Docs · 4 min read
AI with root access, safely: modes, approvals and a kill switch
What your AI may do on its own, what needs you, and how to stop everything.
Every action has a risk level
Reading (logs, files, status) runs at once. Changes (installing packages, editing config) run after /etc is saved. Destructive actions (deleting folders, dropping databases, changing SSH or the firewall, removing packages, deleting users or plugins) wait for your approval. A few things are never allowed, such as reading the agent's own key.
Approving
- Your AI gives you a link, and you get an email.
- Open it signed in to sudowhizzy.com and read exactly what will run.
- Approve and run once, or Deny. Tell your AI it is approved; it repeats the call with the approval id.
- An approval runs once, only with exactly the arguments you saw, within 30 minutes.
Approving needs you signed in, which your AI never is. Text planted in a log file or web page cannot approve anything.
Modes per server
Read-only: your AI can only look. Normal: the default described above. Full trust: nothing asks, everything is still logged; use it when you are watching a big job. Change modes on the Servers page.
Stop
Pause one server or everything on the Servers page. Disconnect stops the agent for good. On the server itself: systemctl disable --now sudowhizzy-agent.
Free connects one server in read-only mode: your AI can look, read logs and explain what is wrong.
Connect your server