Inspect the boundary before a workflow
- Ask your coding agent
- Run in terminal
Explain the effective RELAI permission profile and path restrictions for this repository without changing anything. Do not reveal credential or environment values. Tell me which reads, writes, and commands would pause for approval.
Choose an approval profile
relai setup records auto when no global profile exists. On commands that expose it, --permissions overrides the global profile for that invocation. Simulation and
optimization do not expose this flag; check nested --help.
Know which configuration owns each rule
Resume resolves the profile again. Repeat the override when you need the same boundary, for example
relai init --resume --permissions ask.
Restrict project paths
Read and write rules use Gitignore-style patterns relative to the repository root. A presentallow list is complete; allow = [] allows nothing. Global and project allowlists intersect, while all deny rules combine. Denials and built-in protections always win.
[permissions] profile only in ~/.relai/config.toml, never in the project file.
Two similarly named files have different scope.RELAI does not read
.relaiignore. .relai-snapshotignore affects only source text sent to Agent Optimizer: matching files stay in the optimizer worktree for runtime access and are not deleted. It does not change ordinary workflow permissions.Keep credentials and runtime values separate
~/.relai/credentials.json
OAuth access and refresh tokens are plaintext in a user-only file: mode
0600 on Unix and a user-only ACL on Windows. They are not stored in config or CLI logs. Anyone who can read files as your user can read them, so never share or commit this file..relai/simulator.env
Ignored local values are deliberately forwarded to the Harbor agent phase during simulation and optimization. Store only values the tested agent or its tools need, and keep them out of chat and Git.
.env.example as a template, but cannot write or mount it. Add project-specific secret paths to permissions.read.deny.
Ready to initialize?
Use the profile and path boundary you chose while RELAI builds the shared project runtime.