Safety
An agent that can't wreck your machine
An agent in Olli cannot delete what is outside your project, rewrite its own config, or touch production without your explicit approval. Here is how.
One checkpoint
Every action, from every agent, takes the same path
File edits, shell commands, git, network calls and tools from other servers all go through the same five steps. Nothing has a side door.
- 01
Policy
Allow, ask or deny, from rules you can read. A risk score from 0 to 100, worked out without asking the model.
- 02
Approval
Anything risky waits for you, with the exact command shown as plain text.
- 03
Checkpoint
A snapshot is taken before the change, so you can undo it.
- 04
Sandbox
The action runs inside an operating system sandbox, with network traffic through a proxy.
- 05
Event log
What happened is written to a tamper-evident log for the session.
Risk tiers
The riskier the action, the more Olli asks
Every block shows the rule and a plain reason, with a "Why?" view. Presets range from strict to trusted workspace, and no preset can switch off the firewall or protected paths.
| Tier | Score | To approve |
|---|---|---|
| Low | 0 to 29 | Usually allowed automatically |
| Medium | 30 to 59 | One tap; similar actions can be approved together |
| High | 60 to 84 | A short reason and a second check that it is you |
| Critical | 85 to 100 | A second approver and a short delay against reflex clicks |
In the alpha, critical actions are always denied. Risk-tiered approvals arrive in beta.
Layers
Seatbelts, all the way down
An operating system sandbox
Seatbelt on macOS, bubblewrap and Landlock on Linux, restricted tokens on Windows. The agent can write only inside your project. If the sandbox cannot start, Olli refuses to run commands rather than running them unprotected.
A destructive-command firewall
Deleting outside your project, formatting disks and force-pushing to protected branches are always denied. Commands like git reset --hard, DROP TABLE and terraform destroy need your approval.
A network proxy
All sandbox traffic goes through a local proxy with an allowlist. Unknown hosts ask you, or are denied when no one is watching. Secrets are added at the proxy and never exist inside the sandbox.
Checkpoints and undo
A snapshot before every change, kept for at least 14 days, in a history separate from your own git.
Protected config
The agent can't rewrite its own settings, your policy files or other sensitive paths, and workspace trust stops a repository from loosening your rules.
An audit trail
A hash-chained event log for every session and clear trailers on AI-assisted commits.
Prompt-injection defence
Olli tracks untrusted content. An action that would mix untrusted input, sensitive data and outbound traffic is escalated to you.
Session replay
Step back through what an agent did and why, action by action.
Your code stays yours
Source code does not leave your machine by default. Model calls go from your machine straight to the provider you chose, with your own keys. Anything that would send data elsewhere, such as cloud runners or shared replays, is off until you turn it on, and all of it is listed on one page in settings. Telemetry is off by default.
Honest about limits
No sandbox is perfect, and we won't claim one is. Olli ships a sandbox self-test you can run yourself, we publish what we test, and every release notes any change to safety behaviour. If you find a way around a protection, tell us at support@oltinolli.com with "Security" in the subject.
See the seatbelts for yourself
Olli is in a private alpha with a small group of developers. Tell us what you build and we'll be in touch.