Skip to content

How much Kyra asks

By default Kyra asks before doing anything with consequences. That is the right default, and for a while it is also the right experience — you are finding out what it does, and a question is cheap.

It stops being right when the answer is always yes. Being asked “are you sure?” for the thousandth time is not consent, it is a reflex — and a reflex yes is less informed than one decision made properly.

So the decision moves up a level. You say once what you want, and it holds.

Terminal window
kyra consent # what is in force right now
kyra consent posture trusted # about you, across the account
kyra consent sensitivity low # about one place — usually your editor
kyra consent clear # back to normal

Or Portal → Settings → Desktop control, which does the same thing in one place.

Reading it happens in the terminal. Changing it finishes in the browser — the last three commands print a link and a short code, you confirm there, and the terminal reports what is now in force:

This needs your confirmation in a browser:
Set your posture to trusted. Kyra will act without asking — but only at targets
you have declared low.
Open:
https://kyra-hi.com/settings/desktop-control/confirm?code=RTBK-9WQM
and confirm the code: RTBK-9WQM

Why the browser step, when you were already typing

Section titled “Why the browser step, when you were already typing”

Because of what you were typing into. The credential on that machine is the one that lets Kyra run code there — that is its whole job — so anything it can change on its own is something a compromise of that machine can change on its own.

And these settings are not local. They belong to your account, so a machine that could set them by itself could mark your real editor low from a throwaway container, which is exactly the travelling switch the two halves below exist to prevent. Confirming in the browser is a few seconds, for a setting you will change about twice a year, and it is what keeps “I decided this” true rather than merely likely.

There is a deliberate reason this is not one “stop asking me” switch.

That switch travels. You turn it on for a throwaway container on a Tuesday, and it is still on in October when you point the same account at something that matters.

So it is split into two halves that mean different things, and Kyra skips a question only where both hold.

About you. Applies to your whole account.

PostureMeans
planKyra tells you what it would do and changes nothing.
askKyra asks before anything with consequences. The default.
trustedKyra may act without stopping — but only where the second half says so.

plan is worth knowing about even if you never leave ask. It is what makes “walk me through what you’d change on the production box” a safe sentence: there is no path from a planning session to a change, so you can think out loud without watching your words.

About one place. You declare it per target.

SensitivityMeans
lowCheap to get wrong. A dev container, a scratch checkout, a test tenant.
normalThe default, and what anything undeclared counts as.
highExpensive to get wrong. Kyra asks even when it could undo the change.

high is not merely the absence of relief — it changes behaviour in the other direction. Normally a change Kyra can undo is announced rather than confirmed, because “I renamed it, say the word and I’ll put it back” is a better experience than a dialog. Where mistakes are expensive that reasoning breaks down — undo only helps if you notice in time — so Kyra asks first.

With no target, sensitivity and clear act on your editor. To name something else:

Terminal window
kyra consent sensitivity high --target com.kyra_hi.vscode.insiders

Target ids are hierarchical, and a declaration applies to the id you name and everything beneath it. So com.kyra_hi.vscode means “my editor” — every window, every machine — which is what a person means when they say it.

The most specific declaration wins, so these coexist happily: the editor family is disposable except the one variant you singled out.

Terminal window
kyra consent sensitivity low # the editor family
kyra consent sensitivity high --target com.kyra_hi.vscode.insiders

A declaration only ever names an application, never one window on one machine. That is deliberate: a claim pinned to a window would stop applying the next time you opened one, which is not what anybody means.

Two kinds of action always ask, whatever you have set. Neither is a limitation intended to be removed.

Anything that leaves your machine. Sending, calling, posting, paying. A disposable environment is a claim about being able to recover the environment — an email has already left it. No container un-sends it.

Anything the application cannot verify it did. When Kyra is driving through accessibility interfaces, or worse from pixels, the application cannot actually confirm what changed — so its offer to undo is exactly as unverified as the change was. A relaxed setting rests on being able to get back; where that cannot be checked, it does not apply.

Changing permissions is on the same list — including changing these settings.

Every action Kyra takes is recorded with the posture and sensitivity that were in force, and with how the question was settled: asked and agreed, announced, or relieved.

So “what did it do while I wasn’t watching, and under what claim?” is answerable after the fact rather than a matter of trust.

Relief removes the question. It never removes the record, and it never removes the way back.

A shape that works well:

Terminal window
kyra consent posture trusted # you have decided how involved you want to be
kyra consent sensitivity low # …and only your editor is disposable

Leave everything else alone. Anything undeclared is normal, so the strict behaviour is what you get by default and by omission — you have to say something for that to change.