Permissions
Each conversation has two modes, set below the chat input: Ask every time and Allow all actions. New chats start with Ask every time. The choice applies to that conversation and is remembered when you reopen it, including after a restart.
Ask every time
Before the agent saves a strategy, runs a terminal command, executes code or acts in a browser, an approval card appears in Chat with the tool name and its arguments. Choose Allow once to run it, or Reject. Reading market data, charts and news runs without asking.
Allow all actions
Allow all actions lets those tools run in that conversation without individual confirmation. Switching to it also releases an action already waiting for approval. Switch back to Ask every time and the next action asks again.
Actions that ask first
| Tool | What it does |
|---|---|
terminal | Runs a shell command under your account, with credentials removed from its environment |
execute_code | Runs local JavaScript with file access limited to the task workspace |
browser_navigate, browser_click, browser_type, browser_back | Drives Chrome, or the browser set in SERIS_BROWSER_PATH |
strategy_save_draft | Writes a reviewed strategy to your data directory |
Stop
Tasks can continue through as many model and tool calls as they need. Stop in the chat input ends the active response at any time.
Who can change the mode
You change the mode in the app. It goes through Seris's authenticated UI, and a model request cannot switch it. SECURITY.md describes the permission model in detail.