Skip to main content
Choose how much native access an attended Session may request, then cap attended and autonomous work for each Machine. Cogno applies the more restrictive setting whenever a Session choice and a Machine maximum differ.

Choose access for attended Sessions

Use the shield menu beside the composer to choose the Session access level. On first use, a Session starts with Auto in workspace unless the Machine maximum is lower. After you choose another level, Cogno remembers that choice for the same Machine in this browser. If the Machine maximum is lower the next time you open a Session, Cogno starts at the maximum instead of restoring a higher choice.
A Machine maximum is a ceiling, not a default. Raising the maximum to Full access does not automatically raise a new Session from Auto in workspace.

Set access limits for a Machine

1

Open the Machine settings

Open Settings → Machines. Find the Machine whose limits you want to change.
2

Set the attended maximum

Under User-initiated maximum, choose the highest level a person may select for Sessions started or continued on that Machine.
3

Set autonomous access

Under Cogno autonomous access, choose the level for unattended queue turns on that Machine.
If Cogno cannot save a setting, the page keeps the error visible and offers Try again.

Confirm Full access once per Machine

The first time you choose Full access for a Machine in this browser, review and accept the warning. Cogno remembers the confirmation for that Machine, so changing a Session or Machine setting to Full access later does not open the same dialog again. Clearing browser storage or enrolling the computer as a new Machine removes the remembered confirmation. Cogno then asks again the next time you choose Full access.
Full access removes native approval safeguards. An agent may run commands, change files outside the workspace, and reach credentials available to the operating-system account.
Full access requires Engine protocol 3 or later. On an older Engine, the option is disabled and the Machine settings explain that Engine must be updated.

Understand what can stop tool access

Cogno checks tool access against the current Workspace, Project, Machine, and run. A token issued earlier does not preserve access after those relationships change. Tool access also depends on the member’s current permission for the requested operation. A tool’s presence in the catalog is not permission to execute it. External integrations still require their own connection and provider permission checks.

Discover available Project sources

Source discovery separates connections even when they contain the same resource ID. It returns only selected targets still present in that connection’s current catalog. Personal connections are visible only to the trusted actor who owns them; without an actor, discovery returns shared connections only. Discovery does not replace the permission check performed when a tool reads the source.

Keep the execution components updated

Queue claims and attended-run token requests require an explicit execution-policy acknowledgement. A Machine running an older Engine receives execution_policy_upgrade_required before a new queue run is claimed or a token is issued. Update the execution components together with the web and desktop application; do not disable the access checks to restore compatibility.
Cloud refusal does not stop a coding-agent process already running on your computer. Older desktop and Engine combinations can also continue local attended execution after a token request fails. A cloud-only update does not guarantee that those older local processes have stopped or enforce the saved policy.

Retry within the correct run

Attended writes require an execution-turn identity supplied by Engine. Read-only access can precede Session registration, but the absence of that turn identity does not authorize a write. A later explicit turn has a different identity even if the transport restarts its request numbering. Queue retries retain the same logical work identity. A new request identifier is not a new permission and does not make a previously uncertain external result safe to resend.