Safety

An agent that can't wreck your machine

An agent in Olli cannot delete what is outside your project, rewrite its own config, or touch production without your explicit approval. Here is how.

One checkpoint

Every action, from every agent, takes the same path

File edits, shell commands, git, network calls and tools from other servers all go through the same five steps. Nothing has a side door.

  1. 01

    Policy

    Allow, ask or deny, from rules you can read. A risk score from 0 to 100, worked out without asking the model.

  2. 02

    Approval

    Anything risky waits for you, with the exact command shown as plain text.

  3. 03

    Checkpoint

    A snapshot is taken before the change, so you can undo it.

  4. 04

    Sandbox

    The action runs inside an operating system sandbox, with network traffic through a proxy.

  5. 05

    Event log

    What happened is written to a tamper-evident log for the session.

Risk tiers

The riskier the action, the more Olli asks

Every block shows the rule and a plain reason, with a "Why?" view. Presets range from strict to trusted workspace, and no preset can switch off the firewall or protected paths.

TierScoreTo approve
Low0 to 29Usually allowed automatically
Medium30 to 59One tap; similar actions can be approved together
High60 to 84A short reason and a second check that it is you
Critical85 to 100A second approver and a short delay against reflex clicks

In the alpha, critical actions are always denied. Risk-tiered approvals arrive in beta.

Layers

Seatbelts, all the way down

In the private alpha

An operating system sandbox

Seatbelt on macOS, bubblewrap and Landlock on Linux, restricted tokens on Windows. The agent can write only inside your project. If the sandbox cannot start, Olli refuses to run commands rather than running them unprotected.

In the private alpha

A destructive-command firewall

Deleting outside your project, formatting disks and force-pushing to protected branches are always denied. Commands like git reset --hard, DROP TABLE and terraform destroy need your approval.

In the private alpha

A network proxy

All sandbox traffic goes through a local proxy with an allowlist. Unknown hosts ask you, or are denied when no one is watching. Secrets are added at the proxy and never exist inside the sandbox.

In the private alpha

Checkpoints and undo

A snapshot before every change, kept for at least 14 days, in a history separate from your own git.

In the private alpha

Protected config

The agent can't rewrite its own settings, your policy files or other sensitive paths, and workspace trust stops a repository from loosening your rules.

In the private alpha

An audit trail

A hash-chained event log for every session and clear trailers on AI-assisted commits.

Coming in beta

Prompt-injection defence

Olli tracks untrusted content. An action that would mix untrusted input, sensitive data and outbound traffic is escalated to you.

Coming in beta

Session replay

Step back through what an agent did and why, action by action.

Your code stays yours

Source code does not leave your machine by default. Model calls go from your machine straight to the provider you chose, with your own keys. Anything that would send data elsewhere, such as cloud runners or shared replays, is off until you turn it on, and all of it is listed on one page in settings. Telemetry is off by default.

Honest about limits

No sandbox is perfect, and we won't claim one is. Olli ships a sandbox self-test you can run yourself, we publish what we test, and every release notes any change to safety behaviour. If you find a way around a protection, tell us at support@oltinolli.com with "Security" in the subject.

See the seatbelts for yourself

Olli is in a private alpha with a small group of developers. Tell us what you build and we'll be in touch.