Agentic Mode

Approvals and permissions


You decide which tools run. Nothing executes without a policy you control.

The approval prompt

When the AI wants to use a tool that isn't pre-approved, the run pauses and Kerlig asks you right in the chat window. The question appears in the input area and the actions list becomes your answer:

  • Approve: run the tool this once.
  • Always allow: run it now and never ask again for this tool. If the AI queued several calls to the same tool, they all proceed.
  • Deny: the tool doesn't run. The AI is told and continues without it.

Pressing Esc or closing the window cancels the run, and pending approvals count as denied.

Per-tool policies

Every tool has one of three policies, adjustable in Settings → MCP:

  • Allow: runs without asking. The default for built-in tools, which are all read-only.
  • Ask: approve the first use. The default for all MCP tools.
  • Deny: never offered to the model at all (and costs no tokens).

Always allow in the approval prompt is a shortcut for switching that tool's policy to Allow.

Per-action control

Independent of tool policies, each action decides whether tools are available at all. Only Ask (and typed follow-ups) uses tools by default. See the Use Tools switch in action preferences.

© 2026 Kerlig™. All rights reserved.