Guide

Run AI coding agents unattended with guardrails

Reviewed

Use a separate branch or worktree and commit your starting point. Give the agent one bounded task and remove production credentials.

Before leaving your desk

Use a separate branch or worktree and commit your starting point. Give the agent one bounded task and remove production credentials. Check scripts before allowing them, restrict network and filesystem access, and keep deployments and deletion behind explicit approval. Try one harmless approval and one timeout before leaving. A pending decision can stop the task overnight; that is preferable to silently approving it.

Where Saeta fits

Coming soon. Saeta is in development. The phone app launches on Android first, with iOS soon after. Join the waitlist and we'll email you when early access opens.

Saeta watches the agent configurations it installs and warns you if they change unexpectedly. It keeps its local connection and token readable only by your user account. If nobody answers a request in time, it is denied by default, not approved. That makes accidents much less likely to slip through. It does not make a determined attack impossible.

The activity log shows what each agent asked, what you answered and which rule matched. It stays on your computer.

Check the result

Review the diff, run the relevant checks and read the activity log before merging. An approval inbox does not verify that the resulting code is correct. For MCP connections, the model can skip asking; use operating-system isolation when enforcement matters.

Security tools that overclaim put people at risk. If you need to contain an agent you don't trust, run it in a container or a virtual machine that can't reach anything you can't afford to lose.

Sources

Be first to know when Saeta ships.

We'll only email you about the Saeta launch. Unsubscribe anytime. Privacy notice