
# Controls, permissions, privacy & general settings

These settings control what agents and external scripts are allowed to do, how your data and activity are handled, and a range of productivity features that don't belong to a single integration.

---

## Agent permission level {#agentPermissionLevel}

Controls how much a Claude agent can do on its own before Omniscio stops to ask you. Four levels are available: **Read-only** (agent can read files but must ask before writing or running commands), **Guarded** (auto-approves edits inside the project, asks for commands and outside-project writes — the recommended default), **Autonomous** (auto-approves edits and commands inside the project, asks only for writes outside), and **Full trust** (approves everything except the built-in protection for SSH keys, credentials, and system files, which always asks). Applies to Claude Code sessions, and to new Codex sessions, which get the closest Codex policy unless the [Codex permission level](settings-extra-bcdefg.md#codexApprovalMode) overrides it.

---

## Require approval for AI session spawn {#requireApprovalForAiSessionSpawn}

When ON, any AI-initiated session spawn — from a deep link or the CLI — appears as an inbox card you must approve before the session starts. When OFF (default), spawns happen immediately in the background and show in the sidebar without interrupting you. Turn ON if you want a human-in-the-loop checkpoint before AI orchestration can spin up new paid sessions.

---

## Require approval: App settings {#requireApprovalForCliSettings}

When ON (default), an agent or script trying to change any Omniscio setting via the CLI must wait for your inbox approval first. Governs both single-key changes and bulk settings-file imports. Turn OFF to let agents adjust settings without asking.

---

## Require approval: Session pause / snooze / archive {#requireApprovalForCliSessionLifecycle}

When OFF (default), CLI requests to pause, unpause, snooze, or archive a session are applied immediately, so an agent can manage session lifecycle without asking. Turn ON to send those requests to your inbox for approval first — worth doing if you let agents you do not fully trust manage the fleet, since an ungated CLI once let an agent silently pause many sessions at once.

---

## Require approval: Tags {#requireApprovalForCliTags}

When ON (default), CLI requests to create, rename, or delete library tags require your inbox approval. Turn OFF to let agents manage tags freely.

---

## Require approval: Project edits {#requireApprovalForCliProjectEdits}

When ON (default), CLI requests to update a project's bug-intake settings or upload/delete project documents require your approval. Turn OFF to allow agents to edit project details without asking.

---

## Require approval: Project / group delete {#requireApprovalForCliProjectDelete}

When ON (default), CLI requests to delete a project (soft-delete — recoverable) or remove a sidebar group (its projects become ungrouped) require your inbox approval. This is a destructive action. Turn OFF to let agents delete projects and groups without asking.

---

## Require approval: Away-Mode (Auto-Run) rules {#requireApprovalForCliAwayMode}

When ON (default), CLI requests to create, edit, or delete auto-run rules need your approval. Auto-run rules define what runs automatically while you are away, so changes to them have broad effects. Turn OFF to let agents manage these rules freely.

---

## Require approval: Email Summarizer rules {#requireApprovalForCliEmailSummarizer}

When ON (default), CLI requests to create, update, delete, or toggle email-summarizer rules — including running the setup wizard or triggering a Gmail pass — require your approval. Turn OFF to let agents adjust summarizer rules without asking.

---

## Require approval: Drip {#requireApprovalForCliDrip}

When OFF (default), CLI requests to create, update, or delete Drip campaigns or their folder/book sources are applied immediately, so agents can manage Drip campaigns freely. Turn ON to require your approval first — worth doing if agents write to outbound campaigns you have not reviewed.

---

## Require approval: Bug-Intake sources {#requireApprovalForCliIntakeSources}

When ON (default), CLI requests to enable a bug-intake source require your approval before going live. Enabling a source arms a recurring paid poll, so unexpected enables cost money. Turn OFF to let agents enable intake sources without asking.

---

## Require approval: AI Coaching {#requireApprovalForCliAiCoaching}

When ON (default), CLI requests to create, edit, or delete coaching artifacts, or to start a coaching interview, require your approval. Starting an interview spawns a paid Claude session. Turn OFF to let agents manage coaching content and start interviews without asking.

---

## Require approval: Recipe run {#requireApprovalForCliRecipeRun}

When ON (default), CLI requests to run a recipe (or arm a recurring schedule for one) require your approval, because running a recipe spawns a paid Claude session. Turn OFF to let agents trigger recipe runs without asking.

---

## Require approval: Nighty-Tidy run-now {#requireApprovalForCliNightyTidyRun}

When ON (default), CLI requests to run a Nighty-Tidy audit immediately require your approval, because the run spawns a paid Claude session. Turn OFF to let agents trigger audits without asking.

---

## Require approval: Re-run from a message {#requireApprovalForCliSessionRerun}

When ON (default), CLI requests to re-run a session from a specific message require your approval, because a re-run forks a new paid Claude session. Turn OFF to let agents trigger re-runs without asking.

---

## Require approval: Send SMS {#requireApprovalForCliSmsSend}

When ON (default), CLI requests to send or schedule a text message require your approval, because each SMS counts against your monthly limit. Turn OFF to let agents send texts without asking.

---

## Require approval: Send a share link {#requireApprovalForCliShareSend}

When ON (default), CLI requests to deliver a share link (via email, SMS, or Slack) require your approval. SMS delivery counts against your monthly limit. Turn OFF to let agents send share links without asking.

---

## Require approval: Install / enable / disable / uninstall plugins {#requireApprovalForCliPluginToggle}

When ON (default), CLI requests to install, enable, disable, or uninstall a plugin require your approval. Installing or enabling activates the plugin's UI, backend code, and any scheduled work; uninstalling deletes its files — both are significant changes. Turn OFF to let agents manage plugins without asking.

---

## Require approval: Screen-capture AI {#requireApprovalForCliCaptureAi}

When ON (default), CLI requests to auto-title a snip or summarize a recording require your approval, because these call the paid Anthropic API. Turn OFF to let agents use screen-capture AI features without asking.

---

## Require approval: Vault image AI analysis {#requireApprovalForCliKmsImageAnalysis}

When ON (default), CLI requests to analyze Vault images using AI require your approval, because analysis calls the paid Anthropic vision API. Turn OFF to let agents run image analysis without asking.

---

## Require approval: Vault note summaries {#requireApprovalForCliKmsSummary}

When ON (default), CLI requests to generate or bulk-seed Vault note summaries require your approval, because summary generation calls the paid Anthropic API. Turn OFF to let agents generate summaries without asking.

---

## Require approval: Vault deletes {#requireApprovalForCliKmsDelete}

When ON (default), CLI requests to delete a Vault note, tag, or image require your approval. Notes move to the vault trash and are recoverable. Turn OFF to let agents delete Vault content without asking.

---

## Require approval: Tasks AI & agent runs {#requireApprovalForCliTasksV2Ai}

When ON (default), CLI requests for paid Tasks AI actions — ranking, daily check-ins, task breakdowns, launching a task agent — require your approval, because all of these call or spawn paid Claude. Turn OFF to let agents run Tasks AI features without asking.

---

## Require approval: Meeting-note AI enhance {#requireApprovalForCliMeetingsAi}

When ON (default), CLI requests to AI-enhance a meeting note (Generate notes) require your approval, because enhancement calls the paid Anthropic API. Turn OFF to let agents enhance meeting notes without asking.

---

## Require approval: Send Gmail {#requireApprovalForCliGmailSend}

When ON (default), CLI requests to send, reply to, or forward an email via Gmail require your approval, because these send a real email to a real recipient. Turn OFF to let agents send Gmail without asking.

---

## Require approval: Send Supermail / open assistant {#requireApprovalForCliSupermailSend}

When ON (default), CLI requests to send or reply to a Supermail email, or open a thread's AI assistant, require your approval. Sending emails reaches real recipients; opening the assistant spawns a paid Claude session. One toggle governs all three. Turn OFF to let agents do these without asking.

---

## Require approval: Supermail panel settings and commands {#requireApprovalForCliSupermailControl}

When ON (default), CLI requests to write sensitive Supermail settings (AI-filter rule, filter mode, master on/off) or dispatch destructive commands (trash, sign-out, and similar) require your approval. This is a destructive category. Turn OFF to let agents manage Supermail settings directly.

---

## Require approval: Send Telegram messages {#requireApprovalForCliTelegramSend}

When ON (default), CLI requests to send, edit, delete, or forward a Telegram message require your approval, because these are real actions a real person sees. Turn OFF to let agents interact with Telegram without asking.

---

## Require approval: Admin actions {#requireApprovalForCliAdminActions}

When ON (default), an agent or script asking Omniscio to do any of these must wait for your inbox approval first: claim the public support address, let (or stop) a project's cloud machine reading its repository, move sessions from one Overseer to another, start a session in an abandoned working folder, or delete one. Turn OFF to let them proceed without asking.

**These six are the ones worth reading before you turn anything off.** One of them spends money (starting a session in an abandoned folder), and one destroys work that may exist nowhere else (deleting that folder). The other four change what a machine can reach: enabling cloud repo access writes a deploy key onto a repository you own, disabling it revokes one, moving sessions re-homes work that is already running, and claiming the support address re-points a door anyone can email to start a session.

**You can also allow just one of them.** Every approval card for these carries an "always allow" option, so approving one command once and asking to stop being asked changes that command alone — the others keep asking.

---

## Let agents bring Omniscio to the front {#allowAgentForegroundFromBackground}

When OFF (default), an agent's request to focus or pop Omniscio to the front while you're working in another app is ignored — instead you get a dismissible inbox note naming the session that tried. When ON, agents may pull the app to the front from behind. Your own shortcuts, notification clicks, and phone taps are never affected.

---

## Let agents switch your view directly {#allowAgentDirectNavigation}

When OFF (default), an agent's request to jump you to a hub, the inbox, a settings pane, a note, a mind map, or a Gmail thread shows a click-to-go toast rather than moving you immediately — so Omniscio never takes over your screen without permission. When ON, agents may switch your view directly (useful for guided tours and demos). If you're in another app entirely, the request still can't move you — you get an inbox note instead.

---

## Let agents restart the app {#allowAgentAppRestart}

When OFF (default), the CLI restart route is disabled entirely — no agent or external script can quit and relaunch Omniscio, even one holding the global CLI token. Your own "Restart Omniscio" button in the app is unaffected. Turn ON only if you need a headless script to restart the app.

---

## Let agents spawn sessions with their own token {#allowAgentTokenSpawn}

When OFF (default), a session-spawn request is rejected if it presents only an agent's scoped token (the Omniscio-injected `$AMC_CLI_TOKEN`). This stops a compromised MCP server or npm dependency that reads an agent's environment from spending your money by spawning paid sessions. Agents still spawn normally with the global CLI token. Turn ON to allow agents to spawn sessions directly with their own scoped token.

---

## Let agents write to Team Chat with their own token {#allowAgentTokenTeamChat}

When OFF (default), Team Chat writes over the CLI (send/DM, react, edit, delete, pin, schedule, invite) are rejected if they use only an agent's scoped token — preventing a compromised dependency from messaging your teammates as you. When ON, agents may write to Team Chat with their own token; every message is still labeled as coming from your agent. Reading Team Chat is unaffected.

---

## Auto-approve config file writes {#autoApproveConfigFiles}

When ON, Omniscio automatically approves when Claude wants to modify its own configuration files (`.claude/` directories and `CLAUDE.md`). When OFF, you are asked to approve each config-file change before it is written. Useful to turn ON in a heavily automated workflow; leave OFF if you want to review every instruction-file edit.

---

## Auto-approve plans {#autoApprovePlans}

When ON, Omniscio automatically approves the plan Claude proposes before writing code, skipping the approval step entirely. When OFF (default behavior without this toggle), you are prompted to approve or reject each plan first. Saves a click in high-volume, trusted workflows.

---

## Auto-fix broken cloud base {#autoFixBrokenCloudBase}

When the cloud test-offload workspace fails to build (a dependency or toolchain break it cannot self-heal), Omniscio raises an inbox card. When ON (default), it also automatically launches a fixer session to resolve the problem hands-free. When OFF, you get only the card and must act manually. Because a fix session costs money, the OFF switch lets you approve each one.

---

## Auto-fix master debt {#autoFixMasterDebt}

When ON, Omniscio automatically spawns fix sessions for accumulated debt on the master branch. When OFF (default), you receive an inbox card asking you to approve each fix run first. Requires the Master-Debt Auto-Fixer feature to be enabled separately. Because each fix run is a paid session, the OFF default lets you control the spend.

---

## Auto-remediate infrastructure alerts {#autoRemediateAlertsEnabled}

When an Omniscio infrastructure alert fires (cloud fleet degraded, auto-lander health, worktree or database health, freeze-prevention gate degraded), Omniscio automatically launches a background session into the Omniscio project to investigate and fix it — once per problem, with a global cap — then archives the alert card. When OFF, the card sits passively for you to act on. Because a fix session costs money, the OFF switch lets you approve each one.

---

## Redact pasted secrets {#redactPastedSecrets}

When ON, API keys and secrets you paste into a chat message are replaced with a placeholder before the message is saved to disk, so your keys are not stored in plain text in the local database. The agent still receives the real key in the outgoing request so it can act on it. Turn OFF only if the redaction interferes with a specific workflow.

---

## Email diagnostics to the team {#telemetryEmailEnabled}

Master switch for Omniscio's outbound diagnostic emails from this installation. When ON (default), a weekly usage digest is sent, plus individual crash reports (unless you turn off the crash email below). When OFF, both are silenced. On-disk crash logs, Sentry error triage, and all in-app diagnostics continue regardless.

---

## Email crash reports {#crashAlertEmailEnabled}

When ON (default, and requires diagnostic emails to be on above), Omniscio emails the team on each crash as it happens. When OFF, only the weekly digest is sent — crashes still auto-triage inside Omniscio via Sentry, and the local crash log continues unchanged.

---

## Email bug reports & feedback {#bugReportEmailEnabled}

When ON (default), clicking the bug-report icon, sending feedback, or reporting a missed question widget sends your report to the Omniscio team through **two** channels: email (Resend) and the bug database (Firestore).

When OFF, **none** of them fires — the report is written to the local disk fallback
(`<userData>/bug-reports/…json`, the same outbox the retry drain reads — its 20 most recent reports
are kept) and stays on your computer; the retry drain sends nothing while the switch is off, and the
kept reports go out once you turn it back on.

> **Changed by the privacy audit.** This toggle used to gate the email leg ONLY, while a
> submission actually fanned out to both destinations — so the one control a user was offered
> silenced one of two, and the copy said so out loud. Firestore's only gate was
> `bugReportTransport`, which was declared in the settings types
> but wired into no settings schema, so neither the UI nor the CLI could change it. The switch now
> means what it says.

---

## Developer messages {#developerMessagesEnabled}

When ON (default), you receive announcements, surveys, and read-receipt events from the Omniscio team inside the app. When OFF, all of these are silenced from this installation.

---

## Performance & interaction tracing {#diagnosticTracingEnabled}

When ON, Omniscio records freeze/long-task and click-latency timing to local troubleshooting log files (renderer diagnostics and `interaction.log`). **Off by default** — until you turn it on, no timing data is being collected, so switch it on *before* you reproduce a freeze if you want that data to exist. Turning it OFF stops that local logging and removes the small overhead it adds to the main process. Crash reports, error logs, and the heartbeat freeze recorder stay on regardless. Nothing is sent anywhere — all data stays on your computer.

---

## Track which UI controls you use {#usageTrackingEnabled}

When ON (default), Omniscio records which buttons, menus, and sidebar integrations you actually use, powering the "UI Usage" panel where you can see what is used versus never used and decide what to hide or remove. The report stays on this device. Anonymous click counts also ride the weekly diagnostics digest when diagnostic emails are on. Turn OFF to stop all usage recording.

---

## Capitalize tasks automatically {#autoCapitalizeTasks}

When ON, the first word of a task and the start of each sentence are auto-capitalized as you type — skipping URLs, file paths, and abbreviations. Matches the behavior of the Vault notes app. On by default; turn it OFF if you would rather capitalize manually.

---

## Automatically tidy away controls you never use {#autoTidyEnabled}

When ON, Omniscio moves sidebar integrations and toolbar icons you have not used in 30 or more days into a quiet "Unused" group or the "…" overflow to reduce clutter, and notifies you in the inbox. Nothing is deleted — you can restore anything from the list at any time. Off by default; turn ON if you want the sidebar to stay lean on its own.

---

## Bookmarks CLI access {#bookmarksCliEnabled}

When ON (default), external agents can list, create, update, delete, reorder, and launch bookmarks over the local CLI control server. Turn OFF to disable all bookmark CLI access from this installation at once without touching individual bookmark settings.

---

## Pre-compute codebase stats in the background {#codebaseStatsBackgroundEnabled}

When ON (default), Omniscio quietly analyzes and caches each hub's codebase stats (size, languages, git activity, code health) in the background so the "Codebase Stats" view opens instantly. The analysis is heavily throttled — one hub at a time, only changed content, and it backs off when the machine is busy — so it never slows things down. Dependency security scans still run only on demand when you open a hub and refresh.

---

## Custom format block {#customFormatBlockEnabled}

When ON, Omniscio silently adds a short, editable formatting standard to the first message of each new session, alongside the question-widget hint, so the agent shapes its responses to be easy to skim. You can edit the exact text in the field below. Turn OFF to stop the hint from reaching the model entirely.

---

## Support chat {#supportChatEnabled}

When ON (default), the support chat icon appears in the toolbar, giving you a direct line to the Omniscio team from within the app. When OFF, the icon is hidden and the chat channel is disabled from this installation.

---

## Support chat operator mode {#supportChatOperator}

When ON, all support conversations from every user are visible in your inbox — intended for the Omniscio support team. When OFF (default), you see only your own conversations. Only visible when Support chat is enabled above.

---

## Log level {#logLevel}

Controls how much detail is written to the local log file. Options (each includes all levels below it): **Error** — critical failures only; **Warn** — errors and warnings; **Info** — general operational events (recommended for everyday use); **Verbose** — detailed operational events, useful when troubleshooting; **Debug** — everything, including low-level internals. Default is `info`. Switch to `verbose` when investigating an issue, then switch back to avoid log growth.

---

## Catch follow-ups when a session ends {#tasksV2CatchesEnabled}

When ON (default), after a session ends or is archived, a quick AI pass reads its transcript for any follow-up tasks and stages them in the Caught view for you to approve or dismiss. When OFF, no scan happens — no transcript is read and no AI spend is incurred. Requires the Tasks feature to be active.

---

## Tasks memory (learned planning context) {#tasksV2MemoryEnabled}

When ON (default), Omniscio journals what you planned versus finished each day so the AI can learn your real patterns — typical daily capacity, chronic carry-overs, and tasks you keep snoozing. Reading the stored journal data is free (no AI calls); AI calls happen only when the arrange/check-in features actively use that context.

---

---

## Support chat display name {#supportChatUserName}

The name shown on the messages you send in support chat. Type whatever you'd like the support team to see beside your messages — usually your first name or full name. It only changes how your name appears in that chat; it doesn't affect your account anywhere else. Leave it blank to fall back to the default. This field only appears once support chat is turned on.

---

## Follow-up catching guidance {#tasksV2CatchesGuidance}

Optional free-text guidance that steers which follow-up tasks the AI "catches" from your finished sessions. Describe, in your own words, what makes a follow-up worth keeping — for example "only things I still owe someone" or "skip anything about code." The AI uses it to decide which suggestions to keep; the format it returns is fixed, so rewording this can never break catching. Leave it empty for the standard behavior. It only matters when follow-up catching (above) is turned on.
