Core concepts

Permissions

Control what Morbium agents may do: allow, ask before, or deny each action, with granular rules, wildcards, and per-agent overrides.

Permissions decide what an agent is allowed to do without checking with you first. Every tool maps to an action, and each action can be set to allow, ask, or deny.

  • allow: the agent does it without asking.
  • ask: the agent pauses and asks for your approval.
  • deny: the agent cannot do it at all.

Permissions live in your config under the permission key, and each agent can override them.

Actions

You can set permissions for these actions:

read, edit, glob, grep, list, bash, task, external_directory, todowrite, question, webfetch, websearch, and skill.

A simple config that asks before any edit or shell command, and allows everything else:

{
            "permission": {
              "edit": "ask",
              "bash": "ask"
            }
          }
          

Granular rules

Instead of a single value, an action can take a set of pattern rules. The pattern is matched against the thing being acted on (a file path, a shell command), and the last matching rule wins, so order matters.

Allow edits everywhere except a secrets file, and allow most shell commands but never rm -rf:

{
            "permission": {
              "edit": {
                "**/*": "allow",
                "**/.env": "deny"
              },
              "bash": {
                "*": "allow",
                "rm -rf *": "deny"
              }
            }
          }
          

Patterns support wildcards (* within a segment, ** across segments). A leading ~ or $HOME in a path expands to your home directory.

External directories

Morbium works inside your project folder. When an agent needs to read or write outside it, that is gated by the external_directory action, so you stay in control of anything that reaches beyond the project.

Per-agent permissions

Each agent has its own permissions, merged on top of the global ones. This is how the specialists stay safe:

  • The Plan agent denies all editing, which is what makes it read-only.
  • The board designer can only edit board files, nothing else.
  • The fabricator can only edit 3D model files.

You can set the same overrides on your own agents. See Custom agents.

Next steps

  • Config: where permissions live.
  • Tools: the actions permissions apply to.