AI Safety · Part 4 of 7

Actions: the human stays in the loop

Watch: thinking is cheap, doing is not · 60 seconds · animated, sound on

Thinking and doing are different risk classes

You can re-ask a bad answer. You cannot un-send an email or un-delete a file. So Cronus separates the two and puts a human gate in front of the second one.

The leash length is yours to set

The Safety page sets an approval mode for each agent, separately:

These are not cosmetic toggles. Under the hood, each mode drives that agent's own real permission system, so the limit holds everywhere the agent runs, not just inside Cronus windows.

Spend caps

Give any agent an optional dollar cap. When it hits the cap, Cronus pauses that agent's next action and asks you to raise the limit before it continues. AI spend stays loud, never silent.

The approvals inbox

Risky actions land in an inbox and wait. You see exactly what an agent wants to do before it does it, and you decide. A wrong action that never ran costs nothing.

No self-updates, ever

Cronus never changes itself behind your back. It does not auto-update, does not check for updates on its own, and does not phone home. New versions are installers you choose to run, or not. Boring, predictable software you can trust with real work.

← Part 3: Grounding Part 5: Watching →