Safety & control

Permissions & guardrails

How Reigh keeps a team of autonomous agents safe — autonomy levels, approvals, deny rules, loop protection and recovery.

Reigh is designed so you can leave a team running without worrying about it. Several layers work together.

Autonomy levels

Each person has an autonomy level, set on their profile or while hiring:

Level Behaviour
Intern Asks before every action
Staff May edit files; asks before running commands
Senior Acts on their own; risky actions are checked with you. Recommended, and the default.
Trusted Never asks. Every command runs without approval. Use only where breaking things is cheap.

Reigh’s own office tools, like messaging, tasks and memory, never need approval.

Permission requests

When someone needs permission, the request appears in your Inbox showing the exact command, file or URL. You can:

  • Approve once — allows this exact request, one time.
  • Always allow — lets this person use that tool from now on without asking. For a tool like Bash, that means every future command, so use it deliberately.
  • Deny, with an optional note.

The tool call waits up to ten minutes for you. If you’re away, the agent moves on and retries once you’ve decided.

Approvals for big moves

Separately from tool permissions, agents are told to ask before anything irreversible or that leaves your Mac: spending money, publishing, deploying, pushing to a shared branch, deleting data they didn’t create, or contacting people. These arrive as Approval items with the action, the reasoning, the risk and any estimated cost.

Pull requests need your approval by default too (Settings → Repositories).

Commands that are always blocked

Whatever their autonomy, nobody on the team can run:

git push --force
git push -f
rm -rf /
rm -rf ~
sudo

These rules also apply when you take the wheel of someone’s session in the terminal.

Loop protection

Two agents replying to each other forever is a real risk. Every reply increases a thread’s hop count, and when it passes the limit (6 by default) the message isn’t sent: the thread stops, the agent is told to stop replying, and you get a Loop stopped item. Change the limit in Settings → Workspace → Loop protection.

The org also limits who can message whom. People can reach their manager, direct reports, peers, their department and anyone below them, and managers can reach other managers. Anything else goes through a manager.

Staying in scope

Agents are told to do exactly what was asked: if you ask for a plan, they deliver a plan and stop. Managers write the scope into every delegation’s BOUNDARIES. Agents can’t put themselves into plan mode; only you can, from the composer.

Crashes and stalled work

  • Crashes. If Reigh quits mid-turn, the next launch marks those runs as crashed, cleans up leftover processes, and sends anyone who was working a Resume after restart message. Turn this off in Settings → Agents → Auto-resume after a crash. Permission prompts that were open expire, and agents ask again if they still need to.
  • Stalled work. If a task has been in progress with no activity for a while (8 minutes by default) and its assignee isn’t busy, Reigh nudges them to pick it up — at most once every 30 minutes per task. Change or turn this off in Settings → Agents → Pick up stalled work.
  • Work you stopped stays stopped. If you interrupt someone, Reigh won’t nudge them to restart it.

Pausing

Pause anyone from their page, their card on the Floor, or the sidebar. Paused people receive no new work until you resume them.