How much Kyra asks
By default Kyra asks before doing anything with consequences. That is the right default, and for a while it is also the right experience — you are finding out what it does, and a question is cheap.
It stops being right when the answer is always yes. Being asked “are you sure?” for the thousandth time is not consent, it is a reflex — and a reflex yes is less informed than one decision made properly.
So the decision moves up a level. You say once what you want, and it holds.
Setting it
Section titled “Setting it”kyra consent # what is in force right nowkyra consent posture trusted # about you, across the accountkyra consent sensitivity low # about one place — usually your editorkyra consent clear # back to normalOr Portal → Settings → Desktop control, which does the same thing in one place.
Reading it happens in the terminal. Changing it finishes in the browser — the last three commands print a link and a short code, you confirm there, and the terminal reports what is now in force:
This needs your confirmation in a browser:
Set your posture to trusted. Kyra will act without asking — but only at targets you have declared low.
Open: https://kyra-hi.com/settings/desktop-control/confirm?code=RTBK-9WQMand confirm the code: RTBK-9WQMWhy the browser step, when you were already typing
Section titled “Why the browser step, when you were already typing”Because of what you were typing into. The credential on that machine is the one that lets Kyra run code there — that is its whole job — so anything it can change on its own is something a compromise of that machine can change on its own.
And these settings are not local. They belong to your account, so a machine that could
set them by itself could mark your real editor low from a throwaway container, which is
exactly the travelling switch the two halves below exist to prevent. Confirming in the
browser is a few seconds, for a setting you will change about twice a year, and it is what
keeps “I decided this” true rather than merely likely.
Two settings, and they have to agree
Section titled “Two settings, and they have to agree”There is a deliberate reason this is not one “stop asking me” switch.
That switch travels. You turn it on for a throwaway container on a Tuesday, and it is still on in October when you point the same account at something that matters.
So it is split into two halves that mean different things, and Kyra skips a question only where both hold.
Posture: how involved you want to be
Section titled “Posture: how involved you want to be”About you. Applies to your whole account.
| Posture | Means |
|---|---|
plan | Kyra tells you what it would do and changes nothing. |
ask | Kyra asks before anything with consequences. The default. |
trusted | Kyra may act without stopping — but only where the second half says so. |
plan is worth knowing about even if you never leave ask. It is what makes “walk me
through what you’d change on the production box” a safe sentence: there is no path from
a planning session to a change, so you can think out loud without watching your words.
Sensitivity: what a mistake costs there
Section titled “Sensitivity: what a mistake costs there”About one place. You declare it per target.
| Sensitivity | Means |
|---|---|
low | Cheap to get wrong. A dev container, a scratch checkout, a test tenant. |
normal | The default, and what anything undeclared counts as. |
high | Expensive to get wrong. Kyra asks even when it could undo the change. |
high is not merely the absence of relief — it changes behaviour in the other
direction. Normally a change Kyra can undo is announced rather than confirmed, because
“I renamed it, say the word and I’ll put it back” is a better experience than a dialog.
Where mistakes are expensive that reasoning breaks down — undo only helps if you notice
in time — so Kyra asks first.
Naming a target
Section titled “Naming a target”With no target, sensitivity and clear act on your editor. To name something else:
kyra consent sensitivity high --target com.kyra_hi.vscode.insidersA declaration covers everything under it
Section titled “A declaration covers everything under it”Target ids are hierarchical, and a declaration applies to the id you name and
everything beneath it. So com.kyra_hi.vscode means “my editor” — every window, every
machine — which is what a person means when they say it.
The most specific declaration wins, so these coexist happily: the editor family is disposable except the one variant you singled out.
kyra consent sensitivity low # the editor familykyra consent sensitivity high --target com.kyra_hi.vscode.insidersA declaration only ever names an application, never one window on one machine. That is deliberate: a claim pinned to a window would stop applying the next time you opened one, which is not what anybody means.
What no setting will relieve
Section titled “What no setting will relieve”Two kinds of action always ask, whatever you have set. Neither is a limitation intended to be removed.
Anything that leaves your machine. Sending, calling, posting, paying. A disposable environment is a claim about being able to recover the environment — an email has already left it. No container un-sends it.
Anything the application cannot verify it did. When Kyra is driving through accessibility interfaces, or worse from pixels, the application cannot actually confirm what changed — so its offer to undo is exactly as unverified as the change was. A relaxed setting rests on being able to get back; where that cannot be checked, it does not apply.
Changing permissions is on the same list — including changing these settings.
Reviewing it afterwards
Section titled “Reviewing it afterwards”Every action Kyra takes is recorded with the posture and sensitivity that were in force, and with how the question was settled: asked and agreed, announced, or relieved.
So “what did it do while I wasn’t watching, and under what claim?” is answerable after the fact rather than a matter of trust.
Relief removes the question. It never removes the record, and it never removes the way back.
Choosing
Section titled “Choosing”A shape that works well:
kyra consent posture trusted # you have decided how involved you want to bekyra consent sensitivity low # …and only your editor is disposableLeave everything else alone. Anything undeclared is normal, so the strict behaviour is
what you get by default and by omission — you have to say something for that to change.