| Tool policies | Choose which commands, domains, and file paths the AI can use |
| Limits | Set how many actions the AI can take before it pauses for your input |
| Snapshots | Undo any AI change with one click |
| Prompt injection defense | External content can’t hijack the AI |