Clio Coder
All experimental

Advanced, opt-in, new in 0.6.0

Safety4 min read

Keep named files with the models you chose

Declare which paths and tool results may reach which model targets, approve the policy, and see a request to any other destination refused.

Written for
v0.6.0
Works in
Terminal
Basis
Documented workflow
On this pageBefore you start Declare a source and where it may go Review and approve What happens in a session

Some files should reach only a model you chose. An information-flow rule names a source, such as everything under secrets/, and the destinations its content may go to. Once a session has read that source, Clio Coder refuses to send the conversation anywhere else, in every permission mode.

Before you start

  • A project where specific paths or tool results must stay with specific models.
  • A configured target for each allowed model, usually a local or institutional one.
  • A restart after you approve the policy.

Declare a source and where it may go

This policy keeps anything read under secrets/ on one local model target:

.clio-coder/safety.yaml

version: 1
informationFlow:
  targets:
    local:
      runtime: llamacpp
      endpoint: http://127.0.0.1:8080/v1
  recipients:
    private-models: ["target:local"]
  sources:
    - id: secrets-local
      paths: [secrets/]
      recipients: ["group:private-models"]

A target is pinned by runtime and endpoint, so pointing the same name at another URL does not keep the approval. A source can also be a tool or an MCP server, and recipients: [] means the content may go nowhere.

Review and approve

  1. Show what would be approved

    Shell

    clio-coder config trust safety

    This prints the policy files, their digest, and the exact approval command. It changes nothing.

  2. Approve those exact bytes

    Shell

    clio-coder config trust safety --hash <reviewed-sha256>

    Approval belongs to this workspace and this content. Restart Clio Coder to load it.

An edit you have not approved can only restrict more: a new, unapproved rule labels content and allows no destination.

What happens in a session

Reading secrets/notes.txt labels the session with secrets-local. Requests to the pinned local target continue. Switch to a cloud model and the next request is refused before it is sent, with the rule, the source, and the allowed destinations named.

The label follows the session through summaries, compaction, resume, branches, and worker results. Changing the model, the policy, or the permission mode does not clear it. To work without it, start a new session.

Workers and other agents

Native workers check each model request. Coding agents that make their own model calls, such as Claude Code or Codex, are refused at launch when any rule does not allow their target, and ACP agents and pane peers are refused.

Boundaries

  • Labels apply to the whole session, not to individual passages.
  • Shell commands are observed conservatively and incompletely. A read hidden in a script, a variable, or a cd is not reliably seen.
  • A rule controls where content may go. Whether a file may be read at all is still decided by permissions.

By The Clio team · Clio Coder

Continue with the documentation