What Allow once means
Allow once permits the exact waiting tool call past TraceRook’s review gate. It does not authorize the session, approve similar future commands, skip the host’s own permissions, or prove execution.
The fingerprint binds provider, session, turn when available, source tool-call ID, tool name, working directory, and canonical original input. When the host lacks a call identifier, a local invocation nonce distinguishes attempts. A redacted summary or command substring is not sufficient authorization.
Terminal state is written once
| State | Meaning |
|---|---|
| pending | Waiting on a live, bound invocation before its deadline |
| approved_once | The exact pending invocation was released past TraceRook |
| denied | The pending invocation was denied |
| expired | The review deadline passed; high-risk request denies |
| aborted | The invocation was invalidated by disconnect, end, or mismatch |
A transaction or compare-and-set operation must accept at most one terminal transition. Double-clicks, notification replays, and simultaneous UI responses cannot create multiple permissions.
Deadlines and disconnects
The default approval window is 45 seconds from the pre-tool event, bounded by the host callback deadline. The proposed outer hook timeout is 75 seconds; exact versions and behavior must be verified on real hosts.
Disconnecting the bridge, ending the session, expiring the invocation, or changing its fingerprint invalidates the request. A late approval cannot release a later retry. Expired UI must show No longer pending and disable live approval controls.
Notifications are entry points
A native notification offers Review and, where supported, Block. Review opens the focused detail panel. Critical denials offer details rather than a quick in-flight allow. Notification text must omit full commands, credentials, source, and private repository names.
Focus mode or denied permissions can prevent delivery. The menu bar and approvals queue remain mandatory; the service must resolve the deadline even if the user never sees a notification or the UI exits.
Try the sample state machine
The current app supports a synthetic review with a 45-second deadline, terminal-response rejection, and a native panel. This local sample is useful for the interaction and foundation tests.
Authenticated service mutations, durable transitions, bridge disconnect handling, and real-host waiting calls remain MVP2.1–MVP2.4 acceptance work. Read the preview guide to try the sample safely.