A write that saferow doesn’t run straight away is held: it waits for you, with an amber dot, in the conversation, in Mission control’s Needs you, and in the command bar (⌘K). Nothing runs until you approve it.
What is held
- An agent’s write plan, always, once, even on dev.
- Anything proposed through saferow mcp.
- Writes on production, writes that touch personal data, writes of more than 1,000 rows, and schema changes.
- Your own writes on local and dev run straight away, with a restore point first, unless one of those rules applies.
DROP, TRUNCATE and DELETE or UPDATE without WHERE are refused for agents and MCP clients on production and on personal data. You can still run them yourself in a SQL tab.
The approval sheet
Press Approve on a held change, or ⌘⇧A. The sheet says who is asking (you, saferow’s agent, or an MCP client), then:
- The count. “Counted just now with the same WHERE: 3 rows. The approval is bound to 3; if the count differs when it runs, it rolls back.”
- The way back. The rows are saved first, on this Mac, for Rewind.
- The dry run. It ran in a rolled-back transaction, with how long it took and how many triggers fired.
Plain Return never approves. The Approve button, Space on it, or ⌘⇧A do.
Touch ID and typed counts
- On production, approving needs Touch ID. The prompt names the count and the connection: “approve 3 row changes on saju · production”. A Mac without Touch ID asks in a system dialog instead.
- A statement that can’t be narrowed, such as a DELETE without WHERE or a DROP, is held until you type its count: “Type 212 to approve”.
When it runs
The change runs in one transaction. saferow counts the rows again as it runs, and if the number differs from the one you approved, it rolls back: “The count changed: 3 approved, 4 now. Nothing was changed.” If the schema changed since the plan, it asks you to re-plan.
A change nobody approves expires after 30 minutes (Settings › Safety can make it 15 minutes to 24 hours), and nothing runs.