The ledger
Every write and every Rewind, by you, saferow’s agent or an MCP client, is in the ledger (⌘L): its statement, its count, how it was approved (directly, by click or by Touch ID), who asked and when. MCP changes say “MCP · Claude Code”, or whichever client it was. The ledger is kept on your Mac and never pruned.
Restore points
Before a write runs, saferow saves the rows it will change, on your Mac. Restore points are kept for 7 days on the free tier and 30 days with Pro; moving from Pro to Free never shortens one already made. After that, the ledger entry stays and says the restore point expired.
Rewinding a change
Press Rewind on a ledger entry. saferow turns the restore point back into SQL and shows it: “Puts back 3 rows as they were before 21:41.” A Rewind is a change like any other: counted and held for your approval, with Touch ID on production.
If someone changed some of those rows since, saferow says “Rewind conflicts with 2 rows” and skips them, unless you tick Include the conflicting rows too, which overwrites their newer values.
What can’t be rewound
- Rows in a table with no primary key, upserts, and updates that change the primary key.
- Privileges, files and settings.
- Schema changes, except a named CREATE INDEX or ADD COLUMN, or a change that came with its own down migration.
- A Rewind itself.
Such entries say “No way back” in the ledger.