Help · Safety

Approvals and Touch ID

What a held change is, what the approval sheet shows, when Touch ID or a typed count is needed, and what happens if the rows change before it runs.

A write that saferow doesn’t run straight away is held: it waits for you, with an amber dot, in the conversation, in Mission control’s Needs you, and in the command bar (⌘K). Nothing runs until you approve it.

What is held

DROP, TRUNCATE and DELETE or UPDATE without WHERE are refused for agents and MCP clients on production and on personal data. You can still run them yourself in a SQL tab.

The approval sheet

Press Approve on a held change, or ⌘⇧A. The sheet says who is asking (you, saferow’s agent, or an MCP client), then:

Plain Return never approves. The Approve button, Space on it, or ⌘⇧A do.

Touch ID and typed counts

When it runs

The change runs in one transaction. saferow counts the rows again as it runs, and if the number differs from the one you approved, it rolls back: “The count changed: 3 approved, 4 now. Nothing was changed.” If the schema changed since the plan, it asks you to re-plan.

A change nobody approves expires after 30 minutes (Settings › Safety can make it 15 minutes to 24 hours), and nothing runs.

Still stuck? In saferow, choose Help › Report a Problem…, or write to support. Please leave out passwords, keys and real data.