Approvals, Autopilot and pick up anywhere
What Remi asks before it acts and how you answer, what Autopilot still asks about, and how to answer from another device.
Remi asks before it does things you might not want, such as creating something, acting in one of your apps or deleting. You answer each request, or allow an action for the rest of a chat.
Answer a request
When Remi needs your OK, it stops and shows what it wants to do, for example Remi wants to send an email, with the recipient, subject and message. The choices are in the message box, and which ones you see depends on the request:
| Choice | What it allows |
|---|---|
| Allow once | This action, this time. Remi asks again next time. |
| Allow in this chat | The same action for the rest of this chat, without asking again. |
| Always | The same action in that app, in every chat, until you revoke it. Offered only for actions in your apps. |
| Deny | Nothing: Remi doesn't do it. |
- To have Remi do something else instead, type it in the message box, which reads Or tell Remi what to do instead…, and send it.
- When Remi wants to delete something, it offers only Allow once and Deny, so it asks every time.
- When more than one request is waiting, Remi shows them one at a time, with how many more approvals are needed.
What Remi asks about
Remi asks before it:
- creates a document, data table, task, project, workspace or workflow, copies a workflow, invites someone, makes an image, video or audio, or changes your profile. It asks each time, unless you've chosen Allow in this chat for that action;
- does something in a connected app that changes something, such as sending an email or adding a calendar event. Reading, such as searching your mail, goes ahead without asking;
- uses any tool of an app you added by its MCP server address, unless the app marks that tool as read-only.
Workflows run with nobody to ask, so they follow their own rules: see What a workflow does without asking.
Take back a permission
- For one chat: in the sidebar, point at the chat, select …, then Permissions. It lists what you allowed for the rest of that chat. Select Revoke on any of them, and Remi asks again next time.
- For an app: select your email address at the bottom of the sidebar, then Integrations, and open the app. On its Tools tab, Standing decisions lists the tools you allowed or blocked for good. Select Revoke, and Remi asks again next time.
Let Remi work on its own with Autopilot
Autopilot is a mode for sessions that work in a folder on your computer, in the Remi CLI and Remi Desktop. Which app is for what shows whether each one is out yet.
In Autopilot, Remi edits files and runs commands without asking. Commands run in a sandbox that can only write in the project folder, temporary folders and tool caches. In the Remi CLI, the sandbox also can't reach the network.
To turn it on:
- Remi CLI: press Shift+Tab until the mode under the input box reads Autopilot, or type
/autopilot. To start in it, runremi --mode autopilot. - Remi Desktop: in Settings, under Models and permissions, turn on Allow Autopilot. Then choose Autopilot from a folder session's Mode menu. If you turn Allow Autopilot off again, sessions on Autopilot go back to Edit freely.
Where there's no sandbox, Autopilot still asks before every command: on Windows, and on Linux without bwrap installed. Remi Desktop says so under Allow Autopilot when the computer can't sandbox commands.
What Autopilot always asks about in the Remi CLI
Even in Autopilot, the Remi CLI asks before a command that:
- Needs the network, such as
git push,git pullorgit clone; installing or publishing packages with npm, pnpm, yarn, bun, pip, uv, cargo, go, gem or brew, or runningnpx;curl,wget,ssh,scporrsync; and tools such asgh,aws,gcloud,kubectl,terraformanddocker. - Names a file that may hold secrets, such as
.envfiles, keys and credentials. Templates such as.env.exampledon't count. - Throws away git history that undo can't bring back, such as
git reset --hard,git clean,git stash drop,git branch -Dand rebases. - Deletes files, with
rm,rmdir,unlink,shred,trashorfind … -delete. - Runs as another user, with
sudo,doas,suorpkexec. - Reaches outside the project folder, with an absolute path,
~or... Temporary folders are fine. - Is too complex to check, such as
$(…), backticks,eval, or code passed straight to an interpreter, such aspython -cornode -e.
Edits go ahead in Autopilot, except to files that change how Remi and your tools behave. Those always ask: .remi/, .claude/, .git/hooks, .git/config, .mcp.json, .husky/, .vscode/ and .envrc.
What Autopilot always asks about in Remi Desktop
Even in Autopilot, Remi Desktop asks before a command that:
- Deletes files, such as
rm,git rmorgit clean. - Installs software, with a package manager such as npm, pnpm, yarn, pip, cargo, brew or apt, or runs a package straight from the internet, such as
npxorcurl … | sh. - Signs in, such as
npm login,gh auth,docker loginorgcloud auth. - Sends work out of your computer, such as
git push, publishing a package, deploying, orssh,scpandrsync. - Runs as another user, with
sudo,doasorsu. - Is too complex to check, such as
$(…), backticks,eval,xargsorsh -c.
Other commands run in the sandbox without asking, including ones that use the network. Edits go ahead, except to .mcp.json, which always asks. So does every tool of a connected app.
Pick up a chat on another device
Chats on the web, your phone and Remi Desktop share one list. Open the chat on whichever device is closest and carry on. On the web, a request Remi is still waiting on shows when you open the chat, and you can answer it there.
Pick up a folder session from another device
A session working in a folder on your computer, in the Remi CLI or Remi Desktop, stays in that app and isn't in your chat list. While it's open, you can still carry it on from the web, your phone or another computer. What you send from there runs on the computer that has the folder, with that folder's rules.
- In the Remi CLI, type
/handoffto open the chat on the web or your phone. - Send a message there. Remi works in the folder on your computer, and the answer shows in both places.
When Remi needs your permission, the request shows on your other devices too, and you get a notification that Remi is waiting for your OK. Select the notification to open the chat. On the web, answer with Allow once, Allow in this chat or Deny. The first answer wins, wherever it comes from.
- The computer has the final say. Every answer is checked again against the folder's rules before anything runs, and a deny rule always wins.
- Allow in this chat from another device allows that exact command, or that one file, again for the rest of the session. For a protected file or an MCP tool, it allows the call just once.
- A request nobody answers in time expires, and counts as a no.
- If a request waits a minute on your computer without an answer, your phone is asked too.
- Stop works from any device.
- If the computer is off, asleep or offline, Remi can't reach the folder, so it answers without it.
Bring the session back to your computer
The last place you typed in, or chose to continue in, is the one that serves your other devices. To bring a session back, type in it on your computer. Or:
- in the Remi CLI, type
/host; - in Remi Desktop, select Continue here, which shows when the session has moved somewhere else.
To stop a CLI session taking messages from your other devices, type /host off, or start it with remi --no-host. Pick up anywhere doesn't work with remi -p, or when the CLI is signed in with an access token (REMI_TOKEN).