Skip to main content
Tools let agents read files, search code, edit workspaces, run commands, fetch web content, query integrations, and perform security analysis.

Permission outcomes

Each request is evaluated against ordered rules and resolves to:
  • Allow: execute without prompting.
  • Ask: pause and request your approval.
  • Deny: reject the operation.
Rules can match tool names, filesystem patterns, commands, URLs, metadata, or agent/session policy. More specific rules should be preferred over broad permanent allowances.

Location scope

Filesystem services, tools, providers, and permissions belong to the location that owns the session. Access outside the workspace requires explicit external-directory authority.

Tool settlement

Tool calls are durable timeline parts with pending, running, completed, and error states. TurenOS settles in-flight calls before promoting queued input or completing a provider turn.

Risk boundaries

TurenOS is not a VM or container sandbox. Allowed shell commands and edits run with your user privileges. Read-only analyzers do not execute the target, but their results should still be treated as evidence rather than automatic truth. See Trust and permissions for safe defaults.