Docs · 4 min read

AI with root access, safely: modes, approvals and a kill switch

What your AI may do on its own, what needs you, and how to stop everything.

Every action has a risk level

Reading (logs, files, status) runs at once. Changes (installing packages, editing config) run after /etc is saved. Destructive actions (deleting folders, dropping databases, changing SSH or the firewall, removing packages, deleting users or plugins) wait for your approval. A few things are never allowed, such as reading the agent's own key.

Approving

  1. Your AI gives you a link, and you get an email.
  2. Open it signed in to sudowhizzy.com and read exactly what will run.
  3. Approve and run once, or Deny. Tell your AI it is approved; it repeats the call with the approval id.
  4. An approval runs once, only with exactly the arguments you saw, within 30 minutes.

Approving needs you signed in, which your AI never is. Text planted in a log file or web page cannot approve anything.

Modes per server

Read-only: your AI can only look. Normal: the default described above. Full trust: nothing asks, everything is still logged; use it when you are watching a big job. Change modes on the Servers page.

Stop

Pause one server or everything on the Servers page. Disconnect stops the agent for good. On the server itself: systemctl disable --now sudowhizzy-agent.

Try it on your own server

Free connects one server in read-only mode: your AI can look, read logs and explain what is wrong.

Connect your server
Next guide
Undo what your AI changed: snapshots, rollback and backups