled), the bot posts operational alerts and periodic board-health digests from your Mission Control boards into a Team Chat channel. Off by default; configured over the CLI (/mc/team-chat/bot/config), no Settings-UI toggle. Synonyms: mission control bot, MC bot, team chat bot, enable ops alerts, board alerts on/off. |
| `mcChatBotMode` | select | `"event-driven" \| "digest" \| "both"` | What the Mission Control bot posts: "event-driven" (fire an alert only when something needs attention — a board goes at-risk, a cascade or pattern is detected, or health drops), "digest" (only a periodic board-health summary), or "both". Defaults to event-driven. Synonyms: bot mode, alerts vs digest, event vs summary posting. |
| `mcChatBotSeverityThreshold` | select | `"info" \| "warning" \| "critical"` | The minimum severity an event must reach before the Mission Control bot posts it: "info" (post everything), "warning" (skip info-level), or "critical" (only the most serious). Defaults to warning. Synonyms: bot severity filter, alert threshold, how noisy the bot is. |
| `mcTasksSidePanelCollapsed` | toggle | `true \| false` |  |
| `mcTasksSidePanelColorMode` | select | `"system" \| "light" \| "dark"` | The light/dark/system theme for the Mission Control Tasks side panel specifically (default 'system' — follows the app's dark-mode state). Set with the sun/moon icon inside the Tasks side panel itself, not a Settings-page control. |
| `mcTasksSidePanelEnabled` | toggle | `true \| false` | Docks a collapsible Tasks panel on the right edge of Mission Control so you can see your personal tasks alongside the board. |
| `mcTasksSidePanelWidth` | number | `integer 240..500` |  |
| `mcpServersComposedMigrationDone` | toggle | `true \| false` |  |
| `mcpServersSidebarEnabled` | toggle | `true \| false` |  |
| `meetingDigestScheduleCadence` | select | `"daily" \| "weekly"` |  |
| `meetingDigestScheduleDayOfWeek` | number | `integer 0..6` |  |
| `meetingDigestScheduleEnabled` | toggle | `true \| false` |  |
| `meetingDigestScheduleHour` | number | `integer 0..23` |  |
| `meetingDigestScheduleMinute` | number | `integer 0..59` |  |
| `meetingDigestScheduleRecipeId` | text | `string (≤64)` |  |
| `meetingEnhanceModel` | text | `string` |  |
| `meetingEnhanceOpenAiModel` | text | `string` |  |
| `meetingsAutoEnhance` | toggle | `true \| false` | When on, the AI meeting-notes enhancement pipeline runs automatically right after a meeting capture finishes, instead of waiting for you to click 'Enhance'. Off by default. No Settings-UI control yet; set via CLI/PATCH. |
| `meetingsAutoStopOnInactivity` | toggle | `true \| false` |  |
| `meetingsConsentAckVersion` | number | `integer 0..∞` |  |
| `meetingsConsentAcknowledged` | toggle | `true \| false` |  |
| `meetingsEnabled` | toggle | `true \| false` | Record meetings (mic + system audio), auto-transcribe, and get AI-enhanced notes. In development. |
| `meetingsEnhanceDailyCapUSD` | number | `number 0..100` | Per-day spending ceiling in US dollars on the PAID AI generation that turns raw meeting notes into enhanced notes (the Anthropic/OpenAI completion). A generous runaway backstop, not a usage limiter: once cumulative enhance spend for the day reaches this amount, a cache-miss or a forced regenerate is refused with a friendly message until tomorrow. Default 5.00; range 0 to 100. Set it to 0 to disable paid note enhancement entirely. Twin of meetingsTranscribeDailyCapUSD (the live meeting-transcription spend cap). Synonyms: meetings enhance daily cap, enhanced notes budget, AI meeting notes spend limit, cap meeting note generation cost. |
| `meetingsJargonTerms` | text | `string` |  |
| `meetingsMutedDetectApps` | list | `array of string` |  |
| `meetingsMyRecipeIds` | list | `array of string` |  |
| `meetingsMyTemplateIds` | list | `array of string` |  |
| `meetingsRecentRecipeIds` | list | `array of string` |  |
| `meetingsTranscribeDailyCapUSD` | number | `number 0..1000` |  |
| `memoryDistillerDailyCapUsd` | number | `number 0..1000` | Global Memory — the daily US-dollar cap on the session-end memory distiller LLM spend (0 = disabled). Default 1. The distiller runs automatically at session end and calls a lightweight AI model (Haiku) to extract durable memories; this cap bounds the total charged per day per account so background distillation never drains your budget. Set it to 0 to disable the cap entirely, or raise it if you run many long sessions and want more memories extracted per day. Synonyms: memory distiller cap, memory distiller budget, daily memory spend, global memory cost cap. |
| `memoryDistillerModel` | select | `"haiku" \| "sonnet" \| "opus" \| "deepseek-v4-flash" \| "luna" \| "off"` | The model the Global Memory session-end distiller uses to extract memories from a finished session — for A/B-testing summarization quality across models. Haiku (the default), Sonnet, Opus, DeepSeek V4 Flash, or GPT-5.6 Luna. Agent/CLI-only (set it over the CLI); there is no UI toggle. Synonyms: memory distiller model, memory summarizer model, which model writes memories, global memory model. |
| `memoryReclaimAdvancedEnabled` | toggle | `true \| false` | In-development: on deep free-RAM pressure, run a Windows-only system-wide reclaim (empty all working sets + purge the standby list) via a one-time admin-approved helper. May briefly reduce performance. Hidden until shipped. |
| `memoryReclaimAdvancedFreePercent` | number | `integer 1..90` | Free physical RAM %, at/below which Tier-2 system-wide reclaim fires. Range 1-90. Default 25 (~16 GB free on a 64 GB box). |
| `messageInboundApprovedSenders` | map | `map of string → array of string (≤200)` |  |
| `messageVirtualizationEnabled` | toggle | `true \| false` |  |
| `messageVirtualizationThreshold` | number | `integer 50..1000` |  |
| `metaSttEnabled` | toggle | `true \| false` | Transcribe your voice with Meta's Muse Voice Transcribe. On by default — the voice settings gain a "Meta Muse Voice Transcribe" speech option. It needs its own Meta Model API key and bills to that key; turn this off to hide the option. |
| `meteredVendorSpendAlertUSD` | number | `number 0..10000` | The ALERT MINIMUM, in US dollars, for those same metered vendors: the daily spend at which Omniscio starts raising the 'spend today is unusually high' inbox card for one of them, with a runaway card at 4x this. It NOTIFIES only — it never blocks a session, which is what the per-provider daily cap above does, and the two are independent. Default $25. Raise it if your own ordinary day on a vendor is already above that, or the card will keep reporting a normal day as an anomaly; lower it to hear about smaller spikes. Leave empty for the default. Synonyms: alert threshold, spend alert minimum, when to warn me about spend, metered vendor alert level, kimi alert threshold, deepseek alert threshold, stop alerting me on normal days. |
| `mindmapAiCostCapUsd` | number | `number 0.5..50` | Daily USD spend cap on Mind Map AI calls (expand node / generate map) for your account (default $1; range $0.50-$50). Once the day's spend on these AI features hits this cap, further AI mind-map actions are refused until it resets. No Settings-UI control yet; set via CLI/PATCH. Synonyms: mindmap ai cost cap, mind map spend limit, mindmap ai budget. |
| `mindmapColorMode` | unknown | `any` | The default light/dark/system theme for a Mind Map that has no per-map color-mode override of its own (default 'system' — follows your OS/app theme). Each map's own toolbar color-mode choice overrides this. No Settings-UI control yet; set via CLI/PATCH. Synonyms: mindmap color mode, mindmap dark mode default, mind map theme default. |
| `mindmapDottedBackground` | toggle | `true \| false` | Whether a Mind Map shows a dotted background grid behind its nodes (default off). Toggled from the show/hide dotted-background button in the Mind Map toolbar. Synonyms: mindmap dotted background, mind map grid, dots on mindmap canvas. |
| `mindmapEnabled` | toggle | `true \| false` | In-development: a standalone mind-mapping canvas — build a tree of ideas with the keyboard and mouse, auto-layout, save to a library, and export to JSON or PNG. |
| `mindmapFullScreen` | toggle | `true \| false` | Whether a Mind Map opens in its full-screen overlay layout instead of docked beside the chat (default off — docked). Toggled from the full-screen header button on an open Mind Map; remembered for next time you open one. Synonyms: mindmap full screen, mind map overlay mode, expand mindmap. |
| `mindmapSessionSplit` | toggle | `true \| false` | Whether an open Mind Map shows split-view beside its chat session (default on) or the map alone with chat hidden. Toggled from the split-view button above the Mind Map sidebar tabs; desktop only. Synonyms: mindmap split view, show map and chat together, hide the map chat only. |
| `mindmapSplitWidth` | number | `number 200..4000` | The pixel width of the Mind Map split-view panel, remembered from the last time you dragged its divider (default 460; range 200-4000). A remembered layout size, not a toggle you set directly — drag the mind-map/chat divider to change it. Synonyms: mindmap split width, mind map panel width. |
| `mindmapVisualTheme` | unknown | `any` | The default visual theme (node/edge color scheme) for a Mind Map that has no per-map theme override of its own (default 'app' — follows the app's own theme). Each map's own Palette menu choice overrides this per map. No Settings-UI control yet; set via CLI/PATCH. Synonyms: mindmap visual theme, mind map color scheme default, mindmap palette default. |
| `missionsSidebarEnabled` | toggle | `true \| false` | When on (the default), the sidebar shows the Missions row. Turn it off to hide just that row. This is the row's own visibility gate, separate from the Missions feature itself — hiding the row does not stop anything running. Synonyms: missions sidebar row, show missions in sidebar, hide the missions row, sidebar missions toggle, missions visibility. |
| `mobbinMcpEnabled` | toggle | `true \| false` |  |
| `mobileCreateOnSendEnabled` | toggle | `true \| false` |  |
| `mobileDiffReviewEnabled` | toggle | `true \| false` | In-development: a touch-native version of the Review-Changes surface, so you can read what a session changed and act on it from your phone. Lists the changed files, renders each file's diff as tappable chunks, and lets you accept or reject a single chunk or a whole file, then commit. The desktop reviewer is built on VSCode's editor engine, which is unusable by touch — this is a separate, lightweight renderer over the same data. Off by default. Keep the toggle after it ships: this is the one surface that reaches destructive git commands from a paired phone, so turning it off is also how you close that door. |
| `mobileHeaderLabEnabled` | toggle | `true \| false` | In development: pick the mobile header style (frosted glass, seamless, solid, gradient, floating card, or hairline) and a compact row density, from Settings → Appearance on a phone. |
| `mobileMicDiagnosticEnabled` | toggle | `true \| false` | In-development: a mobile diagnostic that plays a tone while the mic is open and measures whether the mic stays active, how much it hears the tone itself (self-trigger), and whether it hears your voice — $0, pure client-side. Hidden until shipped. |
| `mobilePortraitLockEnabled` | toggle | `true \| false` |  |
| `mobileSessionNavArrowsEnabled` | toggle | `true \| false` |  |
| `mobileShareTargetEnabled` | toggle | `true \| false` | In-development: on your phone, share a screenshot into Omniscio (Android share sheet) or paste it (iPhone), then pick which session it attaches to. Off by default; dev builds only. |
| `mobileSoundEnabled` | toggle | `true \| false` |  |
| `mobileUrgentPanelMountEnabled` | toggle | `true \| false` |  |
| `modelDefaultThinkingLevels` | map | `map of string → "auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `modelProxyUrl` | text | `string (≤500)` |  |
| `modelVendorOverrides` | map | `map of string → any` | RETIRED — ignored, and removed in a later release. It used to pin which company serves a model that more than one company offers (GLM, DeepSeek, Kimi, MiniMax). Which company serves a model, and who pays for it, is now decided by that model family's Who pays & who serves list (Settings → Accounts → Who pays & who serves): to use a company, put its row where you want it tried. This value was read only once, to build those lists the first time, and is kept for one release so a revert loses nothing. Changing it does nothing. Synonyms: model vendor, serving provider, auto vendor, cheapest vendor, provider pin, vendor override, preferred vendor, model routing, which provider serves this model. |
| `modsPlatformEnabled` | toggle | `true \| false` | In-development: community-style layout mods that reshape core surfaces (v1: the sidebar Compact Rail). |
| `modsSafeMode` | toggle | `true \| false` | Safe Mode for layout mods. When on, all layout mods are disabled and every surface falls back to its standard built-in layout no matter what is selected — the recovery kill-switch to use if a mod causes any issue. Synonyms: mods safe mode, disable mods, standard layouts, restore default layout. |
| `mondayCloudEnabled` | toggle | `true \| false` | Adds a "Monday.com" sidebar tab to view and work your real Monday.com boards — groups, items, column values, updates — without leaving Omniscio. Connect with your personal API token in Settings. |
| `mondayCloudInboxEnabled` | toggle | `true \| false` |  |
| `moreRepliesBelowIndicatorEnabled` | toggle | `true \| false` |  |
| `motionPolishEnabled` | toggle | `true \| false` |  |
| `multiModelCouncilEnabled` | toggle | `true \| false` | Ask one question to a panel of AI models; a judge model synthesizes a single best answer. |
| `multiplayerSessionsEnabled` | toggle | `true \| false` | In-development: invite a teammate into a live session so they can follow the whole conversation in their own Omniscio, reply into it under their own name, and be @mentioned. You choose view-only or can-reply per person and can revoke at any time. Sharing copies that one conversation to your cloud for the people you invite; revoking deletes it. Only the session owner needs a paid plan. Off by default and completely inert until switched on. |
| `multiplayerShareUploadNoticeAcknowledged` | toggle | `true \| false` |  |
| `myAutomationsSidebarEnabled` | toggle | `true \| false` |  |
| `narrationDailyCapUSD` | number | `number 0..100` |  |
| `narrationEnabled` | toggle | `true \| false` | In-development: a spoken-audio recap of each completed reply — the audio sibling of Plain Speak. When on, the agent writes a short spoken script that plays back per message (optionally auto-playing new replies). Hidden until shipped. |
| `narrationPlaybackRate` | number | `number 0.5..2` |  |
| `narrationVoiceReplyEnabled` | toggle | `true \| false` | In-development: after the AI reads its spoken recap, a mic button on the message opens a window where you talk, see your words transcribed, and send them back to the session as your reply. Reuses the built-in voice input; requires Voice Input on. Hidden until shipped. |
| `nativeBrowserEnabled` | toggle | `true \| false` | Retired: the "native browser" launched a SEPARATE managed copy of Chrome over a secure CDP pipe — its own blank profile, not your everyday logged-in Chrome. Disabled + hidden in favor of the Real Chrome Bridge (which drives your actual Chrome); its code is kept. Retired means hard-disabled: it is dropped from Settings → Lab, so the toggle cannot bring it back — re-reveal it for testing by launching with AMC_SHOW_NATIVE_BROWSER=1. |
| `nativeSlashCommandsEnabled` | toggle | `true \| false` | Type slash commands like /model, /clear, /cost, /context and /status in the chat composer and have them run for real in Claude Code — switching the model live, clearing context, or showing real cost/usage — instead of being sent to the model as text. |
| `newModelWatcherEnabled` | toggle | `true \| false` |  |
| `newSessionSpawnPacingEnabled` | toggle | `true \| false` | Paces the rate at which brand-new sessions are spawned, so a burst of starts cannot storm the machine. Off by default, and arming it is deliberately governed — one pacing lever is turned on at a time, each behind a crash matrix, a latency benchmark and a soak, never as a side effect of unrelated work. Synonyms: new session spawn pacing, pace session starts, don't spawn a storm, throttle new sessions, spawn pacer. |
| `newSettingsLayoutEnabled` | toggle | `true \| false` | Reorganizes Settings into clearer, better-named "rooms" without changing any individual setting. |
| `nightShiftAutoMonitoringEnabled` | toggle | `true \| false` | Night Shift — when on (the default), while a Night Shift plan runs Omniscio keeps the sessions the plan ITSELF spawned moving overnight (auto-continue, auto-nudge, and the session health monitor), scoped to those sessions only. Your unrelated and already-finished sessions are never auto-continued, nudged, or health-checked just because a plan is running, and your own global monitoring switches are left exactly as you set them. Off: Night Shift will not drive even its own sessions. Synonyms: night shift monitoring, auto-enable monitoring during plans, proactive monitoring while a plan runs, auto nudge and continue during a night shift plan, scoped session monitoring. |
| `nightShiftUiEnabled` | toggle | `true \| false` | In-development: a multi-phase overnight automation runner. Define a plan of steps (spawn sessions, run recipes, wait, branch) and let it execute while you sleep. |
| `nightyTidyAutoRestartOnCrash` | toggle | `true \| false` | Startup crash-recovery for Nighty Tidy 2 scheduled audits: when the app restarts after a crash, a run that was left stranded in "running" (its audit never finished) is re-queued and re-dispatched automatically instead of being marked failed. Default true (on). Set to false to reap a stranded run as failed on restart instead of re-running it. Synonyms: nighty tidy auto restart, restart crashed audits, requeue orphaned runs, resume interrupted audits. |
| `nightyTidyConcurrencyCap` | number | `integer 1..50` |  |
| `nightyTidyCostCapUsd` | number | `number 0..1000` |  |
| `nightyTidyFindingsRetentionDays` | number | `integer 0..3650` |  |
| `nightyTidyNightlyAuditCountLimit` | number | `integer 0..500` |  |
| `nothariAgentToolsEnabled` | toggle | `true \| false` |  |
| `nothariAgentWriteToolsEnabled` | toggle | `true \| false` |  |
| `nothariAggregationCostCapMicroUsd` | number | `integer 10000..10000000` | KMS — the cost cap for one knowledge-aggregation (digest) run, denominated in MICRO-DOLLARS, i.e. millionths of a US dollar. WATCH THE UNIT: 1 USD = 1,000,000 micro-USD, so the default 100000 is $0.10, and the allowed range 10000-10000000 is $0.01 to $10.00. This is the ONE KMS cap in micro-dollars; nothariSummaryCostCapUsd, nothariBulkSeedCostCapUsd and nothariImageAnalysisCostCapUsd next to it are in plain dollars, so copying a value between them is a 1,000,000x mistake. Synonyms: kms aggregation cost cap, digest cost cap, aggregation budget micro usd, knowledge digest spend limit. |
| `nothariAggregationDaily` | toggle | `true \| false` |  |
| `nothariAggregationDailyHour` | number | `integer 0..23` |  |
| `nothariAggregationDeepDiveMax` | number | `integer 1..50` |  |
| `nothariAggregationEnabled` | toggle | `true \| false` |  |
| `nothariAggregationSections` | object | `object { activity: true \| false; bugs: true \| false; decisions: true \| false; lessons: true \| false; openQuestions: true \| false; patterns: true \| false; vaultActivity: true \| false }` |  |
| `nothariAggregationTimeZone` | text | `string` | The IANA time zone the Knowledge (KMS) daily/weekly aggregation digest hours + weekly day are resolved against. Captured automatically on the first run (your current host zone) so the off-peak digest keeps firing at the intended wall-clock after an OS time-zone change. Null until captured. Synonyms: KMS digest time zone, aggregation fire zone. |
| `nothariAggregationWeekly` | toggle | `true \| false` |  |
| `nothariAggregationWeeklyDay` | number | `integer 0..6` |  |
| `nothariAggregationWeeklyHour` | number | `integer 0..23` |  |
| `nothariAutoRegenEnabled` | toggle | `true \| false` |  |
| `nothariAutoRegenIntervalMs` | number | `number 60000..86400000` |  |
| `nothariAutoRegenPerNoteCooldownMs` | number | `number 60000..86400000` |  |
| `nothariBulkSeedCostCapUsd` | number | `number 1..50` | KMS — the PER-RUN cap, in plain US DOLLARS, for the bulk-seed worker (the one-off pass that generates summaries across a whole vault). Default $5, range $1-$50. It OVERRIDES the per-day summary cap for the duration of that single run, so a deliberate bulk seed is not blocked by the daily ceiling. In dollars, unlike nothariAggregationCostCapMicroUsd. Synonyms: kms bulk seed cap, seed the whole vault budget, bulk summary run cost, one-off vault seeding limit. |
| `nothariChecklistStrikethrough` | toggle | `true \| false` |  |
| `nothariColorMode` | select | `"system" \| "light" \| "dark"` |  |
| `nothariEditorBackground` | select | `"theme" \| "paper" \| "sepia"` |  |
| `nothariEditorFont` | select | `"sans" \| "serif" \| "mono"` |  |
| `nothariEditorFontSize` | select | `"sm" \| "md" \| "lg" \| "xl"` |  |
| `nothariEditorShortcuts` | map | `map of string → string (≤100) \| array of string (≤100)` |  |
| `nothariEditorWidth` | select | `"narrow" \| "normal" \| "wide" \| "full"` |  |
| `nothariEnabled` | toggle | `true \| false` |  |
| `nothariFileWatcherEnabled` | toggle | `true \| false` |  |
| `nothariImageAnalysisCostCapUsd` | number | `number 0.5..20` | KMS — the cap, in plain US DOLLARS, on manually-triggered AI image analysis of vault images. Default $2, range $0.50-$20. Enforced as the bulk handler's pre-spawn check, so a run can overshoot by at most one image's billed cost (about $0.05). In dollars, unlike nothariAggregationCostCapMicroUsd. Synonyms: kms image analysis cap, analyze images budget, vault image ai cost limit. |
| `nothariImageAnalysisModel` | text | `string (≤120)` |  |
| `nothariQuickReferenceCompleted` | toggle | `true \| false` |  |
| `nothariRecentCommands` | list | `array of string (≤100)` |  |
| `nothariRightPaneOpen` | toggle | `true \| false` |  |
| `nothariRightPanePanels` | map | `map of string → object { collapsed: true \| false; order: integer 0..100 }` |  |
| `nothariShortcuts` | map | `map of string → string (≤100) \| array of string (≤100)` |  |
| `nothariSidebarPosition` | select | `"left" \| "right"` |  |
| `nothariStarterContentSeeded` | toggle | `true \| false` |  |
| `nothariSummaryCostCapUsd` | number | `number 0.5..50` | KMS — the PER-ACCOUNT DAILY cap, in plain US DOLLARS, on AI summary generation for vault notes. Default $2, range $0.50-$50. Checked pre-flight before a summary is generated. In dollars, unlike nothariAggregationCostCapMicroUsd next to it, which is in micro-dollars. Synonyms: kms summary cost cap, note summary daily budget, vault summary spend limit, kms ai summary cap. |
| `nothariTabsPreviewMode` | toggle | `true \| false` |  |
| `nothariVaultRootPath` | text | `string (≤500)` |  |
| `nothariVisualTheme` | unknown | `"app" \| "glassmorphism" \| "linear" \| "warm-charcoal" \| "aurora" \| "soft-depth" \| "neon" \| "spotify" \| "luxury" \| "gradient-sidebar" \| "neumorphic" \| "frosted-tiers" \| "vercel" \| "liquid-glass" \| any` |  |
| `notificationHistorySidebarEnabled` | toggle | `true \| false` | When on (the default), the sidebar shows the Notification History row — the read-only list of notifications you have already been sent. Turn it off to hide just that row. It sits beside the Notification History feature switch, which is the one that turns the history itself off; this one only controls the sidebar row. Synonyms: notification history sidebar row, show notification history, hide the notification history row, past notifications in sidebar, notification log row. |
| `notificationSoundEnabled` | toggle | `true \| false` |  |
| `notificationSoundError` | text | `string (≤200)` |  |
| `notificationSoundNeedsYou` | text | `string (≤200)` |  |
| `notificationSoundStalled` | text | `string (≤200)` |  |
| `notificationSoundVolume` | number | `number 0..1` |  |
| `notionBoardEnabled` | toggle | `true \| false` | Adds a "Notion" sidebar tab to view and work your Notion databases — status/select columns, page detail, properties, page body — without leaving Omniscio. Connect with a Notion internal integration token in Settings. In development. |
| `objectDbMaintenanceEnabled` | toggle | `true \| false` | When on, a quiet-window background job keeps each of your git projects' SHARED object database (the git-common-dir every worktree points at) fast by writing and refreshing its commit-graph (git maintenance run --task=commit-graph), so concurrent git operations across many worktrees (log, merge-base, history traversal) stay quick instead of slowing down as the loose object store grows. It runs ONLY when your computer is in a quiet window (it skips while the CPU is busy or still settling), runs demoted at low priority, is time-bounded and killed the instant the box gets busy, does at most one project per tick, and fails open (any problem simply means no maintenance ran, exactly like today). It deliberately does NOT repack loose objects — that stays the separate git object-store maintenance service's job — and never runs an aggressive full git gc/repack. Off by default (opt-in). Env kill switch AMC_DISABLE_OBJECTDB_MAINTENANCE=1. Synonyms: git maintenance, commit graph, git object database compaction, keep git fast across worktrees, git housekeeping, quiet-window maintenance. |
| `objectDbMaintenanceUserHarmGateEnabled` | toggle | `true \| false` |  |
| `ollertEnabled` | toggle | `true \| false` |  |
| `onboardingCadenceEnabled` | toggle | `true \| false` | In-development: the video-led onboarding cadence that replaces the mission trickle. After setup, drips short intro VIDEOS to a new user one inbox card at a time — the next releases when the current is archived or after a timeout, and only while the user is active. ON by default (2026-08-28 launch — the welcome-tour card #1 is seeded); the toggle stays live to turn off with one setting flip. |
| `onboardingChecklistCompleted` | list | `array of string (≤100)` |  |
| `onboardingCompleted` | toggle | `true \| false` |  |
| `onboardingDemoTourOverride` | unknown | `unknown` |  |
| `onboardingGuardianEnabled` | toggle | `true \| false` | An invisible AI that quietly watches the Setup v2 flow and the interactive tour and offers a gentle hint ONLY when you appear stuck, occasionally acting to help (highlight a control, open a panel). It otherwise stays completely out of the way. On by default; you can turn it off anytime. |
| `onboardingJourneyCompleted` | toggle | `true \| false` |  |
| `onboardingJourneyStarted` | toggle | `true \| false` |  |
| `onboardingLearnDoneAt` | text | `string` |  |
| `onboardingLearningWindowEnabled` | toggle | `true \| false` | When a new user finishes Setup v2, opens the hosted "learn the app" page in a window; the guided suggestion cards then arrive once they finish it. On by default; the toggle stays live to turn off with one setting flip. |
| `onboardingMissionTrickleEnabled` | toggle | `true \| false` | In-development: the guided-mission suggestion cards. RETIRED from new users (owner 2026-08-26) — off by default, being replaced by the video-led onboarding cadence. The toggle stays live to turn the old mission cards back on with one setting flip. |
| `onboardingOfferAccountSignIn` | toggle | `true \| false` | Show the "sign in with your account" option on first run. Off by default (owner decision 2026-08-18: new users run on their own key or a managed pool, with no account required); flip it ON to bring the account-based sign-in option back into the first-run flow. Synonyms: offer account sign in, show account option on first run, sign in with account, account onboarding. |
| `onboardingPrespawnEnabled` | toggle | `true \| false` | When a new user finishes Setup v2, pre-spawns the guided missions in the background on a company-paid DeepSeek route so they return to agents already working. Fail-closed (needs the funded company DeepSeek lane + sign-in), one-time per user, capped. ON by default (2026-08-25 — the company deepseek-v4-flash lane now serves end-to-end, verified live: the failover chain is 6/6 healthy and a real deepseek-v4-flash completion returns clean output, so the earlier "model unavailable" gateway failure is fixed). The toggle stays live to turn off with one setting flip; the mission trickle remains the fallback. |
| `onboardingPrespawnStartedAt` | text | `string` |  |
| `onboardingReplyNudgeDismissed` | toggle | `true \| false` |  |
| `onboardingSetupAssistantCardEnabled` | toggle | `true \| false` | In-development: after a new user finishes onboarding, shows a one-time, optional inbox card offering a guided setup assistant. Launching it opens an Ask Omniscio session that walks them through connecting an AI provider, adding API keys, integrations, automations, agent autonomy, and backups; it never sees a raw API key. Off by default; hidden until shipped. |
| `onboardingStudioFlow` | unknown | `unknown` |  |
| `onboardingTourEnabled` | toggle | `true \| false` | A scripted, spotlighted product tour that runs after onboarding — it walks you through sessions, the inbox, replying, reading, and starting new work on a demo workspace. Off by default: superseded by the hosted "learn the app" window (onboarding-learning-window); the toggle stays live to turn it back on with one setting flip. |
| `onboardingWelcomeNoteEnabled` | toggle | `true \| false` | When a new user finishes onboarding, seeds one durable "note from the Omniscio founding team" into their inbox, once per user. Informational only — nothing auto-starts. On by default; the toggle stays live to turn off with one setting flip. |
| `openrouterPresetModels` | list | `array of string (≤100)` | The model list shown in the OpenRouter provider preset's picker — the "good coding models" shortlist, not every model OpenRouter carries. Normally maintained for you: OpenRouter is an aggregator with hundreds of models and several added a week, so a background watcher refreshes this from its live catalog. Empty means "not derived yet" and the built-in shipped snapshot is used instead, so a failed refresh can never leave you with an empty picker. Edit it yourself in Settings → Custom Providers (which also sets openrouterPresetModelsCustomized). Synonyms: openrouter model list, which openrouter models show up, openrouter picker models, customize openrouter models, openrouter preset shortlist. |
| `openrouterPresetModelsCustomized` | toggle | `true \| false` | Set to true once you edit the OpenRouter model list yourself. While it is true the automatic catalog refresh stops writing that list, so a nightly poll can never overwrite a choice you made deliberately. Clear it to hand the list back to automatic refresh. Set for you when you edit the list in Settings → Custom Providers — you rarely set this directly. Synonyms: openrouter list is customized, stop auto-updating my openrouter models, lock the openrouter model list, openrouter manual model list, reset openrouter models to automatic. |
| `optInToggleMigrationDone` | toggle | `true \| false` |  |
| `orphanReaperWmiStormHoldEnabled` | toggle | `true \| false` | When on (the default), the orphaned-process reaper holds back its WMI command-line fallback — a full-machine process walk that would add CPU load — while the machine is in a kernel-bound storm. The reaper keeps sweeping; it just stops reaching for the expensive fallback until the storm passes, so a box that is already struggling is not made worse by the reaper itself. Turn it off to always allow the fallback. Synonyms: orphan reaper wmi storm hold, pause the wmi fallback while busy, reaper hold during a storm, kernel storm hold, wmi walk hold. |
| `orphanToolTreeReaperEnforce` | toggle | `true \| false` | Whether the reaper for orphaned tool-call process trees actually KILLS the processes it finds, or only writes down what it would have killed. Off by default — it ships in shadow mode, so you can read its findings before letting it act. Master kill: AMC_DISABLE_ORPHAN_TOOL_TREE_REAP=1. Synonyms: orphan tool tree reaper enforce, kill orphaned processes, shadow mode reaper, leftover tool processes, stray child processes. |
| `orphanWorktreeArchiveEnabled` | toggle | `true \| false` | When on (the default), a worktree whose session has been gone for 24 hours is ARCHIVED rather than left to fill your disk: the folder is reclaimed while the branch and every change on it are kept, and the archive is reversible on demand. This is the third outcome between "keep the folder forever" and "delete the branch". Kill switch AMC_DISABLE_ORPHAN_WORKTREE_ARCHIVE. Synonyms: orphaned worktree archive, reclaim old worktrees, automatic worktree archive, 24 hour worktree cleanup, free up disk from worktrees, keep the branch drop the folder. |
| `orphanWorktreeArchiveReportedAt` | text | `string` | ISO timestamp the orphan-archive sweep stamps after its ONE report-only cycle — the run that raises the card and the list without removing anything. Null means that cycle has not happened yet and the next tick is a dry run. Persisted rather than held in memory so it happens once ever, not once per app restart. Job-written bookkeeping, deliberately SEPARATE from the user-owned on/off above so the sweep never writes the field the user controls. |
| `outboundWebhooksLabVisible` | toggle | `true \| false` | In-development: deliver curated internal events (agent status, budget alerts, recipe/job completion, inbox alerts) to your own callback URLs. Subscribe by event type, with per-webhook delivery history and a test ping. Off by default. |
| `overlayFeedbackEnabled` | toggle | `true \| false` |  |
| `overseerAutoPerProject` | toggle | `true \| false` | When on, EVERY project automatically gets its own Overseer watching it, instead of opting each project in one at a time. Off by default, because each one is a real running session that costs money. You can still switch an individual project off while this is on — an explicit per-project choice always wins. Synonyms: overseer for every project, always have an overseer, auto per-project overseer, one overseer per project, automatic overseers. |
| `overseerDailyBudgetUsd` | number | `number 1..100000` | A hard ceiling, in US dollars, on what the Overseer and the swarm it runs may spend in one day across both estates. Reaching it pauses further spend rather than slowing it. Deliberately separate from overseerSpendBreakerMultiplier, which is a ratio-based anomaly detector calibrated on an Overseer working alone — this is the shared dollar ceiling, and the two must not be conflated. Accepts 1 to 100000. Synonyms: overseer daily budget, overseer spend cap, how much can the overseer spend per day, swarm cost ceiling, daily dollar limit for the overseer. |
| `overseerEnabled` | toggle | `true \| false` | An always-on assistant that guides your agents, watches for patterns, and screens your inbox. |
| `overseerFleetBoardChannelId` | text | `string` | The Team Chat channel id the Overseer posts its fleet-board updates to and reads from each heartbeat round. Empty (the default) means the fleet board is off. An opaque destination id you already picked, not a credential. No Settings-UI control yet; set via CLI/PATCH. Synonyms: overseer fleet board channel, overseer team chat channel. |
| `overseerFleetBoardWorkspaceId` | text | `string` | The Team Chat workspace id paired with overseerFleetBoardChannelId for the Overseer's fleet-board posts. Empty (the default) lets the relay resolve its own workspace. Has no effect unless overseerFleetBoardChannelId is also set. No Settings-UI control yet; set via CLI/PATCH. Synonyms: overseer fleet board workspace. |
| `overseerGatekeeperEnabled` | toggle | `true \| false` | When on (the default), the Overseer holds new inbox items for the hold window (overseerHoldWindowMinutes) before routing them, screening for noise and spam. Turn it off to let items through immediately without the screening delay. Synonyms: overseer gatekeeper, inbox hold, inbox screening, hold new items, noise filter. |
| `overseerHandoffEnabled` | toggle | `true \| false` | When on (the default), a session an Overseer OWNS hands its finished turn to that Overseer instead of raising it in your inbox — the Overseer reads the report and only brings you what actually needs you. Turn it off to get every finished turn yourself, whoever owns the session. Deliberately separate from overseerGatekeeperEnabled: that one screens ALERT CARDS on their way to you, this one redirects an OWNED AGENT'S REPORT, and you may want one without the other. Only affects sessions an Overseer owns, which happens by explicit assignment or by that Overseer spawning them. Overseer panel → Behaviour. Synonyms: overseer handoff, let the overseer take my agents' reports, stop overseer sessions filling my inbox, route finished turns to the overseer, overseer answers for its sessions, turn off overseer handoff. |
| `overseerHeartbeatMinutes` | number | `integer 0..1440` | Minutes between each Overseer wake-up (default 15; range 0-1440). Every wake-up is a real paid turn — set this with that in mind. 0 turns cadence wake-ups off entirely. An individual Overseer can set its own pace in the Overseers list, overriding this fleet-wide default. Settings → Overseer → Behaviour → "How often they wake up". |
| `overseerHoldWindowMinutes` | number | `integer 1..120` | How many minutes the Overseer holds a new inbox item before routing it through the gatekeeper screening step (only meaningful when overseerGatekeeperEnabled is on). Range 1–120 minutes; default 10. Synonyms: overseer hold window, gatekeeper delay, inbox hold time, screening window, how long to hold new items. |
| `overseerProjectOverrides` | map | `map of string → true \| false` | Per-project override for whether an Overseer runs on that project, keyed by project id (true/false forces it on/off for that one project). A project with no entry here follows the blanket overseerAutoPerProject setting instead. Set via the "Run this Overseer" toggle on each project's Overseer row. Synonyms: per-project overseer, overseer on or off per project. |
| `overseerRestartHours` | number | `integer 1..168` | How many hours between automatic Overseer session restarts. The Overseer periodically restarts to stay fresh and pick up any new instructions. Range 1–168 hours (up to 1 week); default 24. Synonyms: overseer restart interval, how often the overseer restarts, overseer session lifetime, restart every N hours. |
| `overseerSelfCloneLimit` | number | `integer 1..50` | An optional cap on how many standing peer Overseers an Overseer may create on its own authority — the self-clone path that otherwise writes the slot without raising an approval card. It bounds the WHOLE fleet, not one slot: one number covers every Overseer on the box. Blank (the default) means NO LIMIT, which is how this ships — an Overseer may mint a standing peer by itself, and you only set a number if you want to cap it. The count is of the self-cloned peers that still EXIST, so deleting one frees a slot back up. Accepts 1 to 50. Independent of the built-in burst guard, which refuses more than a few self-clones in one hour whatever you set here. Set from Settings → Overseer (the fleet-level settings for every Overseer at once). Synonyms: how many overseers can an overseer make, cap self-cloned overseers, limit overseer copies, overseer self-clone limit, maximum standing peers, stop the overseer making more copies of itself. |
| `overseerSessionAssignments` | map | `map of string → string` | Which Overseer slot is explicitly watching each session, keyed by session id and valued by the assigned Overseer slot id. An explicit assignment here outranks the project-level rule for routing that session; a session with no entry falls back to its project's Overseer. Set via the "Sessions it watches" picker on an Overseer's row, or by CLI/API. Synonyms: overseer session assignment, which overseer watches this session. |
| `overseerSlotOrder` | list | `array of string (≤128)` |  |
| `overseerSlots` | map | `map of string → object { allowedAgentTypes: array of "builder" \| "reviewer" \| "fixer" \| "researcher" \| "tester" \| "janitor" \| "planner" \| "auditor" \| "first-principles" \| "pattern-finder" \| "red-teamer" \| "triager" \| "tool-builder" \| "documenter" \| "optimizer"; approvedAt: string; autoActions: array of object { agentType: "builder" \| "reviewer" \| "fixer" \| "researcher" \| "tester" \| "janitor" \| "planner" \| "auditor" \| "first-principles" \| "pattern-finder" \| "red-teamer" \| "triager" \| "tool-builder" \| "documenter" \| "optimizer"; approvedAt: string; id: string (≤64); job: string (≤4000); maxPerHour: integer 1..60; trigger: discriminatedunion }; autoTitle: string (≤80); enabled: true \| false; heartbeatMinutes: integer 0..1440; instructions: string (≤10000); interruptBudgetPerHour: integer 0..100; name: string (≤80); purpose: string (≤2000) }` | The name and instructions for each individual Overseer — the global one, each project one, and any you create yourself. Leave the instructions empty and that Overseer runs the built-in stock job description, so turning one on never requires writing a prompt first. For a custom Overseer, creating its entry here is what brings it into existence; you can pause one without losing what you wrote for it. Synonyms: overseer prompt, overseer instructions, custom overseer, name an overseer, multiple overseers, per-overseer prompt, what my overseer does. |
| `overseerSpendBreakerMultiplier` | number | `integer 2..50` | Multiplier on the user's average session spend that triggers the Overseer's spend breaker: if a session's cost exceeds this multiple of the average, the Overseer pauses further activity until you review it. Range 2–50; default 4 (four times the average). Synonyms: overseer spend breaker, cost multiplier, spend safety, runaway cost protection, pause if spend exceeds N times average. |
| `overseerSweepIntervalMinutes` | number | `integer 1..120` | How often (in minutes) the Overseer sweeps for new patterns and outstanding items. A shorter interval means faster pattern detection at the cost of more background activity; a longer interval is quieter. Range 1–120 minutes; default 10. Synonyms: overseer sweep interval, scan frequency, how often the overseer checks, pattern sweep cadence. |
| `ownerAssignmentsEnabled` | toggle | `true \| false` | In-development: route an incoming bug to a designated owner so it lands on the right person instead of a shared queue. Hidden until shipped. |
| `ownerWelcomeNoteSeedAt` | text | `string` |  |
| `pangasinanPilotEnabled` | toggle | `true \| false` | Adds Pangasinan (Pangasinense) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `peerCoordinatorSessionIds` | list | `array of string (≤200)` | Session ids designated as fleet COORDINATORS. A cross-session message whose TARGET is one of these runs in the separate, larger `coordinator` rate-limit lane instead of the standard one — the N-workers-to-1-coordinator fan-in that legitimately needs more than a single worker's routine budget while staying bounded (see peer-message-rate-limiter.ts). The lane is SEPARATE, not merely larger: routine chatter draws on the standard bucket, so a worker that has spent its routine budget can STILL report an incident to the coordinator. That is the whole point — on 2026-08-29 workers were 429'd while trying to report infra failures to the monitor, during exactly the incident the channel exists to surface. A FAIRNESS input only, never an authorization input (session-provenance I7): being listed grants a larger send allowance to sessions messaging it, and nothing else. Operator-granted. Like `allowAgentTokenTeamChat` this is NOT in SETTINGS_PATCH_BLOCKED, because the scoped agent-session token cannot reach `PATCH /settings/:key` at all (the dispatcher refuses it — the key is absent from AGENT_SESSION_MUTATION_ROUTE_ALLOWLIST and the route declares no `allowAgentSession`), and a global-token PATCH queues for owner approval (`requireApprovalForCliSettings`, default ON). So no agent can self-designate. |
| `peopleMemoryEnabled` | toggle | `true \| false` | In-development: the Mirror's sibling — it reads the full email history of the people you actually write to and builds a running dossier on each one: a short read on who they are, how they are wired, how to work with them, and what is going on with them right now, plus a scannable list of key facts. It appears as a "What I know" panel next to each conversation in Supermail, and one tap forgets a person for good. Bots, newsletters and no-reply senders are never profiled, and someone you have barely written to gets nothing rather than a guess. The data stays on your machine, wipes on Gmail sign-out, and is cost-capped. Off by default; hidden until shipped. |
| `perProjectWorktreeLocationEnabled` | toggle | `true \| false` |  |
| `perfStatusEnabled` | toggle | `true \| false` | Whether anything is slowing this computer right now, and what the app is doing about it. Opens on a one-line plain-language verdict, then the readout it comes from — box counters, the app's main-thread stall share, the external-memory pool, fleet + process-birth rate, per-volume disk runway, cloud verdict share, the auto-lander pulse and where your agents' time goes — and finally every agent-load governor grouped by the plain-English mechanism it belongs to, with a switch on the ones where turning it off is a sane thing to do. Read from the app's own tapes in process; it starts no probes. Governor switches go through the ordinary settings path. |
| `perfStatusSidebarEnabled` | toggle | `true \| false` | Whether the Performance Status item appears in the sidebar (default on). It is a visibility toggle only — turning it off hides the entry, it does not disable performance monitoring or change anything the app measures. Settings → Sidebar. Synonyms: hide performance status from the sidebar, show perf status, sidebar performance item, remove the perf panel from the sidebar, performance sidebar visibility. |
| `permissionReadNudgeEnabled` | toggle | `true \| false` |  |
| `persianPilotEnabled` | toggle | `true \| false` | Adds Persian / Farsi (فارسی) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `personaDefaultsApplied` | toggle | `true \| false` | One-shot migration/backfill marker: whether your chosen user persona's defaults have already been applied to your settings. Written automatically the first time persona defaults are applied; remembered internal state, not a preference you configure. Synonyms: persona defaults applied flag, persona backfill done, persona initialization. |
| `phoneControlEnabled` | toggle | `true \| false` | In-development: gives agents a set of mobile_* tools to drive an Android device — tap, swipe, type, take screenshots, install apps, and more — via the @mobilenext/mobile-mcp MCP server. Requires adb (Android Debug Bridge) and the mobile-mcp runtime; both are auto-provisioned on first enable. Off by default; hidden until shipped. |
| `picovoiceWakeWordEnabled` | toggle | `true \| false` | Retired: the paid Picovoice wake-word engine. Its proprietary models are no longer bundled and it is hidden from the wake-word engine picker — the free built-in engine recognizes the same wake words. Retirement outranks this entry’s toggle, so switching it on cannot bring the engine back; only the AMC_SHOW_PICOVOICE_WAKE_WORD=1 developer setting re-reveals it, for testing. |
| `pinnedSessionCommandIds` | list | `array of string (≤64)` |  |
| `pinnedSheetIds` | list | `array of string (≤200)` |  |
| `pinnedSidebarHeaderItemIds` | list | `array of string (≤64)` | Which project-header actions (e.g. terminal, collapse, new session, search) show as bar icons versus being tucked into the ⋮ menu, by action id. Set by right-clicking a header icon and choosing "Pin to header" / "Move to ⋮ menu"; desktop only. |
| `pinnedToolbarItems` | list | `array of string (≤50)` |  |
| `pipelineAutoAdvanceEnabled` | toggle | `true \| false` |  |
| `pipelineAutoApprovePlanGate` | toggle | `true \| false` |  |
| `pipelineGateAutoApprove` | object | `object { build: true \| false; docs: true \| false; elegance: true \| false; plan: true \| false; redTeam: true \| false }` | Per-gate auto-approval for the dev-pipeline: one switch per gate (Plan, Red Team, Build, Elegance, Docs) saying whether Omniscio clears it itself the moment a phase reports done, or always waits for you. Plan asks you by default; the other four auto-clear by default. A gate that asks a real question or reports a blocker is never auto-approved whatever its switch says. Set it in Settings → Optional Features or the Dev Pipeline panel — both bind the same map. Synonyms: gate auto approval, auto approve gates, skip the gate click, which gates ask me, dev pipeline gates automatic. |
| `pipelineStandardsGateAutoApprove` | object | `object { standards-audit: true \| false; standards-check: true \| false }` | Per-gate auto-approval for the two bundled standards gates (the Standards Check and the Standards Audit), on the same footing as pipelineGateAutoApprove. Absent means automatic, resolved from the gate's own default, so a gate you have never touched behaves the way it always has. Synonyms: standards gate auto approve, standards check automatic, standards audit automatic, bundled standards gates. |
| `plainSpeakActionEmojisEnabled` | toggle | `true \| false` |  |
| `playwrightMcpEnabled` | toggle | `true \| false` |  |
| `pluginAiNativeCliEnabled` | toggle | `true \| false` | Lets the Omniscio AI and CLI invoke an installed plugin's own actions through its registered CLI endpoints (ctx.cli.handle), including nested multi-segment paths. No UI surface — it gates a control-server route. |
| `pluginBackendPermissions` | map | `map of string → true \| false` |  |
| `pluginConsents` | map | `map of string → object { consentedAt: string (≤40); permissions: array of string (≤100); version: string (≤50) }` |  |
| `pluginDocumentsIoEnabled` | toggle | `true \| false` | In-development: let an installed plugin open a normal "choose a file" window, read the file you pick, and add to the end of it — how a PDF viewer would save your notes back into your own PDF. It only ever gets the files you pick yourself, never a folder and never a location on your computer, and each pick is fixed at the time you make it as read-only or read-and-add. A plugin can also ask to REMEMBER a file you picked, so it can reopen that one file later without asking again — it has to ask your permission once before it may remember anything, you can see every remembered file and take any of them back under Settings → Plugins, and turning a plugin off forgets them all. On by default — every install, new or existing, has it on; turning it off darkens the whole capability in Main, so nothing can read or write your files. |
| `pluginSettings` | map | `map of string → map of string → unknown` |  |
| `pluginUiContributionsEnabled` | toggle | `true \| false` | Lets installed plugins add their own buttons to the header toolbar and session menus, and navigate the app to a session, hub, or view. Plugin chrome is desktop-only — the phone/WS bridge blocks plugin navigation and dispatch over the wire. |
| `pluginWidgetsEnabled` | toggle | `true \| false` | In-development: lets a plugin show a small live status widget in the app header — a number, a short label, and a status colour. Omniscio draws the widget from the plugin's data; the plugin never draws in the header itself. Off by default; hidden until shipped. |
| `pluginsGroupCollapsed` | toggle | `true \| false` |  |
| `pluginsGroupDisplayOrder` | number | `integer` |  |
| `pmAdvisorDailyLlmCap` | number | `integer 0..∞` | How many times per day the PM "quick question" advisor may escalate a template answer to a real LLM call (default 100). Once hit, no more comfort-tier escalations happen until the next day. No Settings-UI control yet; set via CLI/PATCH. |
| `pmAdvisorDailySpendCapUsd` | number | `number 0..∞` | Daily USD spend cap on the PM advisor's LLM calls (default $5). Once cumulative spend for the day hits this, further advisor LLM calls are refused until it resets. No Settings-UI control yet; set via CLI/PATCH. |
| `pmAgentTrustEnabled` | toggle | `true \| false` | Agent trust levels, approval gates, progressive trust, and enriched activity timeline for Mission Control boards. |
| `pmApprovalWorkflowsEnabled` | toggle | `true \| false` | Multi-step approval chains for board items — define serial steps with parallel approvers, three approval types (any-one, all-must-approve, majority), triggered by status column changes. |
| `pmAutomationCostWarnEnabled` | toggle | `true \| false` | Master switch for the PM automation cost guard — when on (default), a PM automation that crosses its daily cost threshold (pmAutomationCostWarnThreshold) logs a warning, is auto-paused for the rest of the day, and raises an alert. No Settings-UI control yet; set via CLI/PATCH. |
| `pmAutomationCostWarnThreshold` | number | `number 0.1..100` | Per-automation daily USD cost threshold for PM automations (default $1; range $0.10-$100). Crossing it, with pmAutomationCostWarnEnabled on, pauses that one automation for the rest of the day and raises an alert. No Settings-UI control yet; set via CLI/PATCH. |
| `pmAutomationsEnabled` | toggle | `true \| false` | Automation triggers on board item changes — when a status changes, an item is created, or a due date passes, run an action chain (notify, move item, set column value, or start a session). On by default; turn it off anytime. |
| `pmBoardDensity` | select | `"dense" \| "compact" \| "comfortable" \| "spacious"` |  |
| `pmBoardSnapshotTtlMs` | number | `integer 0..∞` | Cache lifetime in milliseconds for a PM board's own 'hot' intelligence snapshot (default 900000 = 15 minutes) — kept short since item moves on an active board are frequent. No Settings-UI control yet; set via CLI/PATCH. |
| `pmColdSnapshotTtlMs` | number | `integer 0..∞` | Cache lifetime in milliseconds for a PM board's overnight 'cold tick' intelligence snapshot (default 90000000 ≈ 25 hours) — meant to survive overnight and go stale by the next workday. No Settings-UI control yet; set via CLI/PATCH. |
| `pmColorMode` | select | `"system" \| "light" \| "dark"` | Color mode for the Mission Control / Project Management panel: "system" (default, follow the app/OS theme), "light", or "dark". A per-user display preference for the PM surface. Synonyms: PM color mode, mission control theme, project management light/dark mode. |
| `pmCommentVisibilityEnabled` | toggle | `true \| false` | Internal vs external comment visibility for Mission Control items. Team members can discuss items internally, then selectively share comments with external stakeholders. Comments default to internal (team-only); individual comments can be toggled to external. Role-based filtering ensures viewers see only external comments. |
| `pmComposabilityEnabled` | toggle | `true \| false` | Validates feature interactions before enabling or disabling PM features. Checks prerequisites, warns about behavior changes, and provides a 30-day undo window. |
| `pmComputeChunkSize` | number | `integer 1..∞` | How many PM boards the intelligence scheduler processes per batch on each tick (default 50) — a performance/batching knob, not a cache TTL. No Settings-UI control yet; set via CLI/PATCH. |
| `pmConnected` | toggle | `true \| false` | Internal remembered flag for whether the Mission Control / Project Management integration is currently connected (signed in and syncing PM boards). Default true; set by the PM auth/sync layer — it reflects live connection state, not a user preference. Synonyms: PM connected, mission control connected, project management sync status. |
| `pmCrossBoardSnapshotTtlMs` | number | `integer 0..∞` | Cache lifetime in milliseconds for the cross-board PM intelligence aggregate (default 1800000 = 30 minutes) — expensive to compute and changes propagate slowly, so it is cached longer than a single board. No Settings-UI control yet; set via CLI/PATCH. |
| `pmCrossboardIntelligenceEnabled` | toggle | `true \| false` | PM Cross-Board Intelligence |
| `pmDataDensityEnabled` | toggle | `true \| false` | Tracks per-domain usage density to gate PM intelligence (the "Earn the Right to Speak" system), and detects user behavior patterns like repeated status changes, recurring subtask creation, and batch workflows. On by default; turn it off anytime. |
| `pmDiscoveryCalloutsEnabled` | toggle | `true \| false` | Weekly personalized callouts that surface cross-tool connections and automation offers based on your Omniscio usage patterns. |
| `pmDismissedHelpTips` | list | `array of string (≤200)` |  |
| `pmDismissedNudges` | list | `array of string (≤200)` |  |
| `pmDocumentsEnabled` | toggle | `true \| false` | Document, spreadsheet, and form entities in Mission Control — each with its own sidebar section, list page, and detail page, stored per workspace alongside boards and dashboards. On by default; the toggle stays live so you can turn it off with one setting flip. |
| `pmEmailIntegrationEnabled` | toggle | `true \| false` | Link email threads to PM items, create tasks from emails, and trigger PM automations from incoming mail. Works across Gmail, Agent Email, and Supermail. |
| `pmFeatureProfilesEnabled` | toggle | `true \| false` | PM Feature Profiles |
| `pmFeedSignificanceWeights` | object | `object { maxRecencyBoost: number; mentionBoost: number; mutedBoardPenalty: number; promotedBoardBonus: number; tierCritical: number; tierImportant: number; tierNotable: number }` | Advanced override for the PM Unified Feed's ranking weights — the promoted-board bonus, muted-board penalty, mention boost, max recency boost, and the critical/important/notable tier thresholds. null (the default) uses the built-in weights. A power-user/debug escape hatch; no Settings-UI control, set via CLI/PATCH. |
| `pmHomeBeaconActive` | toggle | `true \| false` | Internal state flag for whether the Project Management "home beacon" is currently active — the attention indicator the PM home entry point uses to draw you to the PM home surface. Default false; managed by the PM home flow, not a user preference. Synonyms: PM home beacon, mission control home beacon, PM home indicator. |
| `pmImportEnabled` | toggle | `true \| false` | Unified import framework for bringing data into PM boards from external sources — Google Sheets (SOP-aware with tab/header color detection), Excel, CSV. Connected sources with scheduled refresh. |
| `pmIntelligenceAdvisorEnabled` | toggle | `true \| false` | PM Intelligence Advisor |
| `pmItemHistoryEnabled` | toggle | `true \| false` | Full change history timeline on PM board items with quick undo (Ctrl+Z), point-in-time rollback, actor provenance (human/agent/automation), and session-linked audit trail. |
| `pmNotificationsEnabled` | toggle | `true \| false` | Smart PM event notifications with session-scoped batching, per-board mute/promote, and due-date alerts. Routes PM changes to the right people through the right channels. |
| `pmOnboardingBoardCreated` | toggle | `true \| false` |  |
| `pmOnboardingCheckedItems` | list | `array of string (≤200)` |  |
| `pmOnboardingComplete` | toggle | `true \| false` |  |
| `pmOnboardingDismissCount` | number | `integer 0..∞` | How many times you have dismissed the Mission Control (PM) onboarding callout. Combined with pmOnboardingDismissDate: once you have dismissed it 3 times, the callout stays hidden for the rest of the day (reset daily). Internal remembered state, not a user-facing toggle. Synonyms: pm onboarding dismissal count, mission control callout dismissals. |
| `pmOnboardingDismissDate` | text | `string (≤40)` | The date (YYYY-MM-DD) of the most recent Mission Control (PM) onboarding callout dismissal. The callout hides for the day when this equals today AND pmOnboardingDismissCount is at least 3. Internal remembered state, not a user-facing toggle. Synonyms: pm onboarding dismissal date, last callout dismiss date. |
| `pmOnboardingHelpEnabled` | toggle | `true \| false` | In-development: preset-scoped onboarding checklist, contextual help tips, scoped help search, and one-click escape to AI sessions with PM context. Hidden until shipped. |
| `pmOpsDailyActionBudget` | number | `integer 0..∞` | Daily cap on how many automated actions the PM autonomous ops engine may take (default 200). Hitting it raises an inbox alert and blocks further automated ops actions until the next day. No Settings-UI control yet; set via CLI/PATCH. |
| `pmOpsEngineEnabled` | toggle | `true \| false` | PM Operations Engine |
| `pmOpsSessionSpawnCostWeight` | number | `integer 1..∞` | What one session SPAWN costs against pmOpsDailyActionBudget, so a day of spawning is not counted as a day of cheap edits. Read by the ops engine's weighted daily-action count. |
| `pmOpsShiftHandoffCompactEnabled` | toggle | `true \| false` | Internal format toggle: include a compact summary in shift handoff output. No user-facing UI. |
| `pmOpsShiftHandoffNarrativeEnabled` | toggle | `true \| false` | Internal format toggle: include a narrative summary in shift handoff output. No user-facing UI. |
| `pmPersonaBAspirationEnabled` | toggle | `true \| false` | In-development: replaces the three-lane onboarding selector with an aspirational checklist that auto-routes users to Quick Start, Guided Setup, or Build with AI based on their checkbox selections. Hidden until shipped. |
| `pmPersonaCImportEnabled` | toggle | `true \| false` | In-development: first-run entry screen for users migrating from other platforms. Shows multi-select platform cards and auto-applies the Operations preset. Hidden until shipped. |
| `pmPostImportHomeEnabled` | toggle | `true \| false` | In-development: personalized Home screen shown after a board import — imported-boards grid, a smart insight card computed from real data, and tailored onboarding checklist items. Hidden until shipped. |
| `pmPostImportHomeSeen` | toggle | `true \| false` |  |
| `pmPredictiveAnalyticsEnabled` | toggle | `true \| false` | Velocity tracking, Monte Carlo completion predictions, what-if scenarios, three-tier pattern detection with proactive warnings, and analytics dashboard widgets. On by default; turn it off anytime. |
| `pmProjectKickoffEnabled` | toggle | `true \| false` | Guided AI interview that helps plan and set up a new project in Mission Control. Accessible from the New Project modal, blank session chips, mid-conversation detection, and AI Coaching. |
| `pmRoleEntryPointsEnabled` | toggle | `true \| false` | In-development: multi-lane onboarding with quick-pick, guided setup, and AI-driven deep interview. Maps AI comfort and organizational role to a default workspace configuration. Hidden until shipped. |
| `pmSavedViewsEnabled` | toggle | `true \| false` | Private, per-user saved views on Mission Control boards. A saved view is visible only to the person who created it, separate from the shared team views everyone else on the board sees. |
| `pmSelectedImportPlatforms` | list | `array of string (≤200)` |  |
| `pmSetupAiComfort` | select | `"low" \| "medium" \| "high"` |  |
| `pmSetupChecklist` | list | `array of string (≤200)` |  |
| `pmSetupChecklistBoardId` | text | `string (≤200)` | Internal pointer to the PM board Omniscio auto-created for your setup checklist. App-written when the checklist board is created; not user-set. |
| `pmSetupChecklistItemMap` | map | `map of string → string (≤200)` | Internal lookup mapping each onboarding checklist step to the concrete PM item id on your auto-created setup-checklist board, so "launch AI on this step" can jump straight to it. App-written when the checklist board is created; not user-set. |
| `pmSetupComplete` | toggle | `true \| false` |  |
| `pmSetupLane` | select | `"quick-pick" \| "interview" \| "deep-session"` |  |
| `pmSetupOrgRole` | select | `"tasks" \| "team" \| "department" \| "engineering"` |  |
| `pmSetupWizardEnabled` | toggle | `true \| false` | Onboarding interview and preset picker shown when Mission Control is first enabled. Asks four questions (AI comfort, role, feature needs, free text) and recommends a preset (Tasks, Projects, Operations, or Engineering). |
| `pmSprintsEnabled` | toggle | `true \| false` | First-class time-boxed iterations for Mission Control boards — sprint lifecycle (planned, active, completed), sprint planning view, completion with velocity snapshots, and burndown tracking. |
| `pmSyncStaleThresholdMs` | number | `integer 30000..∞` | How old (in milliseconds) a PM board's data may get before it is re-synced, while you are NOT connected via the realtime websocket (default 300000 = 5 minutes; minimum 30000). No Settings-UI control yet; set via CLI/PATCH. |
| `pmSyncStaleThresholdWsActiveMs` | number | `integer 60000..∞` | How old (in milliseconds) a PM board's data may get before it is re-synced while a realtime websocket connection is active (default 900000 = 15 minutes; minimum 60000) — longer than pmSyncStaleThresholdMs since a live connection already keeps data fresh. No Settings-UI control yet; set via CLI/PATCH. |
| `pmSyncTickIntervalMs` | number | `integer 30000..∞` | How often (in milliseconds) the scheduled 'PM Board Sync' job ticks (default 300000 = 5 minutes; minimum 30000). No Settings-UI control yet; set via CLI/PATCH. |
| `pmTeamChatEnabled` | toggle | `true \| false` | In-development: reference PM items in chat with #mentions, create tasks from messages, see status updates in channels, and view linked chat messages on PM items. Hidden until shipped. |
| `pmUnifiedFeedDigestEnabled` | toggle | `true \| false` |  |
| `pmUnifiedFeedDigestTimeZone` | text | `string` | The IANA time zone the daily project-management feed digest’s 8am fire hour is resolved against. Captured automatically on the first run (your current host zone) so the digest keeps posting at 8am local after an OS time-zone change. Null until captured. Synonyms: PM digest time zone, project feed digest fire zone. |
| `pmUnifiedFeedEnabled` | toggle | `true \| false` | Unified cross-board activity timeline ranked by significance, with inline actions, daily digest, and AI summaries. |
| `pmUsageDailyWarnEnabled` | toggle | `true \| false` | Master switch for the PM backend API usage warning — when on (default), a 'high daily usage' alert fires once your daily PM backend call count hits pmUsageDailyWarnThreshold. No Settings-UI control yet; set via CLI/PATCH. |
| `pmUsageDailyWarnThreshold` | number | `integer 100..50000` | The daily PM backend API call count that triggers the 'High Task backend API usage' alert (default 5000; range 100-50000), when pmUsageDailyWarnEnabled is on. Counts all PM backend calls, not just automations. No Settings-UI control yet; set via CLI/PATCH. |
| `pmWarmStaleAgeMs` | number | `integer 0..∞` | How long (in milliseconds) a PM board may sit idle before the intelligence scheduler's 'warm tick' recomputes it (default 600000 = 10 minutes) — a staleness-age threshold, distinct from the raw cache TTLs above. No Settings-UI control yet; set via CLI/PATCH. |
| `polishAmbient` | toggle | `true \| false` |  |
| `polishDashboard` | toggle | `true \| false` |  |
| `polishDepth` | toggle | `true \| false` |  |
| `polishGlideReorder` | toggle | `true \| false` |  |
| `polishInboxZero` | toggle | `true \| false` |  |
| `polishInteractive` | toggle | `true \| false` |  |
| `polishPilotEnabled` | toggle | `true \| false` | Adds Polish (Polski) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `polishViewCrossfade` | toggle | `true \| false` |  |
| `portableBackupEnabled` | toggle | `true \| false` | Export an encrypted backup file you can move to another computer, and import it back. |
| `postLandBuildHarmYieldEnabled` | toggle | `true \| false` |  |
| `postRestoreWizardPending` | toggle | `true \| false` |  |
| `prBodyCheckEnabled` | toggle | `true \| false` |  |
| `prJanitorPaused` | toggle | `true \| false` | PR JANITOR — operator pause, driven by the Pause control in the PR Merge Queue panel's PR Janitor section. When `true`, the panel shows the janitor as "not scheduled" (never a fabricated next-run time) — see .claude/memory/contracts/pr-janitor-in-app-contract.md C6. Setting it through the panel ALSO deactivates the janitor's cron job, so pausing genuinely stops the nightly rather than only changing what the panel displays — a Pause that left the job firing would tell the operator closing had stopped while it had not. Resuming re-activates the job only when it is actually approved; one sitting at pending or rejected is waiting on a human and is left alone. The flag remains the single settings-backed answer to "should the janitor be treated as paused?", which is what the panel reads to decide between a real next-run time and "not scheduled". Default `false` (running normally, matching every install's existing behavior). |
| `prMergeQueueAiSummariesEnabled` | toggle | `true \| false` | AI ONE-LINE SUMMARIES — when true (default), the queue generates a plain- English one-sentence summary of each open PR during refresh and shows it as the pill headline (falling back to the PR title while one is still generating or if the AI call fails). Cached per PR head SHA in `pr_merge_queue_summaries`, so each PR is summarised once per head. Off → zero AI calls; pills show `#num · <title>`. Title + description + changed- file list are sent to the configured lightweight AI provider. |
| `prMergeQueueArchivedPrs` | map | `map of string → array of integer 0..∞` | ARCHIVED PRs — per-PR personal dismissals, keyed by AMC `projectId` → the archived PR numbers for that repo. An archived PR is hidden from the queue lanes AND dropped from BOTH the inbox `reviewNeededCount` nudge AND the `stuckCount` — archiving clears a PR everywhere, stuck merges included (the I26 reversal), so dismissing a PR quiets it like archiving an email. The inbox shows one row PER attention-needing PR; dismissing that row archives just that PR. A transient "Show archived" view toggle re-reveals them (dimmed, in their lane) with an Unarchive action. Stored here (not a DB table) so the renderer reads it reactively via the settings-store and main reads it via `getSettings()`. Unset = nothing archived. Each repo's list is capped at 500 in the Zod schema (the map at 100 repos); orthogonal to lane (a render+count filter, never a new `Lane` value). |
| `prMergeQueueAutoBatchEnabled` | toggle | `true \| false` | AUTO-BATCH — when `true`, the auto-merge daemon combines several eligible (fast-lane, non-overlapping, this-shard, not-in-flight) PRs into ONE merge session that applies them together and runs the gate ONCE, instead of one session per PR — cutting the duplicated test/build cost. Default `false` (off; today's one-PR-per-tick behavior). Only NON-overlapping PRs are grouped (their file sets are disjoint), so the single gate run is trustworthy. |
| `prMergeQueueAutoBatchMaxSize` | number | `number` | Max PRs the daemon packs into one auto-batch session. Default `8` (range 2-32). A batch may be smaller if fewer non-overlapping PRs are available this tick. Only meaningful when `prMergeQueueAutoBatchEnabled` is `true`. |
| `prMergeQueueAutoMergeEnabled` | toggle | `true \| false` | AUTO-MERGE DAEMON — master gate. When `true` AND a repo's `trustLevel === 'autonomous'`, the daemon will automatically spawn merge sessions for fast-lane PRs without human approval. Default `false` (off by default; users must opt in explicitly through a confirmation modal in Settings). |
| `prMergeQueueBatchPromptTemplate` | text | `string (≤20000)` |  |
| `prMergeQueueDailyBudgetUsd` | number | `number 0..100` | Daily-spend budget cap in USD for daemon-initiated merge sessions. Default `5.00`. Range: 0–100. A value of `0` DISABLES the cap (no spending limit). Queried per-repo against `api_cost_log` rows with `source = 'pr-merge-queue-auto'` for the current UTC day. |
| `prMergeQueueMergePromptTemplate` | text | `string (≤20000)` | EDITABLE MERGE PROMPTS (global). Optional operator overrides for the prompt sent to a single-PR / batch merge session. When set + non-blank, the template is rendered (with `{{token}}` substitution) INSTEAD of the built-in default in pr-merge-queue/prompt.ts. A per-repo override (`PrMergeQueueRepoConfig.mergePromptTemplate` / `batchPromptTemplate`) takes precedence over these. Unset = use the built-in default (recommended — the default is the version that never touches `master`). A saved custom prompt is a frozen copy and won't receive future default edits; Reset-to-default in Settings re-syncs it. Capped 20000 chars. |
| `prMergeQueueRepos` | list | `array of object { baseBranch: string (≤120); batchPromptTemplate: string (≤20000); ghSlug: string (≤140); mergePromptTemplate: string (≤20000); name: string (≤120); projectId: string (≤100); riskyPaths: array of string (≤300); standingInstructions: string (≤4000); trustLevel: "pause-and-ask" \| "fast-lane-only" \| "autonomous" }` | One entry per AMC project that opts into the queue. Each entry pairs an AMC project ID with a GitHub repo slug, so the queue knows which sessions to spawn (project-scoped) and which repo's PRs to triage. |
| `prPrepPromptCustomRules` | text | `string (≤10000)` | CUSTOM RULES for the AUTOMATIC PR-prep prompt — the EASY way to add standing rules without rewriting the whole `prPrepPromptTemplate` (and having to preserve its load-bearing anchors). When set + non-blank, this text is appended to the END of the effective prompt (under an advisory "Your custom rules" header) that the scheduled "PR prep (auto)" cron gives every session — see `appendCustomRules` / `resolveEffectivePrepPromptTemplate` in shared/pr-prep-prompt.ts. It is ADDITIVE: applied on top of the built-in default OR a full override (even an invalid one, which still falls back to the safe default), and it can only ADD text — never remove an anchor or weaken the never-push-master guardrail. Unset/blank = zero change (today's behavior). Capped 10000 chars. |
| `prPrepPromptTemplate` | text | `string (≤30000)` | EDITABLE AUTOMATIC PR-PREP PROMPT. Optional operator override for the prompt the scheduled "PR prep (auto)" cron gives each session it spawns to prepare an open PR for merge (this is the prompt driving your automatic PR merging, NOT the in-app queue's merge prompts above). When set + non-blank AND it keeps every load-bearing anchor (`REQUIRED_PREP_PROMPT_ANCHORS` in shared/pr-prep-prompt.ts — the ready-to-merge hand-off, the pipeline success marker, the never-push-master guardrail), the main process serves it to the cron over `GET /pr-prep/effective-prompt`; an override MISSING an anchor is ignored and the built-in default is used instead, so a bad edit can never silently break merging. Unset = built-in default. Reset-to-default in Settings re-syncs a custom copy. Capped 30000 chars (the default is ~15k). |
| `prReplyDelivery` | select | `"prefer-original" \| "always-restart" \| "card-only"` |  |
| `prReplyRestartMaxSessions` | number | `integer 1..20` |  |
| `prSpawnerEnabled` | toggle | `true \| false` |  |
| `prVisualEvidenceEnabled` | toggle | `true \| false` | Coding-agent sessions attach before/after UI screenshots to their GitHub PR. |
| `preferredHarness` | select | `"claude" \| "codex" \| "other" \| "not-sure"` | Your preferred AI-agent harness, captured once during the Setup v2 onboarding intake ("claude" \| "codex" \| "other" \| "not-sure"). It steers the onboarding install only: "codex" also enables Codex sessions and installs the Codex CLI, and Claude Code always installs for everyone. Optional: undefined until you answer; "claude" is the safe default. Synonyms: preferred agent, harness choice, which agent I use. |
| `presentationBlockAutoSpawn` | toggle | `true \| false` |  |
| `presentationContentScrub` | toggle | `true \| false` | Optional extra layer that also blurs the CONTENT inside an open session while presenting — message text, file paths, and names — not just the sidebar. Off by default; layered on top of the always-on chrome hiding. Synonyms: blur message content, scrub open session on camera, hide conversation text during a demo. |
| `presentationCustomLabels` | unknown | `catch` | Custom placeholder labels for the "placeholder" hide style, keyed by project/session id (e.g. name a hidden client "Acme"). An id with no entry falls back to an auto "Project N" / "Session N" label. Edited inline in the Presentation backstage. Synonyms: custom placeholder names, rename hidden items for a demo, presentation labels. |
| `presentationDemoIdentity` | unknown | `catch` | The optional demo identity shown in place of your real account while presenting: a display name plus an optional small avatar image (empty avatar falls back to an initials chip). null (the default) shows a neutral "Presenter" placeholder. Nothing about your real name/email/avatar is shown on camera. Synonyms: demo name, fake account name for a demo, presenter identity, hide my email on screen. |
| `presentationExitStripPosition` | unknown | `catch` | Which edge of the screen the "Presentation Mode / Exit" strip anchors to while presenting ('top' or 'bottom'; default 'bottom'). No Settings-UI control yet; set via CLI/PATCH. |
| `presentationHiddenIntegrationIds` | unknown | `catch` | Which of your built-in Omniscio panels are hidden from camera while presenting, by integration id — a per-integration opt-out on top of the master "Show my integrations on camera" switch. Empty (the default) hides none. Set from the per-integration checkboxes in the Presentation Mode staging panel. |
| `presentationHideAccountWidget` | toggle | `true \| false` | Opt-in toggle that hides the header account switcher / balancer widget ENTIRELY while presenting — the account chip plus the balance-scale "N accounts in use" load-balancer count all leave the header, rather than just disguising the name on them. Off by default (the chip stays, showing a demo identity). Synonyms: hide the account widget on camera, hide the account switcher during a demo, hide how many accounts I am running, remove the account pill while presenting. |
| `presentationHideStyle` | select | `"remove" \| "blur" \| "placeholder"` | How a NON-revealed project or session looks while presenting: "remove" (default, safest) filters it out of the sidebar entirely so it can never leak; "blur" keeps the row but blurs the name in place; "placeholder" swaps a neutral label like "Project 1" / "Session A". Synonyms: presentation hide style, how to hide items on camera, blur vs remove vs placeholder. |
| `presentationModeEnabled` | toggle | `true \| false` | Master switch for Presentation Mode (recording-safe / demo mode). When on, Omniscio hides everything private on camera — your projects and sessions, account name/email, and live spend — except the items you explicitly reveal in the Presentation backstage, plus any session you start yourself while it is on. Persists across restarts and only turns off when you exit. Off by default. Synonyms: presentation mode, demo mode, screen-share/recording safe mode, privacy mode, hide everything for a demo, backstage. |
| `presentationQuietInbox` | toggle | `true \| false` |  |
| `presentationRevealIntegrations` | toggle | `true \| false` | When on (default), your built-in Omniscio panels (Mail, Calendar, Tasks, Mind Map, and so on) show on camera while presenting; turn individual ones off with presentationHiddenIntegrationIds. Off hides them all. Presentation Mode staging panel → "Show my integrations on camera". |
| `presentationRevealedProjectIds` | unknown | `catch` | The list of project ids you chose to SHOW while presenting (everything else is hidden). Managed from the Presentation backstage reveal toggles; a project the user creates while presenting is auto-added. Synonyms: revealed projects, which projects are visible on camera, presentation allow-list (projects). |
| `presentationRevealedSessionIds` | unknown | `catch` | The list of session ids shown while presenting — your explicit picks PLUS any session you start yourself while Presentation Mode is on (automation/recipe/background spawns are never added, so they stay hidden). Managed from the Presentation backstage. Synonyms: revealed sessions, which sessions are visible on camera, presentation allow-list (sessions). |
| `presentationShowExitStrip` | unknown | `catch` | Whether the "Presentation Mode / Exit" strip renders at all while presenting (default on). No Settings-UI control yet; set via CLI/PATCH. |
| `proAnnualBillingEnabled` | toggle | `true \| false` | In-development: adds a monthly/annual choice to the Pro card on Plan & Billing, so a customer can buy the $144/year plan the Terms advertise (about 20% off the monthly price). Held dark until the gateway has a live STRIPE_PRO_ANNUAL_PRICE_ID: without it every annual checkout returns "not available", so a customer would see a priced offer they cannot buy. Reveal this flag as part of the annual go-live, together with setting that price id on BOTH the gateway and firebase-functions deploys — the gateway sells the plan and firebase grants it, so a partial config would charge someone $144 and leave them on Free. Off by default; hidden until shipped. |
| `proSubscriptionEnabled` | toggle | `true \| false` | A Plan & Billing screen to see your plan, compare Free vs Pro, upgrade to Pro ($15/mo) via Stripe, bring your own API key, and track your monthly AI allowance. |
| `proactiveSpeechAwayAfterMinutes` | number | `integer 0..240` | Go quiet once you have been away from the computer this many minutes, so Omniscio is not talking to an empty room. Measured from the operating system's own idle timer, so it keeps counting while the app is in the background. 0 (the default) turns the away rule off entirely; the maximum is 240 minutes. Applies only to speech you did not ask for; anything you explicitly request still plays. Synonyms: stop talking when I am away, idle timeout for speech, do not speak to an empty room, away gate for read-aloud, mute speech when idle, how long before it goes quiet. |
| `proactiveSpeechQuietHoursEnabled` | toggle | `true \| false` | When on, Omniscio stays silent during your quiet hours — it will not speak anything you did not ask for (read-aloud, narration, the spoken briefing, voice report-back). Anything you explicitly ask it to say still plays. Off by default, because these settings gate speech that already ships and a non-neutral default would change read-aloud for everyone. Pair it with proactiveSpeechQuietHoursStart and proactiveSpeechQuietHoursEnd. Synonyms: quiet hours for speech, stop talking at night, do not speak after hours, mute read-aloud overnight, silence proactive speech, no talking while I sleep. |
| `proactiveSpeechQuietHoursEnd` | text | `string` | When the speech quiet-hours window ENDS, as a local 24-hour HH:MM time (default 07:00). Only has an effect while proactiveSpeechQuietHoursEnabled is on. The window wraps midnight when the start is later than the end. Setting start and end to the same time means an EMPTY window, not all day. Synonyms: quiet hours end time, when can it talk again, end speech quiet hours, silence speech until, no-talking end time. |
| `proactiveSpeechQuietHoursStart` | text | `string` | When the speech quiet-hours window BEGINS, as a local 24-hour HH:MM time (default 22:00). Only has an effect while proactiveSpeechQuietHoursEnabled is on. The window wraps midnight when the start is later than the end — 22:00 to 07:00 is the usual case. Setting start and end to the same time means an EMPTY window, not all day. Synonyms: quiet hours start time, when should it stop talking, begin speech quiet hours, silence speech from, no-talking start time. |
| `problemAlertReRaiseThrottleEnabled` | toggle | `true \| false` |  |
| `processReaperDryRunLaunches` | number | `integer 0..1000` |  |
| `processReaperMode` | select | `"dry-run" \| "active"` |  |
| `productivityCollapsed` | toggle | `true \| false` |  |
| `profileMinerEnabled` | toggle | `true \| false` | Master switch for the Profile Miner ("The Mirror") — when on (and Supermail is enabled on the amc-gmail path with Google connected), it periodically mines your Gmail (via the Supermail mirror) into typed, evidence-backed profile SIGNALS — facts, preferences, relationships, goals, problems, needs — each with a short supporting quote from the email. Signals land as `proposed` and can be reviewed / promoted into the AI Coaching profile. Off by default; controlled over the CLI (/profile-miner/* routes), no Settings-UI toggle. Synonyms: profile miner, the mirror, mined signals, contact profile mining, email signal mining, propose contact facts. |
| `projectDefaultModels` | map | `map of string → string (≤100)` |  |
| `projectDefaultProviders` | map | `map of string → any` |  |
| `projectDefaultThinkingLevels` | map | `map of string → "auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `projectMcpDefaults` | map | `map of string → map of string → true \| false` |  |
| `projectProviderDefaultModels` | map | `map of string → map of string → string (≤100)` |  |
| `projectProviderDefaultThinkingLevels` | map | `map of string → map of string → "auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `projectsSidebarIconsOnly` | toggle | `true \| false` |  |
| `projectsSidebarWidth` | number | `integer 120..400` |  |
| `promptRateLimitWarningPct` | number | `number 1..100` | Rate-limit utilization percent (1–100) at which the pre-send "This prompt may be expensive" confirmation ALSO warns about your 5-hour usage: when your current bucket utilization is at or above this percent, the danger confirm adds a rate-limit line before you send. Null disables the rate-limit warning (the dollar-cap warning can still fire independently). Synonyms: rate limit warning threshold, 5-hour usage warning, utilization percent alert, bandwidth warning percent. |
| `promptSpendWarningCapsUSD` | map | `map of string → number 0..10000` | Per-model dollar caps (in USD) for the pre-send spend warning: a map of model name (or "_default") to a dollar amount — when the estimated cost of a prompt you are about to send reaches that cap, a "This prompt may be expensive" confirmation appears before the send. Null or empty disables the spend warning entirely. Estimates are approximate (input + draft + a fixed output estimate) and use each model's catalog price. Synonyms: spend warning threshold, expensive-prompt warning, cost cap before send, per-model dollar limit, prompt price alert. |
| `promptSpendWarningEnabled` | toggle | `true \| false` | Warns you before sending a prompt that is estimated to cost more than your threshold. API-key users set a per-model dollar cap; subscription users set a 5-hour rate-limit percentage. |
| `promptToolsCollapsed` | toggle | `true \| false` |  |
| `providerBalanceAutoResumeEnabled` | toggle | `true \| false` | When an API-key provider account (DeepSeek, Kimi) runs out of balance, automatically resume its parked sessions once the account is funded again. |
| `providerConfigSyncCursorProjectDirs` | list | `array of string (≤500)` |  |
| `providerConfigSyncSkillBudgets` | map | `map of string → integer 0..100000` | Provider Config Sync — the per-engine skill-count budget: engine id (codex, gemini, cursor) → the max number of skills to sync to that engine before the Skill Budget alert fires. 0 (or absent) = the code default (Codex has a real strict-loader limit; other engines default OFF). User-tunable, so the alert never depends on reverse-engineering an engine internal limit. Synonyms: skill budget, per-engine skill cap, codex skill limit, how many skills per engine. |
| `providerConfigSyncSkillExclusions` | map | `map of string → array of string (≤200)` | Provider Config Sync — the per-engine skill exclusions you chose: engine id (codex, gemini, cursor — the COPYING engines) → skill folder names to hold back from THAT engine fan-out. An excluded skill stays fully installed and usable everywhere else; it is only kept out of that one engine (its already-synced copy is swept on the next sync). Populated via the Skill Budget alert / its settings, never an automatic cut. Synonyms: skill exclusions, per-engine skip list, do not sync these skills, hold back skill. |
| `providerDefaultModels` | map | `map of string → string (≤100)` |  |
| `providerDefaultThinkingLevels` | map | `map of string → "auto" \| "minimal" \| "low" \| "medium" \| "high" \| "max" \| "xhigh" \| "ultra"` |  |
| `providerFunding` | map | `map of string → array of "own-key" \| "omniscio"` |  |
| `providerKeyExhausted` | map | `map of string → string` | RETIRED — ignored, and removed in a later release. It used to record which of your own provider keys were out of balance. Omniscio now remembers an account that runs out of credit while the app is running: every session skips it and uses the next row of its Who pays & who serves list, and it is tried again every 10 minutes, or as soon as a balance check sees money there. Nothing reads this setting any more, so editing it changes nothing. Synonyms: provider key out of balance, my api key ran out of credit, why is it using company credits, exhausted provider key, unfunded key fallback, key balance cache. |
| `providerRouteOverrides` | map | `map of string → any` | Per-AI connection route: for each AI that can be reached more than one way — today Codex, natively, through Claude, or through a custom provider — pins which one to use. Empty means each AI uses its own default. Your pick applies to sessions you start from then on; sessions that already exist keep the connection they started with. If the one you pick is not set up, the app falls back to one that is. The session page carries no route picker — this is the only route editor. It never decides who pays: that is supplyLists (Settings → Accounts → Who pays & who serves). Settings → Sessions → How each AI connects. Synonyms: route, connection route, transport, gateway, claude via codex, custom provider via codex. |
| `providerSessionCoreEnabled` | toggle | `true \| false` |  |
| `providerStatusMonitorEnabled` | toggle | `true \| false` |  |
| `proxyModelsEnabled` | toggle | `true \| false` | Run GPT, xAI Grok, CrofAI, or DeepInfra (cheap open-weight DeepSeek/Qwen/Llama/GLM/Kimi/MiniMax) inside the Claude Code harness by pointing it at a local model-translating proxy. On by default — the CLIProxyAPI model-proxy binary ships in the installer (with a runtime download-on-first-use fallback). Turn it off to hide these providers. |
| `pullRequestsEnabled` | toggle | `true \| false` | Adds a "Pull Requests" sidebar tab to view, comment on, approve, and merge GitHub pull requests across all your repos. |
| `punjabiPilotEnabled` | toggle | `true \| false` | Adds Punjabi (ਪੰਜਾਬੀ) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `quickChatTargets` | list | `array of object { hotkey: string (≤100) \| array of string (≤100); id: string (≤64); kind: "person" \| "channel"; label: string (≤200); refId: string (≤128) }` |  |
| `quickEmailEnabled` | toggle | `true \| false` |  |
| `quickEmailHotkeysEnabled` | toggle | `true \| false` |  |
| `quickEmailShowSubjectByDefault` | toggle | `true \| false` |  |
| `quickLaunchDefaultProjectId` | text | `string (≤64)` |  |
| `quickLaunchHotkeyEnabled` | toggle | `true \| false` |  |
| `quickLaunchPinnedActionIds` | list | `array of string (≤64)` |  |
| `quickLaunchTabHotkeys` | map | `map of string → string (≤100) \| array of string (≤100)` |  |
| `quickLaunchTabsBackfilledAt` | text | `string (≤64)` |  |
| `quickLaunchTaskDefaultListId` | text | `string (≤64)` |  |
| `quickRepliesSidebarEnabled` | toggle | `true \| false` |  |
| `quickReplyEnabled` | toggle | `true \| false` |  |
| `quickReplyNumberKeysDirection` | select | `"bottom-up" \| "top-down"` | Quick Replies — how the number badges count in the Alt+S quick-reply picker. bottom-up puts 1 on the bottom row (nearest the send box) and counts up; top-down puts 1 on the top row and counts down. Default bottom-up. Pinned numbers always win either way. Synonyms: numbering direction, number keys order, Alt+S numbering, quick reply badge order. |
| `quickReplyNumberKeysEnabled` | toggle | `true \| false` |  |
| `quickReplyText` | text | `string (≤500)` |  |
| `quickSmsRecipients` | list | `array of object { id: string (≤64); name: string (≤100); phone: string (≤40) }` |  |
| `quietHoursDays` | list | `array of integer 0..6` | Which days of the week (0=Sunday..6=Saturday; default all 7) the quiet-hours window applies on. Only takes effect when quietHoursEnabled is on. No Settings-UI control yet; set via CLI/PATCH. |
| `quietHoursEnabled` | toggle | `true \| false` | Master switch for the quiet-hours window — when on, desktop notifications, mobile push, SMS alerts, and owner-critical pushes are silenced during the quietHoursStart–quietHoursEnd window on the days listed in quietHoursDays. Off by default. No Settings-UI control yet; set via CLI/PATCH. |
| `quietHoursEnd` | text | `string` | The time of day (24-hour HH:MM, local time; default 07:00) the quiet-hours window ends. Only takes effect when quietHoursEnabled is on; pairs with quietHoursStart. No Settings-UI control yet; set via CLI/PATCH. |
| `quietHoursStart` | text | `string` | The time of day (24-hour HH:MM, local time; default 22:00) the quiet-hours window starts. Only takes effect when quietHoursEnabled is on; pairs with quietHoursEnd (the window wraps overnight when start is later than end). No Settings-UI control yet; set via CLI/PATCH. |
| `qwCorpusEnabled` | toggle | `true \| false` |  |
| `rateLimitDowngradeEnabled` | toggle | `true \| false` | Opt-in auto-downgrade: when enabled and your 5-hour or 7-day rate-limit utilization reaches the downgrade threshold, active sessions automatically switch to a cheaper fallback model to protect your usage bucket, and switch back once utilization drops. Off by default. The fallback model (rateLimitDowngradeFallbackModel) must be in the model catalog, and the threshold (rateLimitDowngradeThresholdPct) defaults to 80%. Synonyms: auto downgrade model, rate limit fallback, cheaper model when limited, tier-down protection. |
| `rateLimitDowngradeFallbackModel` | text | `string` | The model active sessions fall back to while the rate-limit auto-downgrade is active — set it to a cheaper model in the catalog (e.g. a fast mid-tier model) so usage is preserved during a utilization spike. Must be a valid catalog model; an unknown value is rejected. Only used when rateLimitDowngradeEnabled is on and the threshold is reached. Synonyms: fallback model, downgrade model, cheaper model, backup model. |
| `rateLimitDowngradeThresholdPct` | number | `number 50..99` | The rate-limit utilization percent (50–99, default 80) that triggers the auto-downgrade when rateLimitDowngradeEnabled is on: when your 5-hour or 7-day bucket utilization is at or above this percent, sessions switch to the fallback model, and clear again once utilization falls ~10% below it. Synonyms: downgrade threshold percent, utilization trigger, rate limit cutoff percent, when to tier down. |
| `realChromeBridgeDriveAnyTabEnabled` | toggle | `true \| false` | Opt-in that lets Omniscio agents see and drive ANY tab in your real Chrome — including tabs you opened yourself — not just tabs the agent created. Off by default; it WIDENS the data-safety boundary (an agent could then drive your email or banking tab), so turn it on only when you need an agent to reach a pre-existing tab, such as finishing a Claude account re-login in the sign-in tab. Every tab an agent drives shows a loud "Omniscio AI is controlling this tab" banner, and turning the setting off immediately releases (never closes) any of your tabs the agent had grabbed. Desktop-only, full-trust-token gated. Synonyms: drive any tab, let agents drive any Chrome tab, real chrome any tab, attach an existing tab, reach my login tab. |
| `realChromeBridgeDrivePopupsEnabled` | toggle | `true \| false` |  |
| `realChromeBridgeEnabled` | toggle | `true \| false` | Retired: "My Real Chrome — Full" drove your own everyday Chrome through a companion extension that needs the high-risk debugger permission — the one thing the Chrome Web Store will not approve, so it could only ever be loaded by hand in developer mode. It was the most capable bridge (real/trusted clicks, file uploads, full-page screenshots), and its code and routes are kept. Disabled + hidden in favor of its Web-Store-approvable sibling, "My Real Chrome — Lite" (chrome.scripting + native messaging). Re-reveal it for testing by launching with AMC_SHOW_REAL_CHROME_BRIDGE=1. |
| `realChromeBridgeV2DriveAnyTabEnabled` | toggle | `true \| false` | Opt-in for the publishable "My Real Chrome v2" that lets Omniscio agents see and drive ANY tab in your real Chrome — including tabs you opened yourself — not just tabs the agent created. Off by default; it WIDENS the data-safety boundary (an agent could then drive your email or banking tab), so turn it on only when you need an agent to reach a pre-existing tab. Every tab an agent drives shows a loud "Omniscio AI is controlling this tab" banner, and turning the setting off immediately releases (never closes) any of your tabs the agent had grabbed. Desktop-only. Synonyms: v2 drive any tab, real chrome v2 any tab, attach an existing tab v2, reach my login tab v2. |
| `realChromeBridgeV2DrivePopupsEnabled` | toggle | `true \| false` | Opt-in for the publishable "My Real Chrome v2" that lets Omniscio agents drive a popup opened by a tab the agent itself created — the typical "Sign in with Google" / OAuth popup flow. Off by default. Your existing tabs are never touched by this setting. Desktop-only. Synonyms: v2 drive popups, real chrome v2 oauth popup, agent sign-in popup, drive login popup. |
| `realChromeBridgeV2Enabled` | toggle | `true \| false` | In-development: "My Real Chrome — Lite" is a lighter, Web-Store-safe way for agents to drive your everyday Chrome WITHOUT the high-risk debugger permission — it uses Chrome scripting + native messaging (the same architecture as Anthropic's published Claude extension), so it can be approved for the Chrome Web Store and is not broken by other extensions (LastPass, etc.). It does less than "My Real Chrome — Full" (synthetic clicks, no file uploads, visible-tab-only screenshots) in exchange for a cleaner, safer, sideload-free install. Fully separate from the Full build; the agent still only opens and drives its OWN fresh tabs, every AI-driven tab shows a clear on-page banner, and per-site access is granted by you and revocable. Desktop-only. Hidden until shipped. |
| `recipeConcurrencyWarningEnabled` | toggle | `true \| false` |  |
| `recipeDefaultCostCapUsd` | number | `number 0..1000` |  |
| `recordBreakInboxAlertsEnabled` | toggle | `true \| false` |  |
| `recordBreakNotificationsEnabled` | toggle | `true \| false` |  |
| `recurringSpecialEventsEnabled` | toggle | `true \| false` | Add birthdays, anniversaries, and holidays that create Google Calendar events plus lead-time reminders (day-of, a week before, a month before, or any number of days before). |
| `reduceTerminalPopupsPromptSeen` | toggle | `true \| false` |  |
| `reflectionNudgeEnabled` | toggle | `true \| false` | A once-per-weekday inbox nudge, at a random but timely moment, to reflect on what you just did and how an Omniscio agent could take more of it off your plate. "Let's talk about it" opens a chat that brainstorms and can hand off to the automation builder or Foundry. Off by default. |
| `regimeStatusEnabled` | toggle | `true \| false` | In-development: a developer-tools panel that shows the end-to-end merge-gating + cloud-testing regime at a glance — each active branch's merge checks (running / passed / failed / stale) plus the cloud picture (fleet health, last master build + freshness, in-flight & recent cloud runs, and 24h spend). Read-only. Hidden until shipped. |
| `regimeStatusSidebarEnabled` | toggle | `true \| false` | Shows or hides the Test Regime Monitor entry in the sidebar — the developer-tools dashboard for the end-to-end merge-gating + cloud-testing regime status. One of the per-section sidebar visibility toggles; on by default, turn it off to remove Test Regime Monitor from the sidebar. Synonyms: test regime monitor sidebar, gate and cloud status panel, show/hide regime dashboard. |
| `repackOnNextStartupRequestedByUser` | toggle | `true \| false` | True when the USER scheduled the pending compaction above. The Git storage card is the only IN-APP path that sets it together with the list, and it clears both on cancel — but a headless or CLI write (`PATCH /settings`) can set it too, and an import or a restore can CARRY it in alongside the list, since no such path touches either key. It decides the pre-window budget: a marked run keeps the long whole-run budget, an unmarked one gets a minute, so the window is held for at most that. Cleared together with the request at boot. |
| `repackReposOnNextStartup` | list | `array of string` | Absolute paths of git repositories to COMPACT on the next app launch — the git-store twin of `compactOnNextStartup`. Set by the "Compact git storage" action. Honored behind the splash: before the main window opens, before any session resumes, and before the app runs any git of its own, because that is the only moment in the app's life with no git activity to contend with. The list is cleared and flushed to disk BEFORE the work starts, and the work is ABANDONED if that clear fails, so a compaction can never boot-loop. See git-store-maintenance-contract.md § Manual compaction. |
| `repeatedPhraseQuickReplyNudgeEnabled` | toggle | `true \| false` |  |
| `repeatedPhraseQuickReplyNudgeThreshold` | number | `integer 2..100` |  |
| `repoFoundationsPanelEnabled` | toggle | `true \| false` | Repo Foundations |
| `repoFoundationsSkillEnabled` | toggle | `true \| false` |  |
| `repoguardBuiltinMigrated` | toggle | `true \| false` |  |
| `reportConversationsEnabled` | toggle | `true \| false` | Every report sent from the feedback dialog also opens a Help Desk conversation, so support can reply inside the app. Replies show under "Your reports" even when Get Help is off; the AI assistant never answers them. On by default; you can turn it off anytime. |
| `reportTrackerEnabled` | toggle | `true \| false` | In-development: adds a Report Tracker tab inside the Bug Intake panel so you can see the status of every submitted report — triaged, in-flight, or resolved — without leaving the panel. Hidden until shipped. |
| `requireGlobalAuth` | toggle | `true \| false` | The Global Auth sign-in gate's enforce-sign-in flag. When on (the default), the app requires sign-in to your global account through the hosted auth gate before use; when off, sign-in is not enforced. Set by the app's auth-gate provisioning — not user-editable from the Settings UI or the CLI. Synonyms: enforce sign-in, require global auth, sign-in gate on, hosted auth required. |
| `requireMobileAccountLogin` | toggle | `true \| false` |  |
| `requireWorktreeIsolation` | toggle | `true \| false` | When on, a session whose git worktree could not be created is stopped with an error instead of silently falling back to run inside your main project checkout — so an agent can never edit or commit to your shared project tree when isolation fails (for example under heavy load). Off by default for backward compatibility; turn it on if you rely on worktree isolation as a safety net. Pairs with isolationFallbackDir, which (when set) runs a source copy in a safe scratch folder instead of erroring. Env kill switch: AMC_DISABLE_REQUIRE_ISOLATION=1. Synonyms: require worktree isolation, fail-closed isolation, never run in the main repo, keep agents off my project folder. |
| `reserveUiCoreCount` | number | `integer 1..8` | How many performance (P) cores to set aside for Omniscio's window when the reserve setting above is on. One is enough for a responsive window on most machines; raise it if Omniscio's own window, its graphics process and its helpers together need more than a single core to stay smooth under a heavy swarm. Your sessions share every core that is left, and they are never squeezed onto fewer than one performance core no matter how high you set this — on a smaller CPU the reservation quietly lands lower than you asked. Only takes effect while the reserve setting is on. No effect on non-hybrid CPUs or non-Windows systems. |
| `romanianPilotEnabled` | toggle | `true \| false` | Adds Romanian (Română) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `routeInternalAiThroughGateway` | toggle | `true \| false` |  |
| `rssDigestDailyCostCapUsd` | number | `number 0.05..5` |  |
| `rssReaderFontSize` | select | `"sm" \| "md" \| "lg" \| "xl"` |  |
| `rssReaderWidth` | select | `"narrow" \| "medium" \| "wide" \| "full"` |  |
| `rssRetentionDays` | number | `integer 7..730` |  |
| `runawayCommandAutoStopEnabled` | toggle | `true \| false` | When on (the default), the runaway-command watch also stops a READ-ONLY search or listing on its own — only one that has run 20 minutes or more, is still busy, and is slowing the other agents, and at most two per check. Anything that writes, installs, builds or tests is never stopped without you. Turn it off to keep the inbox cards and their Stop button but stop nothing automatically. Synonyms: runaway command auto stop, stop runaway searches automatically, auto stop long searches, automatic command stop, stop slow read-only commands. |
| `runawayCommandWatchEnabled` | toggle | `true \| false` | When on (the default), Omniscio watches every command your agents are running and raises ONE inbox card with a Stop button when a search or listing has run 10 minutes or more and is still busy while the other agents slow, or when a command looks like an unbounded search — a build, test run, install or merge gate never gets it just for being busy. Stop ends only that command — the agent sees it fail and its session keeps running. Turn it off to stop the cards and the automatic stops entirely. Synonyms: runaway command watch, long running agent command, stop a stuck agent command, agent command slowing everything, has run minutes card. |
| `russianPilotEnabled` | toggle | `true \| false` | Adds Russian (Русский) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `scheduledMessagesSidebarEnabled` | toggle | `true \| false` |  |
| `scratchpadAutoDeleteEnabled` | toggle | `true \| false` |  |
| `scratchpadQuickCaptureHotkey` | unknown | `string (≤100) \| array of string (≤100)` | System-wide keyboard shortcut(s) that pop a small floating note box OVER whatever app you are using — a dedicated always-on-top capture window that never switches you to Omniscio. Type a note and press Ctrl+Enter or Escape to save and dismiss, returning to what you were doing. Distinct from the "Quick scratchpad" hotkey (Ctrl+Shift+S), which opens the rich in-app overlay and foregrounds the app. NO default binding (owner request 2026-08-25 — the rich Quick scratchpad on Ctrl+Shift+S is the only scratchpad, so this floating variant ships unbound); rebindable in Settings → Keyboard Shortcuts → System-wide. An empty list disables it. Synonyms: floating scratchpad capture, quick note over current app, floating quick-capture hotkey, jot a note without switching apps. |
| `scratchpadQuickCaptureHotkeyEnabled` | toggle | `true \| false` | Master on/off toggle for the Floating scratchpad capture system-wide hotkey. On by default, but the floating capture ships UNBOUND (no default key — the rich Quick scratchpad on Ctrl+Shift+S is the single scratchpad), so bind a key in scratchpadQuickCaptureHotkey first for anything to register. Off: the shortcut stops being registered system-wide even when bound. The companion field is scratchpadQuickCaptureHotkey. Synonyms: enable floating scratchpad capture, turn off floating capture shortcut, floating scratchpad global hotkey toggle. |
| `scratchpadRenderMarkdown` | toggle | `true \| false` |  |
| `scratchpadRetentionDays` | number | `integer 1..365` |  |
| `scratchpadWindowHotkey` | unknown | `string (≤100) \| array of string (≤100)` | System-wide keyboard shortcut(s) that open the rich Quick scratchpad overlay (the surface with the note list, pop-out, and settings) from any app, even when Omniscio is not the active window. Raises the app, then opens the overlay. Works while the app is running in the background. Default is Ctrl+Shift+S — the SINGLE scratchpad hotkey (owner request 2026-08-25); the stripped-down floating capture below was removed so there is one scratchpad. Rebindable in Settings → Keyboard Shortcuts → System-wide; an empty list disables it. Synonyms: quick scratchpad hotkey, global scratchpad shortcut, open scratchpad from anywhere, launch scratchpad. |
| `scratchpadWindowHotkeyEnabled` | toggle | `true \| false` | Master on/off toggle for the Quick scratchpad system-wide hotkey. On (default): the Ctrl+Shift+S shortcut (or whatever you rebound it to) opens the rich Quick scratchpad overlay from any app. Off: the shortcut stops being registered system-wide. The companion field is scratchpadWindowHotkey. Synonyms: enable scratchpad hotkey, turn off scratchpad shortcut, scratchpad global hotkey toggle. |
| `scratchpadsSidebarEnabled` | toggle | `true \| false` |  |
| `screenCapturePresets` | unknown | `catch` |  |
| `screenCaptureProjectsEnabled` | toggle | `true \| false` | In-development: a "Projects" tab in the Screen Capture library for multi-asset compositions: combine clips and snips from many captures into one timeline, instead of editing a single recording at a time. Hidden until shipped. |
| `screenCaptureTemplates` | unknown | `catch` |  |
| `screenRecorderAutoDndEnabled` | toggle | `true \| false` |  |
| `screenRecorderAutoShareOnStop` | toggle | `true \| false` |  |
| `screenRecorderAutoTitleEnabled` | toggle | `true \| false` | Auto-generate a title from the transcript (sends the recording's speech to Claude) after a recording finishes. Default ON — fires once, only when credentials are available and after local Whisper has produced a transcript. A manual sourceLabel always wins over the AI title. |
| `screenRecorderCaptionFontScale` | number | `number 0.5..2` |  |
| `screenRecorderCaptionPosition` | select | `"bottom" \| "top"` |  |
| `screenRecorderCaptionsEnabled` | toggle | `true \| false` |  |
| `screenRecorderClickRingColor` | text | `string` |  |
| `screenRecorderClickRingSizePx` | number | `integer 16..200` |  |
| `screenRecorderClickRingStyle` | select | `"outline" \| "filled" \| "pulse"` |  |
| `screenRecorderClickSoundEnabled` | toggle | `true \| false` |  |
| `screenRecorderCountdownEnabled` | toggle | `true \| false` |  |
| `screenRecorderCountdownSeconds` | number | `integer 0..10` |  |
| `screenRecorderDefaultCamId` | text | `string (≤200)` |  |
| `screenRecorderDefaultExpiry` | select | `"1day" \| "7days" \| "30days" \| "never"` |  |
| `screenRecorderDefaultMicId` | text | `string (≤200)` |  |
| `screenRecorderDefaultShareExpiry` | select | `"1day" \| "7days" \| "30days" \| "never"` |  |
| `screenRecorderDefaultSourceId` | text | `string (≤200)` |  |
| `screenRecorderDefaultSourceType` | select | `"screen" \| "window"` |  |
| `screenRecorderDefaultSystemAudio` | toggle | `true \| false` |  |
| `screenRecorderDefaultsConfigured` | toggle | `true \| false` |  |
| `screenRecorderDiscardRestartHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderForAgentEnabled` | toggle | `true \| false` | When on (default), the Record for Agent tools appear in the Screen Recorder: mark moments while you record, then send the finished recording to an agent to review with you. Settings → Screen Recording → "Record for Agent". Synonyms: record for agent, send recording to agent, mark moments while recording, review recording with agent. |
| `screenRecorderFrameRate` | number | `integer 15..60` |  |
| `screenRecorderGeminiVideoParseEnabled` | toggle | `true \| false` | Record for Agent — the OPTIONAL Gemini pass that WATCHES the recording, rather than reading a transcript plus stills. Default OFF, and off means byte-identical: the whole point of the existing path is that it works without sending anything anywhere new. Turning it ON sends the ENTIRE recording to Google — everything visible for the whole take, not just the moments you marked — where today a review sends Anthropic only a few cropped stills plus a locally-produced transcript. That is a materially different exposure, so the toggle's own copy says so at the point of enabling. It reuses the SAME `geminiApiKey` the session-spawn proxy uses, so a user who already configured Gemini needs no second credential; with no key the pass simply does not run and the send proceeds exactly as before. |
| `screenRecorderIntroCardEnabled` | toggle | `true \| false` |  |
| `screenRecorderIntroCardName` | text | `string (≤100)` |  |
| `screenRecorderLastCamId` | text | `string (≤200)` |  |
| `screenRecorderLastCanvasHeight` | number | `integer 1..7680` | Remembered output canvas HEIGHT in pixels from your last screen recording, used to seed the next Record composer output size. Null until you record once. Part of remember-my-setup. Synonyms: last canvas height, remembered output height, recording resolution height. |
| `screenRecorderLastCanvasWidth` | number | `integer 1..7680` | Remembered output canvas WIDTH in pixels from your last screen recording, used to seed the next Record composer output size. Null until you record once. Part of remember-my-setup. Synonyms: last canvas width, remembered output width, recording resolution width. |
| `screenRecorderLastLayoutPreset` | select | `"pip" \| "side-by-side" \| "grid" \| "freeform" \| "custom"` | Remembered composer layout preset ("pip" \| "side-by-side" \| "grid" \| "freeform" \| "custom") from your last screen recording, used to seed the next Record composer arrangement. Null until you record once. Part of remember-my-setup. Synonyms: last layout, remembered arrangement, picture-in-picture, side by side. |
| `screenRecorderLastMicId` | text | `string (≤200)` |  |
| `screenRecorderLastMicMuted` | toggle | `true \| false` | Remembered flag for whether the microphone was muted in your last screen recording, used to seed the next Record composer. Default false. Part of remember-my-setup. Synonyms: last mic muted, remembered microphone mute. |
| `screenRecorderLastSourceId` | text | `string (≤200)` |  |
| `screenRecorderLastSystemAudio` | toggle | `true \| false` | Remembered flag for whether system (computer) audio capture was on in your last screen recording, used to seed the next Record composer. Default false. Part of remember-my-setup. Synonyms: last system audio on, remembered computer audio capture. |
| `screenRecorderLastSystemAudioMuted` | toggle | `true \| false` | Remembered flag for whether the captured system audio was muted in your last screen recording, used to seed the next Record composer. Default false. Part of remember-my-setup. Synonyms: last system audio muted, remembered computer audio mute. |
| `screenRecorderLocalExportFolder` | text | `string (≤500)` |  |
| `screenRecorderMarkMomentHotkey` | unknown | `string (≤100) \| array of string (≤100)` | System-wide shortcut that marks the moment you are pointing at while a Record for Agent screen recording is running (default Ctrl+Shift+6 — deliberately NOT Ctrl+Shift+M, which is the show/hide-app shortcut and would lose the conflict). Because a global shortcut does not steal focus from the app you are in, this is the ONLY marking method that also captures the text of the field you were typing in — password fields are never captured. The note box and the draw-a-box overlay mark moments too, but they are Omniscio windows, so they take focus and capture no field text. Does nothing when no recording is running. Synonyms: mark a moment, flag this moment, record for agent hotkey, moment shortcut. |
| `screenRecorderMouseZoomEnabled` | toggle | `true \| false` |  |
| `screenRecorderPanicMuteHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderPauseHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderPickerHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderQuality` | select | `"economy" \| "balanced" \| "high" \| "studio"` |  |
| `screenRecorderQuickRecordHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderRetentionDays` | number | `integer 1..3650` |  |
| `screenRecorderRetentionMaxGb` | number | `number 1..10000` |  |
| `screenRecorderRetentionMode` | select | `"off" \| "age" \| "size"` |  |
| `screenRecorderShareWarningAcknowledged` | toggle | `true \| false` |  |
| `screenRecorderSnipCaptureEngine` | select | `"classic" \| "native"` |  |
| `screenRecorderSnipCaptureNotifications` | select | `"all" \| "errors" \| "off"` |  |
| `screenRecorderSnipCaptureSound` | toggle | `true \| false` |  |
| `screenRecorderSnipCopyOnly` | toggle | `true \| false` |  |
| `screenRecorderStartSoundEnabled` | toggle | `true \| false` |  |
| `screenRecorderStopHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `screenRecorderStorePath` | text | `string (≤500)` |  |
| `screenRecorderVadStrictness` | select | `"relaxed" \| "normal" \| "strict"` |  |
| `screenRecorderVideoCornerRadius` | number | `number 0..0.5` | How round the corners of a recorded video block are, for the "Rounded" video shape — a fraction of the block's shorter side, from 0 (a sharp square) to 0.5 (a fully rounded cap); 0.12 (about 12%) is the default. Has no effect on the "Square" or "Circle" shapes. Synonyms: corner radius, how round the corners, video roundness, rounded corners amount, corner softness. |
| `screenRecorderVideoShape` | select | `"rect" \| "rounded-rect" \| "circle"` | The shape of the recorded video block itself — "Rounded" (default), "Square", or "Circle". Applies to a plain screen/window recording (no camera), where the finished video is baked with that shape; a square keeps the recording exactly as it was before shapes existed. The corner softness of "Rounded" is set by the Video block corner radius setting. Synonyms: video shape, rounded video, round the recording, video corners, square video, circle video, rounded rectangle. |
| `screenRecorderWatermarkImagePath` | text | `string (≤500)` |  |
| `screenRecorderWatermarkMode` | select | `"off" \| "text" \| "image"` |  |
| `screenRecorderWatermarkPosition` | select | `"top-left" \| "top-right" \| "bottom-left" \| "bottom-right"` |  |
| `screenRecorderWatermarkText` | text | `string (≤100)` |  |
| `screenRecorderWebcamPreviewCorner` | select | `"top-left" \| "top-right" \| "bottom-left" \| "bottom-right"` | Screen corner ("top-left" \| "top-right" \| "bottom-left" \| "bottom-right", default "bottom-right") the floating LIVE webcam self-view preview docks into WHILE recording. Controls only the on-screen preview overlay, never the webcam in the final video. Synonyms: webcam preview position, self-view corner, live camera pill corner. |
| `screenRecorderWebcamPreviewSize` | select | `"small" \| "medium" \| "large"` | Size ("small" \| "medium" \| "large", default "medium") of the floating LIVE webcam self-view preview shown on-screen WHILE recording so you can tell you are in frame. Controls only the on-screen preview overlay, never the webcam composited into the final video. Synonyms: webcam preview size, self-view size, live camera pill size. |
| `screenRecorderWebcamShape` | select | `"circle" \| "rounded-square" \| "fullbleed"` |  |
| `screenshotOcrEnabled` | toggle | `true \| false` |  |
| `screenshotOcrModel` | text | `string (≤120)` |  |
| `screenshotSnipHotkey` | text | `string (≤100)` |  |
| `secretHandleEnabled` | toggle | `true \| false` | Intercepts clipboard pastes that appear to contain secrets (API keys, tokens, passwords) before they reach a spawned agent session, storing them under an opaque handle so the raw value stays out of your saved history. Off by default; turn it on in Settings → Features. |
| `selfServeWorkspacesEnabled` | toggle | `true \| false` | Create your own workspace, switch between the workspaces you belong to, and see the plan pricing, all from the User Management header. |
| `semanticSearchEnabled` | toggle | `true \| false` |  |
| `senderRunCardsEnabled` | toggle | `true \| false` | When several messages land back to back — a burst of gate results, a run of machine wake-ups, a coordinator's inbox — the conversation shows ONE quiet line naming how many and who from, which opens to a single swipeable card deck instead of a stack of bubbles. Every message is still there and readable in full. On by default; you can turn it off anytime. |
| `sentryTriageAiDailyCapUsd` | number | `number 0..100` |  |
| `sentryTriageAiSecondLookEnabled` | toggle | `true \| false` |  |
| `sentryTriageAutoPromoteEventCount` | number | `integer 0..1000000` |  |
| `sentryTriageAutoSpawnMinLevel` | select | `"fatal" \| "error" \| "warning" \| "info" \| "debug"` |  |
| `sentryTriageConsolidateByClass` | toggle | `true \| false` |  |
| `sentryTriageEnabled` | toggle | `true \| false` |  |
| `serbianPilotEnabled` | toggle | `true \| false` | Adds Serbian (Српски, Cyrillic script) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `sessionBadgeMode` | select | `"all" \| "unread"` | Controls whether badge-read-acknowledged sessions still count in the project badge. 'all' = current behavior (every needs_you counts), 'unread' = only unacknowledged sessions count (mark-as-read support). |
| `sessionFilesLinksEnabled` | toggle | `true \| false` | In-development: a per-session "Files & Links" panel, opened from a button in the session header, listing every file the agent created or edited in that conversation and every link it handed you — newest first, deduplicated, and clickable. Files come from the session's CLI transcript; links come from its saved messages, so links work on every engine. Read-only and worked out on demand — it stores nothing. Deliberately available on mobile too, where there is no other way to reach a session's files. Off by default; hidden until shipped. |
| `sessionForensicsEnabled` | toggle | `true \| false` | A developer-tools panel that mines your past agent sessions for friction patterns — command timeouts, hook blocks, tool errors, redundant directory changes, and spend concentration — via a free periodic scan. An opt-in WEEKLY deep run spawns a paid AI session to produce a full analysis report with ranked fixes. |
| `sessionForensicsSidebarEnabled` | toggle | `true \| false` |  |
| `sessionHandoffEnabled` | toggle | `true \| false` | Roll a long session over into a fresh one that is already caught up — a "Hand off to a fresh session…" item in the session ⋯ menu, plus a one-per-session in-chat note once a chat has used a lot of context, and the same actionable note at a context give-up. The note never spends; only confirming the handoff pays for the one summary call. |
| `sessionHealthMonitorEnabled` | toggle | `true \| false` | In-development: detect sessions stalled mid-task, classify via LLM, and auto-recover with context-aware nudges. Hidden until shipped. |
| `sessionHealthMonitorSkipPipelineComplete` | toggle | `true \| false` |  |
| `sessionIoPriorityUserHarmGateEnabled` | toggle | `true \| false` |  |
| `sessionMenuCustomizationEnabled` | toggle | `true \| false` | In-development: lets each user reorder the items in a session's ⋯ (more actions) menu and hide the ones they don't use — from a drag-to-reorder list in Settings → Sessions and by right-clicking a row in the menu itself. Off by default; hidden until shipped. |
| `sessionMenuHidden` | list | `array of string (≤64)` | Which entries are hidden from a session's ⋯ overflow menu, by entry id. Edit the list in Settings → Sessions → session menu customization; ships with a curated default set of hidden entries. |
| `sessionMenuOrder` | list | `array of string (≤64)` | Your custom display order for entries in a session's ⋯ overflow menu, by entry id. Empty (the default) uses the built-in order. Edit it in Settings → Sessions → session menu customization. |
| `sessionNamingMode` | select | `"ai_title" \| "first_prompt" \| "session_number"` |  |
| `sessionRefillDailyMaxRevives` | number | `integer 1..5000` | Session Refill Governor — hard backstop on the number of sessions it may revive per local day regardless of cost, bounding absolute worst-case spend. Default 200 (range 1–5000). Synonyms: daily revive cap, refill max revives per day, session refill daily ceiling. |
| `sessionRefillEnabled` | toggle | `true \| false` | In-development: a per-user background governor that keeps X sessions running — when the live running count drops below your target it revives recently-active interrupted work sessions back up to X every ~5 minutes. Reuses the existing revive + spawn-pacing path; bounded by a per-tick batch cap, per-session cooldown, a restart-safe daily $ ceiling, and a daily revive-count backstop. It spends money autonomously and is cost-capped. Off by default; hidden until shipped. |
| `sessionRefillExcludeNamePatterns` | list | `array of string (≤200)` | Session Refill Governor — case-insensitive regex name patterns that EXCLUDE a session from revival, so generic shells and outward-facing intake are never brought back. Defaults exclude names like "^Session 1", "[BUG]", "[FEEDBACK]", "Email:", and "Tweet:". Synonyms: exclude session names, never revive these, refill exclusion patterns, don't revive. |
| `sessionRefillIncludeProjectNamePatterns` | list | `array of string (≤200)` | Which projects the Session Refill governor is allowed to restart sessions in, as a list of case-insensitive patterns matched against the project name. Empty (the shipped default) means every project. Once you set it the list FAILS CLOSED: a session must match one of your patterns or it is left alone — so a renamed project, or a list whose patterns are all invalid, restarts nothing rather than quietly widening back to everything. It exists because the governor previously had no notion of a project at all and would pick up whatever happened to be interrupted, across every project at once. Synonyms: limit session refill to a project, which projects can be auto-restarted, session refill project allow list, restrict the refill governor by project name, only revive sessions in these projects. |
| `sessionRefillNudgeText` | text | `string (≤2000)` | Session Refill Governor — the "continue" message sent to a revived session, e.g. "Please continue where you left off and finish the task." (default). Synonyms: revive nudge text, continue prompt, refill message. |
| `sessionSearchSidebarEnabled` | toggle | `true \| false` |  |
| `sessionSelfArchiveEnabled` | toggle | `true \| false` | Master switch for session self-archiving. On (default): a finished agent session may archive itself off your board once it decides nothing is left for you to see, decide, or receive (it emits a self-archive marker at the end of its turn). Off: that marker is ignored and every session stays on your board until you archive it yourself. This kill-switch overrides sessionSelfArchiveWithoutApproval. |
| `sessionTagsEnabled` | toggle | `true \| false` |  |
| `sessionTitleAppendPrompt` | text | `string (≤10000)` | Free-form text describing how AI-generated session titles should be written, appended BELOW the built-in title prompt (whose rules always win) for EVERY project. A per-project `Project.sessionTitleAppendPrompt` stacks AFTER this, so the narrower scope wins a conflict. Only consulted in `ai_title` naming mode — the other modes never call the model. `''` = none, and empty at both levels reproduces pre-feature titling byte-for-byte. |
| `sessionTitleCustomPrompt` | text | `string (≤10000)` | User-written prompt that replaces the built-in title prompt when `sessionTitleStyle === 'custom'`. Ignored for other styles. |
| `sessionTitleCustomRefresh` | toggle | `true \| false` |  |
| `sessionTitleStylesEnabled` | toggle | `true \| false` | Choose how AI-generated session titles are written with five presets (Brief, Descriptive, Journey, Latest Topic, Custom). Journey and Latest Topic auto-refresh as the conversation evolves. Off by default; hidden until shipped. |
| `sessionTrajectoryEnabled` | toggle | `true \| false` | In-development: a per-session "Trajectory" view (a new option in a session's view switch, beside All / Agent / You / Events) that shows what the agent did — an ordered list of turns and tool-call steps, a turn-level activity timeline, and a metrics strip (turns, tool calls, tokens, cost, duration). Reads data already stored for every engine, so it works for all harnesses. Read-only; off by default; hidden until shipped. |
| `sessionsSidebarWidth` | number | `integer 180..500` |  |
| `settingsDrilldownNavEnabled` | toggle | `true \| false` | Reorganizes Settings into a multi-level drill-down — pick a category, then a page, instead of one long list. It also enables the room grouping. |
| `settingsQuickPresetsEnabled` | toggle | `true \| false` | In-development: a "Quick setup" card on the Settings Home page offering three one-click presets (Minimal, Balanced, Power user) that each apply a batch of benign settings in one action and show which preset is currently active. Off by default; hidden until shipped. |
| `settingsRedesignEnabled` | toggle | `true \| false` | The settings redesign: per-page tab strips (Appearance / Sessions / Voice) with aggressive Basic/Advanced splitting and live previews. Shipped — on by default for everyone; the enable/disable toggle is retired. The settingKey is kept only so older persisted configs still parse; visibility no longer reads it (a shipped feature is always on). Quick-setup presets remain a separate in-development feature. |
| `settingsSidebarEnabled` | toggle | `true \| false` |  |
| `setupBackupConsecutiveFailures` | number | `integer 0..10000` | Consecutive failure count since last successful send. Resets to 0 on success. |
| `setupBackupEnabled` | toggle | `true \| false` | Setup-backup feature flag. Default: false. |
| `setupExitedAt` | text | `string` | The timestamp (ISO 8601) of when you last exited first-run setup without finishing it — the onboarding "exit" marker. When set, onboarding does NOT auto-reopen on the next launch; instead the "Finish setting up" inbox reminder nudges you to complete setup. Unset (undefined) until you have exited setup early at least once. Distinct from setupV2CompletedAt (a genuinely finished setup). Internal remembered state, not a user-facing toggle. Synonyms: setup exited at, skipped setup time, first-run exit timestamp, exited onboarding. |
| `setupV2CompletedAt` | text | `string` |  |
| `setupV2Enabled` | toggle | `true \| false` | In-development: the redesigned cinematic first-run "Setup" flow — a keyboard-driven, step-sidebar shell (Light/Dark → sign in → API key → install essentials → permissions → autonomy → your look). Preview it any time from Settings → Setup Wizards. This entry is the preview toggle for the shell; whether a brand-new install is routed into it is the separate "Setup v2 live first-run onboarding" entry. |
| `setupV2OnboardingEnabled` | toggle | `true \| false` | Setup v2 is the live first-run onboarding (replaces the legacy wizard): new users are routed into the cinematic Setup v2 shell instead of the legacy onboarding wizard. On by default for every new install; the toggle stays live so it reverts with one setting flip. |
| `shareCommentsEnabled` | toggle | `true \| false` | Commenting and feedback on shared artifacts. Viewers can leave inline or general comments, which cross-post to Team Chat and the inbox. |
| `sharedNodeModulesEnabled` | toggle | `true \| false` | In-development: point a new worktree's node_modules at a single shared base via one junction instead of copying every dependency file, cutting a worktree's file count by about 89% — so worktrees create and delete faster and churn far less disk. Hidden until shipped. |
| `sharedSessionRequireTurnApproval` | toggle | `true \| false` |  |
| `sharesSidebarEnabled` | toggle | `true \| false` |  |
| `showComposerAttachButton` | toggle | `true \| false` |  |
| `showComposerQuickRepliesButton` | toggle | `true \| false` |  |
| `showEndedSessions` | toggle | `true \| false` |  |
| `showHotkeyWhisper` | toggle | `true \| false` |  |
| `showOnlyActiveProjects` | toggle | `true \| false` |  |
| `showScreenshotButton` | toggle | `true \| false` |  |
| `showSelfHealNotices` | toggle | `true \| false` |  |
| `sidebarDriftColorsEnabled` | toggle | `true \| false` | When on (the default), the sidebar drift chip colours its numbers by severity, so a metric past its warn or critical threshold is coloured to match. Turn it off and the chip still reports every drift number — it just renders in one neutral colour, for when the colour shift reads as noise and you want the numbers without the alarm. Synonyms: sidebar drift colours, colour the drift chip, drift warning colours, turn off drift colouring, sidebar version drift severity colours. |
| `sidebarDriftLevels` | object | `object { appAhead: object { critical: integer 0..1000000; warn: integer 0..1000000 }; appBehind: object { critical: integer 0..1000000; warn: integer 0..1000000 }; queueAgeMinutes: object { critical: integer 0..1000000; warn: integer 0..1000000 }; queueDepth: object { critical: integer 0..1000000; warn: integer 0..1000000 }; remoteAhead: object { critical: integer 0..1000000; warn: integer 0..1000000 }; remoteBehind: object { critical: integer 0..1000000; warn: integer 0..1000000 } }` | The warn and critical thresholds the sidebar drift chip colours against, one pair per metric. Every value is a COUNT except queueAgeMinutes, which is in MINUTES. Raise a threshold to make that metric look calmer, lower it to flag drift sooner. Ships with defaults for every metric, so you only need to set the ones you care about. Synonyms: sidebar drift thresholds, drift warn levels, drift critical levels, when does drift go red, tune the drift warning thresholds. |
| `sidebarGroupOrder` | list | `array of string (≤64)` |  |
| `sidebarRarelyUsedCollapsed` | toggle | `true \| false` |  |
| `sidebarSortByUsageEnabled` | toggle | `true \| false` |  |
| `sidebarUngroupedItems` | list | `array of string (≤64)` |  |
| `sidebarUsageWindowDays` | number | `integer 1..365` |  |
| `simpleModeEnabled` | toggle | `true \| false` | In-development: a friendly Chief of Staff mode — one plain-language chatbox that runs the app for you, so you can set reminders, save notes, check your inbox, and get things done without the full cockpit. Off by default; hidden until shipped. |
| `simpleModeFullView` | toggle | `true \| false` | While you are opted into Simple Mode, which view you are looking at: false (default) = the Simple Mode chatbox (the friendly concierge takeover), true = the normal full Omniscio app. Flipped by the Full <-> Simple switch in the header (and by the Simple Mode hotkey / command bus), NOT a Settings toggle — turning Simple Mode on still enters the Simple view by default, and switching to Full keeps you opted in so the header switch stays available to jump back. Synonyms: simple mode view, which simple mode view, switch to the full app, back to simple mode, full vs simple view, simple mode header switch, am I in simple or full view. |
| `simplifiedChinesePilotEnabled` | toggle | `true \| false` | Adds Simplified Chinese (简体中文) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `skillsTrustedSourceAcknowledged` | toggle | `true \| false` |  |
| `slackImportEnabled` | toggle | `true \| false` | In-development: import channels, messages, threads, reactions, pins, and recent files from a Slack workspace into Team Chat. Runs as a guided wizard that maps Slack users to existing accounts and writes to your active workspace via a secure Cloud Function. |
| `smartShareReaperEnabled` | toggle | `true \| false` | Finds "never expires" shares and screen recordings that are over a year old and unviewed, gives each a 90-day grace expiry, and drops one inbox card asking you to Keep or delete it. |
| `smsNotificationsEnabled` | toggle | `true \| false` |  |
| `snoozeSmartOrderEnabled` | toggle | `true \| false` | In development: drop the snooze durations you never pick from the menu (after about a month), keeping the rest in the standard order. Off shows the full list. |
| `spamFilterCalendarAiEnabled` | toggle | `true \| false` |  |
| `spamFilterGmailAiEnabled` | toggle | `true \| false` |  |
| `spamFilterGmailEnabled` | toggle | `true \| false` |  |
| `spamFilterSmsAiEnabled` | toggle | `true \| false` |  |
| `spamFilterUiVisible` | toggle | `true \| false` | In-development: an automatic spam filter for texts, calendar invites and your agent's email. Strangers' messages are checked, junk waits in the Inbox's Spam view, and one click brings a message back. Revealing it adds the Spam view and the Inbox → Spam settings; filtering itself stays off until you turn it on there. |
| `spanishPilotEnabled` | toggle | `true \| false` | Adds Spanish (Español) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `spawnOomHoldEnabled` | toggle | `true \| false` |  |
| `spawnPacerUserHarmGateEnabled` | toggle | `true \| false` |  |
| `staleBranchRetireAskEnabled` | toggle | `true \| false` |  |
| `stallThresholdSeconds` | number | `integer 30..3600` |  |
| `statsSidebarEnabled` | toggle | `true \| false` |  |
| `stickyNotesOverlayOpen` | toggle | `true \| false` | Remembered open/closed state of the Sticky Notes overlay, persisted to config.json so the overlay reopens (or stays closed) after a hard reload or app restart — the durable backstop to the instant localStorage flag the overlay reads on first paint. Written automatically whenever you open or close the overlay; it is not a Settings-UI toggle (the on/off feature switch is stickyNotesEnabled). Optional — undefined until you first open or close the overlay. Synonyms: keep sticky notes open after restart, remember sticky notes overlay visibility, sticky notes stay open, persist sticky notes open state. |
| `storyboardWorkflowEnabled` | toggle | `true \| false` | AI-powered storyboard generation from a written script. Breaks a script into scenes with camera angle suggestions, character/location metadata, and reference image slots for pre-production visualization. Off by default; hidden until shipped. |
| `streamingThrottleMs` | number | `integer 16..200` |  |
| `stripeCreditTopupsEnabled` | toggle | `true \| false` | Buy gateway AI credit with a card via Stripe checkout. |
| `sttDailyCapUSD` | number | `number 0..100` |  |
| `stuckTaskHelperEnabled` | toggle | `true \| false` | In-development: notices when you keep snoozing the same session, email, PR, or message and — after the 3rd time — offers a dismissible inbox nudge to start an AI session that interviews you about the resistance and helps you take a tiny first step. |
| `submitKeyMode` | select | `"enter" \| "ctrl_enter"` |  |
| `superPromptCreatorSidebarEnabled` | toggle | `true \| false` | Shows or hides the Super Prompt Creator entry in the sidebar — the prompt-tools helper for building a reusable "super prompt". One of the per-section sidebar visibility toggles; on by default, turn it off to remove it from the sidebar. Synonyms: super prompt creator sidebar, show/hide prompt builder. |
| `superPromptPublicLinkConfirmDismissed` | toggle | `true \| false` | "Don't ask again" dismissal for the "Create a public link?" confirmation shown before a Super Prompt's "Copy link" publishes it to a public Shares page. When true, Copy link publishes + copies with no confirmation. Default false. |
| `superPromptsSidebarEnabled` | toggle | `true \| false` | Shows or hides the Super Prompts entry in the sidebar — your library of saved, reusable "super prompt" templates. One of the per-section sidebar visibility toggles; on by default, turn it off to remove Super Prompts from the sidebar. Synonyms: super prompts sidebar, show/hide saved prompts library, prompt templates panel. |
| `supermailAiFilter` | map | `map of string → object { enabled: true \| false; instruction: string (≤8000); mode: "preview" \| "live" }` | Supermail — per-identity AI Filtering settings, keyed by the signed-in identity (or "anon"): an enable override (inherit / force on / force off), a mode (preview / live), and an instruction. An empty or absent entry inherits the global AI-filter toggle. Controls how the AI filter runs per account when reading and triaging email. Synonyms: AI filter per account, triage AI instruction, per-identity filter override. |
| `supermailAiFilterEnabled` | toggle | `true \| false` | In-development: let AI read each new email in Supermail and triage it against a plain-language instruction you write — keeping, archiving, labeling, marking read, or starring it. Starts in preview mode (shows what it would do without touching anything) until you switch it to live; it never trashes mail, and it is cost-capped. Off by default. |
| `supermailAiSummaryEnabled` | toggle | `true \| false` | In-development: a "Catch me up" AI summary in Supermail that reads an open conversation and summarizes it in two parts — what the thread has been about so far, then what the most recent email says. You choose whether it runs on a button or automatically when a thread opens, and you can edit the prompt it uses. Off by default, and cost-capped. |
| `supermailArchiveInsightsDwell` | toggle | `true \| false` | The more sensitive Archive Insights dwell switch: whether Supermail may record how long each email was open before you archived it, to improve its insights. On by default. Turn it off to stop dwell-time tracking while keeping the rest of Archive Insights. Synonyms: dwell tracking, time-spent tracking, how long an email was open. |
| `supermailArchiveInsightsEnabled` | toggle | `true \| false` | Master switch for Supermail Archive Insights tracking: whether Supermail records your archive behaviour at all to power its insights. On by default. Turning it off disables the whole feature. Synonyms: archive insights, archive tracking, track what I archive. |
| `supermailArchiveInsightsSuggestFilters` | toggle | `true \| false` | The Archive Insights proactive-nudge switch: whether Supermail may surface a "create a filter" toast when it notices you repeatedly archiving similar mail. On by default and independent of the master Archive Insights switch. Synonyms: suggest filters, create-a-filter nudge, archive filter suggestions. |
| `supermailContactGroups` | map | `map of string → array of object { id: string (≤80); members: array of object { email: string (≤320); name: string (≤200) }; name: string (≤200); source: "local" }` | Supermail — your own device-local contact GROUPS, keyed by the signed-in account (or "anon" when signed out). Each group has an id, name, and member emails. Per-account privacy is an invariant: a group made under one account never surfaces under another. Written by the contact-groups store; no Settings-UI control. Synonyms: contact groups, supermail groups, email contact lists. |
| `supermailContactGroupsEnabled` | toggle | `true \| false` | In-development: name a reusable group of people once, then drop it into a Supermail recipient field (To/Cc/Bcc) to address everyone at once. Reads your existing Google Contacts groups (read-only) and lets you make quick device-local groups in the app; picking a group fills in each person as an individual, removable recipient. Off by default. |
| `supermailContactPaneVisible` | toggle | `true \| false` | Whether the right-hand contact rail (the contact's photo, role, and recent emails) is shown beside an open Supermail conversation. Opt-in and off by default. Turn it on with the Settings "Contact pane" toggle or the Show/Hide Contact Pane command. Synonyms: contact pane, sender details panel, people pane, contact rail. |
| `supermailHoverActEnabled` | toggle | `true \| false` | Act on the hovered conversation with keyboard shortcuts in Supermail. On by default: moving the mouse onto a thread row moves the keyboard cursor to it, so the one-key shortcuts (e = Done, # = Trash, s = Star, u = Unread, and the rest) act on whatever is under the pointer with no click or select first. It moves the cursor only and never opens the reading pane (that still needs a click or Enter). Off restores hover to prefetch-only, so the cursor moves only via click and j/k. Synonyms: hover to act, act on hover, hover keyboard cursor, hover selection. |
| `supermailLeftHandedNav` | toggle | `true \| false` | Left-handed inbox navigation in Supermail. When on, the inbox list can be driven with the left hand: W moves up and S moves down, mirroring the default K/J and arrow keys onto the WASD region. Because S then means down, the one-key Star action relocates to D while this mode is on. Off by default (opt-in). Note that the app-wide one-handed keyboard preset (Settings, Keybindings) forces this on regardless. Synonyms: left-handed mode, one-handed nav, WASD navigation, left hand keyboard. |
| `supermailNavHidden` | toggle | `true \| false` | Whether the Supermail navigation sidebar is unpinned. When true (the Superhuman-style default), the persistent sidebar slot is empty and the nav is reached through a hamburger that opens an overlay drawer. When false, the sidebar is pinned permanently in the sub-sidebar slot ("Show sidebar" on). The Settings "Show sidebar" toggle is the inverse of this value. Synonyms: hide sidebar, show sidebar, pin the nav, hamburger nav, collapse navigation, folders and labels rail. |
| `supermailNotificationPrefs` | object | `object { desktopEnabled: true \| false; filter: "all" \| "important" \| "vip" \| "off"; quietHoursEnabled: true \| false; quietHoursEnd: string (≤64); quietHoursStart: string (≤64); timezone: string (≤128) }` | A read-only mirror of the notification preferences held by your Supermail account: whether desktop notifications are on, which mail notifies you (all / important / VIP / off), and the quiet-hours window with its timezone. The Supermail server stays the source of truth — you change these on the Supermail notifications page, and Omniscio copies them here so its own notification producers stop pinging you about mail you have muted. Empty until that page is first opened, which reads as the account defaults (desktop notifications on, all mail, no quiet hours). Synonyms: supermail notification preferences, mute supermail notifications, quiet hours, which mail notifies me, supermail desktop notifications, VIP notifications, notification filter. |
| `supermailOmniscioGrantEnabled` | toggle | `true \| false` | In-development: when you Connect Google, also register an email-only Google consent with the Supermail backend so unified sign-in works fully without a second full sign-in. A precondition for moving Supermail into the Omniscio cloud. Headless and off by default; it needs the backend deploy configured before it does anything. |
| `supermailReadingLayout` | select | `"standard" \| "centered" \| "editorial"` | The reading-column personality for an open Supermail email: "standard" (the default, full width), "centered" (a centered column), or "editorial" (a narrower editorial measure). A pure display preference. It is deliberately not a colour or theme setting, since Supermail follows the active app theme automatically. Synonyms: reading layout, email column width, centered reading, editorial layout, reading pane personality. |
| `supermailReadingPaneVisible` | toggle | `true \| false` | Whether every Supermail thread-list page (Inbox, labels, Snoozed, Follow-ups) renders as two panes, the list plus a reading pane (true, the default), or as a single full-width list where clicking a row opens the thread on its own page (false). Synonyms: reading pane, preview pane, split view, two-pane inbox, single-column list. |
| `supermailRowHoverActions` | toggle | `true \| false` | Master on/off for the per-row hover action strip (Mark Done and Remind Me) shown at the right of each dense Supermail inbox row. On by default. When off, the strip never renders on any row: the row keeps its metadata (the relative time still shows on hover) and the E / H keyboard shortcuts still work. The finer-grained toolbar-button controls still apply on top of this. Synonyms: row hover buttons, inbox row quick actions, hover action strip, mark done and remind me buttons. |
| `supermailSplitInboxEnabled` | toggle | `true \| false` | Master switch for Supermail's Split Inbox. Off by default: the inbox is a single unified list with no split scoping and no tab strip, while your configured splits stay saved on the backend and return the instant this is turned back on. On: the inbox splits into its configured lanes and tabs. Synonyms: split inbox, inbox tabs, inbox sections, unified vs split inbox, inbox lanes. |
| `supermailSubjectWarningEnabled` | toggle | `true \| false` | Warn before sending or scheduling a Supermail email that has no subject line, via the "Send without a subject?" confirmation. On by default as a light safety net. When off, a blank-subject email goes out immediately with no prompt. Synonyms: empty subject warning, missing subject prompt, no-subject confirmation, send without a subject. |
| `supermailToolbarDone` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's Done (Archive) toolbar button: "shown" (visible and its shortcut and command work, the default), "keyboard" (hidden but the shortcut and command still work), or "off" (hidden and disabled). Synonyms: done button, archive button, mark done, hide done, done toolbar control. |
| `supermailToolbarFilter` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's "Filter like these" toolbar button: "shown" (visible and its shortcut and command work, the default), "keyboard" (hidden but the shortcut and command still work), or "off" (hidden and disabled). Synonyms: filter button, filter like these, hide filter, filter toolbar control. |
| `supermailToolbarFocus` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's Focus-mode toolbar button, the reading-view focus toggle: "shown" (visible and its shortcut and command work, the default), "keyboard" (hidden but the shortcut and command still work), or "off" (hidden and disabled). Synonyms: focus button, focus mode toggle, hide focus, focus toolbar control. |
| `supermailToolbarReply` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's Reply toolbar button: "shown" (button visible and its keyboard shortcut and Ctrl+K command work, the default), "keyboard" (button hidden but the shortcut and command still work), or "off" (button hidden and its shortcut and command disabled). Synonyms: reply button, hide reply, reply toolbar control. |
| `supermailToolbarSnooze` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's Snooze (Remind me) toolbar button: "shown" (visible and its shortcut and command work, the default), "keyboard" (hidden but the shortcut and command still work), or "off" (hidden and disabled). Synonyms: snooze button, remind me, hide snooze, snooze toolbar control. |
| `supermailToolbarStar` | select | `"shown" \| "keyboard" \| "off"` | Visibility of Supermail's Star toolbar button: "shown" (visible and its shortcut and command work, the default), "keyboard" (hidden but the shortcut and command still work), or "off" (hidden and disabled). Synonyms: star button, hide star, star toolbar control. |
| `supermailTriageActionOrder` | list | `array of string (≤40)` | Supermail — the ordered list of enabled reading-pane triage-action ids for the customizable triage bar (the default out-of-the-box 8-button bar: done, snooze, follow-up, mark-unread, label, trash, previous, next). Empty [] is a real empty-bar state. Controls the order (and set) of the triage buttons you see when reading an email. Synonyms: triage bar order, triage actions, reading pane buttons, supermail action bar. |
| `supermailUndoToastEnabled` | toggle | `true \| false` | Show the Undo toast (the bottom-left snackbar) after a Supermail triage action such as Mark done, Trash, Snooze, or Spam. On by default: the toast is both the confirmation and the one-click Undo. When off, those actions apply silently, but Z / Ctrl+Z still reverses the last one within the usual 10-second window (the toast is only the visual, not the undo ability). Synonyms: undo toast, undo snackbar, undo bar, undo after archive, hide the undo popup. |
| `supermailVideoSummariesEnabled` | toggle | `true \| false` | In-development: auto-detects Loom and Vimeo links in a Supermail message, pulls the video transcript (auto-transcribing the audio when no captions exist), and shows a short AI summary card in the message detail when you click into the message. Off by default, and cost-capped. |
| `supermailWindowHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `supermailWindowHotkeyEnabled` | toggle | `true \| false` |  |
| `superpowersMigrationNudgedAt` | text | `string` |  |
| `swahiliPilotEnabled` | toggle | `true \| false` | Adds Swahili (Kiswahili) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `swarmDefaultDailyBudgetUsd` | number | `number 1..500` | The default daily USD spend cap copied onto a new Swarm slot when you don't set one of your own (default $10; range $1-500). Once a slot has its own daily budget, that value — not this default — is what the tick loop checks against spend. Synonyms: swarm daily budget, default swarm spend cap, swarm budget default. |
| `swarmDefaultWorkerCap` | number | `integer 1..10` | The default maximum worker count copied onto a new Swarm slot when you don't set one of your own (default 3; range 1-10). Once a slot has its own worker cap, that value — not this default — is what's checked live each tick before spawning another worker. Synonyms: swarm worker cap, default max workers, swarm worker limit. |
| `swarmEnabled` | toggle | `true \| false` | In-development: give a goal to a lead agent that spawns and coordinates a pool of worker sessions, communicates via a per-swarm message board, and is capped by a per-swarm daily dollar budget and worker limit — it spawns paid sessions and is cost-capped. Off by default; hidden until shipped. |
| `swarmMaxConsecutiveFailures` | number | `integer 2..20` | How many consecutive worker failures a Swarm slot tolerates before the tick loop auto-pauses it, rather than letting it keep spawning failing workers (default 3; range 2-20). Checked live every tick; applies to every slot (no per-slot override). Synonyms: swarm failure limit, auto-pause swarm, consecutive failure kill-switch. |
| `swarmSlots` | map | `map of string → object { dailyBudgetUsd: number 0..500; goal: string (≤4000); goalDone: true \| false; name: string (≤80); orchestrationFailures: integer 0..100; paused: true \| false; pausedReason: string (≤500); projectId: string; retryAfter: string; workerCap: integer 1..10 }` | Your active Swarm slots — one entry per swarm, holding its goal, worker cap, daily budget, project, and pause/done state. Created from the Swarm panel's "Create" form; this key IS the swarm store the tick loop reads every cycle to run each one, not a toggle you flip directly. Synonyms: swarm list, active swarms, swarm database, my swarms. |
| `swarmWorkerDeadlineMinutes` | number | `integer 5..240` | How many minutes of inactivity mark a live Swarm worker as stuck and owed a reap/retro (default 45; range 5-240). Checked live every tick against each worker's last-active timestamp; the swarm lead is exempt. Synonyms: swarm worker timeout, stuck worker deadline, swarm inactivity limit. |
| `syncSkillsToClaudeCode` | toggle | `true \| false` |  |
| `tagalogPilotEnabled` | toggle | `true \| false` | Adds Tagalog to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `tasksSidebarEnabled` | toggle | `true \| false` |  |
| `tasksV2AiDailyCapUsd` | number | `number 0..∞` |  |
| `tasksV2ArrangeAiEnabled` | toggle | `true \| false` | When on (the default), Arrange on the Tasks Today view asks an AI model to put your day in order and to mark which tasks an agent could do for you. Turn it off to keep Arrange free: it then uses the simple built-in order (your check-in focus first, then tasks due soon), with no AI call and no cost. Synonyms: AI arrange, arrange my day, plan my day with AI, smart ordering, Today ranking. |
| `tasksV2ArrangeDailyCapUsd` | number | `number 0..∞` |  |
| `tasksV2BreakdownNudgesEnabled` | toggle | `true \| false` |  |
| `tasksV2CatchesProjectIds` | list | `array of string` |  |
| `tasksV2CaughtColor` | text | `string` | An accent-colour override for the built-in Caught view in Tasks (the triage view for tasks captured from elsewhere), so you can tell it apart from your own lists. Null (the default) uses the standard theme colour. Synonyms: caught view colour, caught accent, recolour the caught view, tint caught. |
| `tasksV2CaughtIcon` | text | `string` | An icon override for the built-in Caught view in Tasks, by Lucide icon name. Null (the default) renders the standard Caught glyph. Synonyms: caught view icon, caught glyph, change the caught icon. |
| `tasksV2CaughtName` | text | `string` | A custom display name for the built-in Caught view in Tasks. An empty string (the default) uses the translated 'Caught' label. Synonyms: caught view name, rename caught, caught view label, what the caught view is called. |
| `tasksV2CheckinHour` | number | `integer 0..23` |  |
| `tasksV2CloseoutAutoOpenEnabled` | toggle | `true \| false` |  |
| `tasksV2CollapsedProjectIds` | list | `array of string` |  |
| `tasksV2CollapsedTaskIds` | list | `array of string` |  |
| `tasksV2DailyCheckinEnabled` | toggle | `true \| false` |  |
| `tasksV2DelegationEnabled` | toggle | `true \| false` | In-development: hand a Tasks task to a background AI agent that drafts it and stops for your review, surfaced as a per-task delegation chip plus a draft-review modal. Hidden until shipped. |
| `tasksV2Enabled` | toggle | `true \| false` | In-development parallel task system: a keyboard outliner whose rows render as real markdown. Hidden until shipped. |
| `tasksV2InboxTriageEnabled` | toggle | `true \| false` | When on (the default), you can start an AI session that sorts the unsorted tasks waiting in your Tasks inbox into lists, following your organizing preferences — offered once more than 10 are waiting. Turn it off and that sorting session cannot be started. Nothing is sorted unless you start it. Synonyms: inbox triage, sort my inbox, auto-sort tasks, unsorted tasks, clean up the task inbox. |
| `tasksV2InterviewEnabled` | toggle | `true \| false` |  |
| `tasksV2PlanMyDayEnabled` | toggle | `true \| false` |  |
| `tasksV2RailCollapsed` | toggle | `true \| false` | Whether the Tasks view's side rail is collapsed (default expanded/false). Toggled from the collapse button or the reopen strip on the Tasks view; a remembered layout state, not a Settings-page toggle. |
| `tasksV2RailWidth` | number | `integer 180..500` |  |
| `tasksV2RightNowAiEnabled` | toggle | `true \| false` |  |
| `tasksV2TodayColor` | text | `string` | An accent-colour override for the built-in Today view in Tasks, so you can tell it apart from your own lists. Null (the default) uses the standard theme colour. Toggles the appearance of the Today view only. Synonyms: today view colour, today accent, recolour the today view, tint today. |
| `tasksV2TodayIcon` | text | `string` | An icon override for the built-in Today view in Tasks, by Lucide icon name. Null (the default) renders the standard Today glyph. Synonyms: today view icon, today glyph, change the today icon. |
| `tasksV2TodayName` | text | `string` | A custom display name for the built-in Today view in Tasks. An empty string (the default) uses the translated 'Today' label. Synonyms: today view name, rename today, today view label, what the today view is called. |
| `teachRecorderEnabled` | toggle | `true \| false` | In-development: records what you do on Windows — clicks, keystrokes, and screen state — and turns the recording into a reusable AI skill that agents can replay on your behalf. Off by default; hidden until shipped. |
| `teachRecorderSidebarEnabled` | toggle | `true \| false` | Shows or hides the Teach Recorder entry in the sidebar - the (in-development) tool that records what you do on Windows and turns the recording into a reusable AI skill. One of the per-section sidebar visibility toggles; on by default, turn it off to remove Teach Recorder from the sidebar. Synonyms: teach recorder sidebar, teach by demonstration, record a task, demonstration recorder. |
| `teamChatApiPlatformEnabled` | toggle | `true \| false` | In-development: an OAuth2 authorization layer for the Team Chat messaging API, enabling third-party integrations to read and write messages with scoped access tokens. The 13 existing CLI routes (channels, messages, reactions, pins, search, etc.) already have Zod validation, pagination, and idempotency — this feature adds the OAuth2 auth surface for external consumption. Hidden until shipped. |
| `teamChatEnabled` | toggle | `true \| false` | In-development: a built-in team chat (channels + direct messages) for your company, delivered in real time to every device via the cloud — a Slack replacement inside Omniscio. Ships dark until the workspace is set up. |
| `teamChatExportEnabled` | toggle | `true \| false` | In-development: export Team Chat channel or DM history to a portable format (JSON/CSV). A GDPR data portability requirement for a multi-user cloud product. Adds an export action to the channel settings menu. |
| `teamChatLivePreview` | toggle | `true \| false` | Whether the Team Chat composer's markdown live-preview pane is open (default closed). A plain remembered UI preference set by the composer's own preview toggle, not a feature gate or a Settings-page control. |
| `teamChatMessageForwardingEnabled` | toggle | `true \| false` | In-development: forward or share a Team Chat message from one channel/DM to another. Adds a forward action to the message hover toolbar and mobile action sheet. |
| `teamChatMessageTranslationEnabled` | toggle | `true \| false` | In-development: translate any Team Chat message inline using the existing LLM layer. Adds a translate action to the message hover toolbar for multi-language teams. |
| `teamChatScreenShareFps` | select | `"5" \| "15" \| "30"` | The frame rate used when you share your screen during a Team Chat video call ("5", "15", or "30" FPS; default "15"). Chosen from the quality-settings popover in the in-call controls bar. A lower FPS stays smooth on slow connections; a higher FPS is better for motion like scrolling or playing video. Synonyms: screen share frame rate, screen sharing FPS, share smoothness, screen share fps. |
| `teamChatShowDmPhotos` | toggle | `true \| false` | When on (the default), the Team Chat sidebar's Direct Messages list shows each teammate's profile photo next to their name, with an initials-circle fallback for anyone without one and their online/away presence dot kept as a small corner badge. Off: the DM list shows just the presence dot and the name. A per-user display preference toggled from the "Show profile photos" item in the Team Chat sidebar's overflow (more-actions) menu. Synonyms: team chat DM avatars, show profile pictures next to direct messages, DM photos, hide chat avatars. |
| `teamChatSidebarEnabled` | toggle | `true \| false` |  |
| `teamChatSidebarWidth` | number | `integer 180..500` |  |
| `teamChatSubmitKeyMode` | select | `"enter" \| "ctrl_enter"` |  |
| `teamChatSummarizationEnabled` | toggle | `true \| false` | In-development: AI-powered summarization for Team Chat channels and threads. Adds a "Summarize" or "Catch me up" button to channel headers and thread panes to generate a concise summary of recent activity. |
| `teamChatVideoBackground` | select | `"none" \| "blur" \| "custom"` | Which video-call background to show during Team Chat calls ("none", "blur", or "custom"; default "none"). Picked from the in-call backgrounds popover. "none" shows your real surroundings, "blur" soft-focuses them for privacy, and "custom" shows the image you set in teamChatVideoBackgroundImage. Synonyms: call background, virtual background, video background, background effect. |
| `teamChatVideoBackgroundBlurLevel` | select | `"light" \| "medium" \| "heavy"` | How strong the background blur is when teamChatVideoBackground is "blur" ("light", "medium", or "heavy"; default "medium"). "light" keeps your room mostly recognizable; "heavy" hides nearly everything behind you. Ignored unless the background mode is "blur". Synonyms: blur strength, background blur amount, privacy blur level. |
| `teamChatVideoBackgroundImage` | text | `string` | The custom image shown as your Team Chat video-call background when teamChatVideoBackground is "custom" (a path or stored image reference; default empty). A non-secret user preference like an avatar or theme choice, never a credential. Synonyms: custom background, video background image, call background picture. |
| `teamChatVideoQuality` | select | `"auto" \| "360p" \| "720p" \| "1080p"` | The outgoing video-capture quality for Team Chat video calls ("auto", "360p", "720p", or "1080p"; default "auto"). Chosen from the quality-settings popover in the in-call controls bar. "auto" lets the connection pick and adapt the resolution to available bandwidth; a fixed value caps your camera at that resolution. Synonyms: call video quality, camera quality, video resolution, call quality. |
| `teamChatWindowHotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `teamChatWindowHotkeyEnabled` | toggle | `true \| false` |  |
| `teamLibraryEnabled` | toggle | `true \| false` | In-development: a members-only shelf where a teammate publishes a skill or saved prompt once and others install it. Cloud security rules are deployed and tested (org + self-serve workspace roots). Renderer data layer (library-client.ts) and list UI (TeamLibraryList.tsx) wired. Ready for final polish and release. |
| `teamSubscriptionEnabled` | toggle | `true \| false` | In-development: shows the per-seat Team plan card on the Plan & Billing screen — a seat picker, a live $25/seat total, and an "Upgrade to Team" button. Held dark until the gateway has a live STRIPE_TEAM_PRICE_ID: without it every Team checkout returns "not available", so a customer would see a fully-priced offer they cannot buy. Reveal this flag as part of the Team go-live, together with the gateway price wiring. Off by default; hidden until shipped. |
| `teamsIntegrationEnabled` | toggle | `true \| false` | In-development: connect your Microsoft account to see your Teams meetings — upcoming and past, with attendees and join links — synced from Microsoft Graph. Off by default. |
| `teamsSyncIntervalMinutes` | number | `integer 5..1440` | Microsoft Teams — how often (in minutes) Omniscio re-syncs your Teams calendar from Microsoft Graph in the background. The poller ticks on this cadence to pull new and updated meetings. 5 to 1440 minutes; default 15 (every 15 minutes). Only used when the Teams integration (teamsIntegrationEnabled) is on; no dedicated Settings-UI control. Synonyms: teams sync frequency, how often teams refreshes, calendar sync interval, meeting refresh rate, how often it checks for new meetings. |
| `teamsSyncWindowDays` | number | `integer 1..90` | Microsoft Teams — how large a window of meetings Omniscio keeps in sync from Microsoft Graph, in days both before AND after today (a symmetric window centered on now: default 14 syncs meetings from 14 days ago to 14 days ahead). 1 to 90 days. Only used when the Teams integration (teamsIntegrationEnabled) is on; no dedicated Settings-UI control. Synonyms: teams sync window, how many days of meetings, calendar date range, meeting lookback and lookahead, how far back and ahead teams syncs. |
| `telegramMtcuteEnabled` | toggle | `true \| false` | The maintained mtcute engine is now the DEFAULT for Telegram (F002 go-live). The engine choice moved to a shipped setting (Settings → Channels → Telegram engine); GramJS remains a reversible opt-out. This entry is retained as shipped so older persisted configs parse cleanly; its reveal toggle no longer gates anything. |
| `terminalEnabled` | toggle | `true \| false` | Inbuilt terminal |
| `thaiPilotEnabled` | toggle | `true \| false` | Adds Thai (ไทย) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `thinSessionProcs` | toggle | `true \| false` | Windows only. When on, each agent session and every tool command it runs (bash, git, powershell) share ONE genuinely-hidden console window, so Windows no longer creates a separate conhost.exe console window per command — the fix for hundreds of terminal windows flashing on screen and a pile of conhost.exe processes. It routes a direct-executable session spawn through a tiny bundled launcher (amc-hidden-launch.exe). On by default (Windows). Fail-open: if off, or on any problem finding the launcher, sessions start exactly as before. Takes effect on the next session you start. No effect on macOS or Linux. Legacy enable env var AMC_HIDDEN_CONSOLE_LAUNCHER=1; kill switch env var AMC_DISABLE_THIN_SESSION_PROCS=1. Synonyms: thin session processes, hidden console, stop the flashing terminal windows, fewer conhost processes, no console window per tool command. |
| `timeTrackerAutoCaptureEnabled` | toggle | `true \| false` |  |
| `timeTrackerAutoCaptureIdleMinutes` | number | `integer 1..60` | Auto-capture idle threshold in MINUTES — the gap of no keyboard/mouse activity that closes an activity block (and splits proposals). Default 5; clamped to 1–60. |
| `timeTrackerAutoCaptureTitles` | toggle | `true \| false` |  |
| `timeTrackerEnabled` | toggle | `true \| false` | Time Tracker |
| `timeTrackerSidebarEnabled` | toggle | `true \| false` |  |
| `titleEvalDailyDollarCap` | number | `number 0..50` |  |
| `toastDurationScale` | select | `"short" \| "normal" \| "long" \| "extra-long"` |  |
| `toastPreferences` | object | `object { accountActions: true \| false; attentionAlerts: true \| false; budgetAlerts: true \| false; clipboardCopied: true \| false; deletions: true \| false; deployProfiles: true \| false; errors: true \| false; extraUsageAlerts: true \| false; general: true \| false; infrastructureActions: true \| false; projectActions: true \| false; recipeActions: true \| false; screenshotCaptured: true \| false; sessionActions: true \| false; sessionArchived: true \| false; settingsConfirmations: true \| false; smsCodes: true \| false; statusAlerts: true \| false; voiceAlerts: true \| false; warnings: true \| false }` |  |
| `toolCallTimingTapeEnabled` | toggle | `true \| false` |  |
| `toolchainWizardDismissed` | toggle | `true \| false` |  |
| `tosAcceptedAt` | text | `string (≤40)` |  |
| `tosAcceptedVersion` | number | `integer 0..1000000` |  |
| `tourCompletions` | map | `map of string → true \| false` |  |
| `tourLastOfferAt` | number | `integer 0..∞` |  |
| `traditionalChinesePilotEnabled` | toggle | `true \| false` | Adds Traditional Chinese (繁體中文) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `trelloEnabled` | toggle | `true \| false` | Adds a "Trello" sidebar tab to view and manage your Trello boards — kanban columns, card detail, comments, checklists, labels — without leaving Omniscio. Connect with your Trello API key and token in Settings. In development. |
| `trelloInboxEnabled` | toggle | `true \| false` |  |
| `tryItFreeOnboardingEnabled` | toggle | `true \| false` | In-development: an onboarding choice that lets a new user run Claude Code (and later Codex) on company-provided API keys during setup — no personal key needed — with a small capped trial credit and a friendly "add your own key" prompt when it runs out. Off by default; inert until the company gateway keys are live. |
| `ttsAutoRead` | toggle | `true \| false` |  |
| `ttsCustomVoices` | list | `array of object { id: string; name: string (≤200); voiceId: string (≤200) }` |  |
| `ttsDailyCapUSD` | number | `number 0..100` |  |
| `ttsVoiceId` | text | `string (≤200)` |  |
| `tunnelEnabled` | toggle | `true \| false` |  |
| `turkishPilotEnabled` | toggle | `true \| false` | Adds Turkish (Türkçe) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `typingTutorBuiltinMigrated` | toggle | `true \| false` |  |
| `unclaimedCheckEnabled` | toggle | `true \| false` | In-development: gives your agents a free "am I owed unclaimed money?" lookup. It installs the bundled unclaimed-check skill and a local search route that proxies each lookup through the Omniscio cloud gateway using your sign-in — no separate key, no cost, just rate-limited. Agent-only (no panel); off by default; hidden until shipped. |
| `unifiedSidebarEngineEnabled` | toggle | `true \| false` | Unified sidebar engine (V2) |
| `unifiedTurnEngineEnabled` | toggle | `true \| false` |  |
| `universalAiSearchEnabled` | toggle | `true \| false` | One search box across every surface: type in plain language and get a single relevance-ranked list blending keyword and meaning-based (semantic) matches. |
| `universalCommandPaletteEnabled` | toggle | `true \| false` | In-development: opens a comprehensive, fuzzy-search command palette (Ctrl+Shift+P) that reaches every action, navigation hub, and setting in one keypress. Flag off = today's curated Quick Launch command tab (no regression). DevOnly while the catalog stabilises. |
| `unusedGroupDisplayOrder` | number | `integer` |  |
| `unusedQuickReplyDeclutterNudgeEnabled` | toggle | `true \| false` |  |
| `updateChannel` | select | `"stable" \| "rc"` |  |
| `urduPilotEnabled` | toggle | `true \| false` | Adds Urdu (اردو) to the language picker as a machine-translated pilot catalog. Urdu reads right-to-left. Any untranslated text falls back to English. |
| `userPersona` | select | `"founder-fred" \| "engineer-ike" \| "pm-parker" \| "aspiring-amy"` | Your avatar persona for onboarding and persona-flavored defaults — one of founder-fred, engineer-ike, pm-parker, or aspiring-amy (null = none chosen). Chosen during onboarding; some default settings are flavored by the persona you pick. Synonyms: avatar persona, persona choice, onboarding persona, which persona. |
| `userRole` | text | `string (≤80)` | Your short self-described role (e.g. "founder", "product manager", "developer"), captured once during the Setup v2 onboarding "tell us about you" step. It personalizes the onboarding flow only; the display name itself comes from your cloud/Google profile, not this field. Local-only free text, optional (undefined until you answer). Synonyms: my role, job title, what I do. |
| `vadThresholdsByDeviceId` | map | `map of string → object { silenceFloor: number 0..1; speechThreshold: number 0..1 }` |  |
| `verdictPanelEnabled` | toggle | `true \| false` | In-development: a developer-tools panel that answers whether the verdict road is healthy, and where it is not, in ten seconds — one status sentence, six headline stats judged against a normal band, the road drawn as an eight-station line with its bottleneck marked, and one-click drill-downs into each station, the fleet, this box and the machinery. Every number carries its source and as-of time; a value nobody measured reads "no reading", never zero. Read in the main process from the broker’s own ledgers and the app’s readouts; read-only, no restart or rollback buttons. Hidden until shipped. |
| `verdictPanelSidebarEnabled` | toggle | `true \| false` | Shows or hides the Verdict entry in the sidebar — the developer-tools panel that shows what the Verdict verification broker on this machine is doing (broker health, queue, executions, deliveries, requests, red flags, diagnostics readout, owner policy). One of the per-section sidebar visibility toggles; on by default, turn it off to remove Verdict from the sidebar (the panel itself is revealed by the verdict-panel Lab toggle). Synonyms: verdict sidebar, verification broker panel, show/hide verdict dashboard. |
| `videoCallsEnabled` | toggle | `true \| false` | In-development: voice and video calling in Team Chat via LiveKit Cloud |
| `videoPlaybackRate` | number | `number 0.5..3` | Global video playback speed (VIDEO_SPEED_MIN..MAX, default 1×). Applied to every <VideoPlayer> on load and remembered across plays + restarts (persisted via updateSetting({ silent: true })). Read as `settings.videoPlaybackRate ?? 1`. |
| `vietnamesePilotEnabled` | toggle | `true \| false` | Adds Vietnamese (Tiếng Việt) to the language picker as a machine-translated pilot catalog. Any untranslated text falls back to English. |
| `voiceActHighlightEnabled` | toggle | `true \| false` | In-development: when voice asks you to confirm an action (like sending a message or ending a thread), highlight the on-screen thread it will act on so you can see what you are confirming. |
| `voiceAttachmentEnabled` | toggle | `true \| false` | In-development: a small chip showing whether voice targets Omniscio (app-level) or a specific session, plus a per-utterance receipt of where each voice command actually went. |
| `voiceBargeInLabFlag` | toggle | `true \| false` |  |
| `voiceBargeInLabVisible` | toggle | `true \| false` | In-development: interrupt the spoken AI response by talking over it. Reveals the barge-in controls + mic calibration in Voice settings. Not yet fully wired, so hidden by default. |
| `voiceCommandCaptureMode` | select | `"auto" \| "single" \| "continuous" \| "buffered"` |  |
| `voiceCustomCommands` | list | `array of object { action: "navigate" \| "session:create" \| "session:send" \| "session:interrupt" \| "session:archive" \| "session:terminate" \| "project:select" \| "tts:speak" \| "tts:stop" \| "mute" \| "unmute" \| "attention"; enabled: true \| false; id: string (≤100); label: string (≤200); params: map of string → string (≤500) \| number \| true \| false; triggers: array of string (≤100) }` |  |
| `voiceFeedbackSounds` | toggle | `true \| false` |  |
| `voiceHistorySidebarEnabled` | toggle | `true \| false` | A viewable history of your voice conversations, in the sidebar. Keeps your hands-free "Omniscio Voice" chats and your per-session "Session Voice" questions, each clearly labeled, so you can revisit what was said. |
| `voiceL2DailyCapUSD` | number | `number 0..100` |  |
| `voiceL2Enabled` | toggle | `true \| false` | In-development: talk back and forth with an AI assistant that has context about what is on screen, can grab more context, navigate the app, and (later) take actions on your behalf. Read-only in this build. |
| `voiceL2Hotkey` | unknown | `string (≤100) \| array of string (≤100)` |  |
| `voiceL2HotkeyEnabled` | toggle | `true \| false` |  |
| `voiceL3DailyCapUSD` | number | `number 0..100` |  |
| `voiceL3Model` | text | `string (≤100)` |  |
| `voiceLlmProvider` | select | `"groq" \| "claude-haiku"` |  |
| `voicePttCommandEnabled` | toggle | `true \| false` |  |
| `voicePttCommandKey` | text | `string (≤100)` |  |
| `voicePttDictateEnabled` | toggle | `true \| false` |  |
| `voicePttDictateKey` | text | `string (≤100)` |  |
| `voiceReportBackDailyCapUSD` | number | `number 0..100` |  |
| `voiceResponseStyle` | select | `"off" \| "short" \| "conversational"` |  |
| `voiceSilenceTimeout` | number | `number 0..10000` |  |
| `voiceprintStudioDailyDollarCap` | number | `number 0..50` |  |
| `voiceprintStudioSidebarEnabled` | toggle | `true \| false` | In-development: a studio in the sidebar that builds an email style guide in your WRITING voice (not audio). Tag your Sent mail, watch the AI re-draft a real email blind, judge it, and approve fixes that sharpen the guide you paste into any AI. |
| `waitingDetectorCorpusEnabled` | toggle | `true \| false` |  |
| `waitingDetectorEnabled` | toggle | `true \| false` |  |
| `waitingDetectorModelEnabled` | toggle | `true \| false` |  |
| `wakeWordFocusOnly` | toggle | `true \| false` |  |
| `wakeWordKeywords` | list | `array of "computer" \| "hey-omniscio"` |  |
| `wakeWordSensitivity` | number | `number 0..1` |  |
| `warayPilotEnabled` | toggle | `true \| false` | Adds Waray (Waray-Waray) to the language picker as a machine-translated pilot catalog. Off by default — English is unaffected, and any untranslated text falls back to English. |
| `warnInternalLinksInTeamChat` | toggle | `true \| false` |  |
| `webAppVerifyNudgeSeen` | toggle | `true \| false` | Web-app verification (Obscura) is retired as of 2026-09-19 — the verify_web_app tool no longer composes into a session, so there is nothing to turn on and no tool to advertise; the engine stays in the tree, unwired. This key is only the one-shot marker that the old "install Obscura" nudge has been seen, and it is now read by nothing. |
| `webMediaDownloadEnabled` | toggle | `true \| false` | In-development: turns on the File Converter’s "Download from web" tab (desktop only) — paste a YouTube/Vimeo/direct link and yt-dlp saves it to your Downloads as Video (MP4), Audio (MP3), or Best. A SEPARATE opt-in on top of the File Converter, which stays conversion-only until you enable this. Off by default. |
| `weeklySummaryScheduleMinute` | number | `integer 0..59` |  |
| `whiteboardBuiltinMigrated` | toggle | `true \| false` |  |
| `windowForegroundHarmYieldEnabled` | toggle | `true \| false` | When on (the default), a window raise Omniscio starts ON ITS OWN takes the cheap path — no always-on-top toggle — while the machine is measurably hurting you. A raise YOU asked for is never gated by this, so clicking a session always brings it forward normally. Turn it off to let every machine-initiated raise use the full path regardless of load. Synonyms: window foreground harm yield, dont steal focus while busy, cheap window raise when hurt, machine window raise gating, foreground harm yield. |
| `wmiHydrationBackoffEnabled` | toggle | `true \| false` | When on (the default), the command-line hydrator backs off its FULL-TABLE WMI walk: a walk that resolves nothing doubles the wait, up to 15 minutes, and any walk that resolves something resets it; off restores one walk per batch, unconditionally. It exists for a measured reason — 44 consecutive full-table WMI walks at the reaper's 2-minute cadence, over ~155 processes the walk never resolved, burned a core in wmiprvse.exe on every tick, forever. Synonyms: wmi hydration backoff, slow down the wmi walk, wmi fallback backoff, command line hydration backoff, stop the wmi CPU burn. |
| `workflowCoachDailyDollarCap` | number | `number 0.05..5` |  |
| `workflowCoachDetectors` | object | `object { duplicateApproval: true \| false; featureGap: true \| false; featureUsage: true \| false; idleSession: true \| false; manualArchive: true \| false; repeatedOutgoingText: true \| false }` |  |
| `workflowCoachEnabled` | toggle | `true \| false` |  |
| `workflowFavoriteKeys` | list | `array of string (≤80)` | The steps and app groups you have PINNED in the Workflows step picker, in pin order. Pinned entries show first in both places you add a step — the drag rail and the "Add step" popup. Managed by the pin button in those pickers rather than a Settings toggle; a pin for a step the engine no longer offers is simply ignored. Empty by default. Synonyms: pinned workflow steps, workflow favorites, favourite nodes, pin a step to the top, my pinned workflow apps, unpin a workflow step. |
| `workflowRecentStepTypes` | list | `array of string (≤80)` | The step types you added most recently in the Workflows editor, newest first and capped at a short list, so the picker's "Recent" row survives a restart instead of resetting each session. Maintained automatically as you build workflows — not something you set. Unknown or removed step types are skipped when the row renders. Empty by default. Synonyms: recent workflow steps, recently used nodes, workflow picker recents, steps I used last, clear workflow recents. |
| `workflowsEnabled` | toggle | `true \| false` | In-development: build n8n/Zapier-style automations on a visual canvas — a trigger plus a graph of steps (deterministic actions and AI steps) that Omniscio runs for you. |
| `workflowsSessionSplit` | toggle | `true \| false` |  |
| `workflowsSidebarEnabled` | toggle | `true \| false` |  |
| `workflowsSplitWidth` | number | `number 200..4000` | Width (px) of the workflow canvas pane in split view. Resizable via the divider; persisted globally. Read as `settings.workflowsSplitWidth ?? 460`. |
| `worktreeCleanupIntervalHours` | number | `integer 1..24` | How often the in-app scheduler runs cleanup, in hours. Read live each tick and clamped to [1, 24] (a bad/zero value falls back to the shipped default). The stale-alert window scales off this (≈ interval × 3, floored at the default stale window) so a long interval never false-alarms "wedged". |
| `worktreeCreateCalmHoldEnabled` | toggle | `true \| false` | Makes each new worktree wait, for a bounded time, until the drive it is created on is no longer busy. Off by default: on a computer whose system drive is also the worktree drive that drive never reads calm, so every create sat out the full wait for nothing. With it off, busy-drive creates are still taken one at a time. Armed under the same one-at-a-time rule as the pacing levers. Synonyms: worktree calm hold, wait for the disk to calm, create queue calm wait, hold worktree creates on a busy drive. |
| `worktreeCreatePacingEnabled` | toggle | `true \| false` | Paces the rate at which new worktrees are created, so a burst of creates cannot storm the disk. Off by default, and armed under the same one-at-a-time rule as the other pacing levers (crash matrix, latency benchmark and soak before it is switched on). Synonyms: worktree create pacing, pace worktree creation, throttle worktree creates, worktree create storm, disk pressure from worktrees. |
| `worktreeFullCopyRepeatCapEnabled` | toggle | `true \| false` |  |
| `worktreeIdleLeaseEnabled` | toggle | `true \| false` |  |
| `worktreeLedgerEnabled` | toggle | `true \| false` | Plain-language view of every workspace in flight, backed by the observed worktree ledger, with a Saved Work vault. |
| `worktreeReapUserHarmGateEnabled` | toggle | `true \| false` | Whether the in-app worktree reaper decides it is safe to run from the user-harm verdict (is anything here about to hurt you?) plus the worktree-drive hold, instead of from how busy the CPU is. On by default. If the verdict cannot be read it falls back to the CPU signal rather than guessing. Master kill: AMC_DISABLE_HARM_KEYED_LOAD_GATES=1. Synonyms: worktree reap user harm gate, harm keyed load gate, worktree cleanup load gate, reap worktrees when busy. |
| `worktreeRegistryFileReadsEnabled` | toggle | `true \| false` | When on (the default), Omniscio lists a repository's worktrees by reading the files under its .git folder instead of running git for each listing — on a checkout with hundreds of worktrees that turns a multi-second git command into a few milliseconds with no process at all. Any doubt falls back to git automatically. Turn it off to make every listing run git exactly as before; the AMC_DISABLE_WORKTREE_REGISTRY_FILE_READS environment variable is the operator's kill switch for the same thing. |
| `worktreeSessionCleanupDailyBudgetUsd` | number | `number 0..100` | Hard daily spend cap (USD) for this feature's sessions, ON TOP of the global daily budget cap — once today's feature spend reaches it, no further sessions spawn. Range 0-100. Default 2. |
| `worktreeSessionCleanupEnabled` | toggle | `true \| false` | Master switch for the SESSION-BASED per-repo worktree cleanup — the newer cleanup that reasons about your ledger of worktrees and their sessions, rather than the free reaper behind worktreeCleanupEnabled. Off by default. Works on every platform. Synonyms: session worktree cleanup, per-repo worktree cleanup, worktree ledger cleanup, advanced worktree cleanup. |
| `worktreeSessionCleanupMaxSessionsPerDay` | number | `integer 1..50` | Hard cap on how many paid cleanup sessions this feature may spawn per day, ON TOP of the global daily budget cap. Range 1-50. Default 5. |
| `worktreeSlotPoolEnabled` | toggle | `true \| false` |  |
| `worktreeStaleInstallRefusalEnabled` | toggle | `true \| false` |  |
| `worktreeTriageEnabled` | toggle | `true \| false` | Sub-switch for the worktree cleanup dashboard: when on (the default) the cleanup also runs the paid stranded-worktree triage helper, which uses an AI session to work out whether a stuck worktree is safe to remove. It only has an effect while worktreeCleanupEnabled is on, and it costs money each time it runs — turn it off to keep the free, rule-based reaping and skip the AI pass. Synonyms: worktree triage, paid worktree triage, stranded worktree helper, ai worktree cleanup, worktree cleanup cost. |
| `worktreeTriageModel` | text | `string (≤100)` | Which model the paid stranded-worktree triage session runs on, within the engine chosen above. Leave it on Default unless you have a reason to move it. Synonyms: worktree triage model, triage ai model, stranded worktree model. |
| `worktreeTriageProvider` | text | `string (≤64)` | Which engine runs the paid stranded-worktree triage session. Leave it on Default unless you have a reason to move it — the default is DeepSeek V4.1 Flash, chosen because it is cheap and can call tools, which this job needs. Changing this changes who receives the uncommitted work from those worktrees, so it is a disclosure decision as much as a cost one. Synonyms: worktree triage provider, triage engine, which model runs the triage. |
| `writeTimeLintHookEnabled` | toggle | `true \| false` | Format + lint each file an agent writes, feeding fixes back to the agent. Off by default. |
| `writerAssistantWidth` | number | `integer 300..720` |  |
| `writerAutocompleteEnabled` | toggle | `true \| false` | When on, Writer shows ghost-text autocomplete suggestions as you type, which you can accept or ignore. Off by default (cost-sensitive). Toggle from the Autocomplete button in the Writer document header. |
| `writerAutocompleteModel` | text | `string (≤100)` | Which AI model powers Writer's inline autocomplete ghost-text — kept separate from writerModel since autocomplete fires constantly and should stay cheap. Automatic (Luna), Luna, Haiku, Sonnet, or Opus (default Automatic). Writer plugin settings → "Autocomplete model". |
| `writerChatAutoInject` | toggle | `true \| false` |  |
| `writerCollapsedFolders` | list | `array of string (≤1024)` | Which folders are collapsed in the Writer sidebar's folder tree, by folder id. Toggled by clicking a folder's collapse arrow; a remembered layout state, not a Settings-page control. |
| `writerCostCapUsd` | number | `number 0.5..50` | Daily USD spend cap on Writer's AI features — edits, autocomplete, and chat (default $2; range $0.50-$50). Once the day's Writer AI spend hits this, further AI actions in Writer are refused until it resets. Settings → Cost Controls → "Writer AI edits". |
| `writerDefaultCreativity` | number | `number` | The AI creativity level (1=Careful to 4=Bold; default 2=Balanced) a NEW Writer document starts with — set once during the writing-defaults setup step and copied onto each new document; each document can then change its own from there. Setup wizard → Writing Defaults → "AI creativity level". |
| `writerDefaultTone` | text | `string` | The default tone (e.g. "professional", "casual", "friendly") a NEW Writer document starts with — set once during the writing-defaults setup step. Blank (the default) lets each document set its own tone. Setup wizard → Writing Defaults → "Default tone". |
| `writerDocViewMode` | select | `"list" \| "grid" \| "compact"` | How your Writer documents list is displayed: list, grid, or compact (default list). Set from the view-mode switcher above your Writer document list; a remembered display preference. |
| `writerDriveEnabled` | toggle | `true \| false` | Kill switch for Writer's Google Drive integration (import from Drive and publish to Google Docs). On by default. No Settings-UI control yet; set via CLI/PATCH. |
| `writerFontSize` | number | `integer 12..24` | The editor font size in Writer, in points (default 16; choices 12/14/16/18/20/22/24). Writer's own Appearance menu → "Font size". |
| `writerKmsSyncOnSave` | toggle | `true \| false` | When on, saving a Writer document also pushes its content to the Knowledge Vault (KMS) note it's linked to. Off by default; has no effect unless KMS is enabled. Toggled from the sync-on-save control in the Writer header. |
| `writerLastOpenedDocId` | text | `string` | Internal record of which Writer document you last had open, used to reopen it automatically the next time you open Writer. Not user-facing; updated automatically every time you switch documents. |
| `writerLineSpacing` | select | `"compact" \| "normal" \| "relaxed"` | The editor line spacing in Writer: compact, normal, or relaxed (default normal). Writer's own Appearance menu → "Line spacing". |
| `writerModel` | text | `string (≤100)` | Which AI model handles Writer's chat, edits, and rewrite options: Automatic (Sonnet for chat, Luna for edits), Luna, Haiku, Sonnet, or Opus (default Automatic). Kept separate from writerAutocompleteModel, which only covers inline ghost-text. Writer plugin settings → "AI model". |
| `writerOnboardingCompleted` | toggle | `true \| false` |  |
| `writerPalette` | select | `"none" \| "parchment" \| "midnight-ink" \| "candlelight" \| "noir" \| "velvet" \| "frost" \| "sage" \| "rose"` |  |
| `writerRewriteOptionsHintDismissed` | toggle | `true \| false` |  |
| `writerSetupComplete` | toggle | `true \| false` |  |
| `writerSetupWizardEnabled` | toggle | `true \| false` | A guided setup wizard for Writer Studio that walks users through writing preferences (creativity level, tone), showcases AI editing features, and helps create the first document. Off by default (in-development); turn it on with one setting flip once Writer Studio itself is revealed. |
| `writerSidebarEnabled` | toggle | `true \| false` |  |
| `writerTheme` | select | `"match-app" \| "light" \| "dark"` |  |
| `writerToolbarLayout` | select | `"icons-text" \| "icons-only" \| "compact" \| "full-icon"` | The button style of Writer's own document-header toolbar: icons + labels, icons only, compact, or all icons (default icons only). Writer's own Appearance menu → "Toolbar". |
| `zapCoachEnabled` | toggle | `true \| false` | When on, Omniscio drops a gentle inbox card when you hand-type a phrase that already has a one-tap shortcut — your Zap (Alt+Z), a saved quick reply (Alt+S), or the "Please continue" button — naming the shortcut so you can use it next time. The inverse of the "save repeated phrases" nudge. OFF by default (opt-in); each phrase is tipped at most once. |
| `zoomApiEnabled` | toggle | `true \| false` | Connect your Zoom account to see meetings, recordings, and transcripts. In development. |
| `zoomApiSyncIntervalMin` | number | `integer 5..120` | Zoom API — how often (in minutes) Omniscio re-syncs your meetings from the Zoom API in the background. 5 to 120 minutes; default 15. Only used when the Zoom integration (zoomApiEnabled) is on. Synonyms: zoom sync interval, zoom poll frequency, how often zoom refreshes. |

---

To fill in or change a "What it does", edit the setting's `helper` in its `src/renderer/src/features/settings/*-definitions.ts(x)`, or add an entry to `scripts/settings-catalog-overrides.ts`, then rerun `npm run settings:catalog`.
