Remote Operation Safety Policy
Effective date: July 21, 2026
Cheers can connect to an external AI agent running on a computer or service chosen by a workspace owner. Cheers is a coordination and approval interface; it does not make an external agent safe, nor does it replace the agent provider’s terms or security controls.
What an agent may do
Depending on the agent, its local configuration, and permissions granted by the host operator, an agent may read or modify files in approved workspace roots, run commands, access network services, create commits or other external changes, and send output back to a channel. A request may have effects that are irreversible, expensive, or visible to third parties.
Required safeguards
- Connect only agents and hosts you control or trust.
- Use a dedicated, least-privilege operating-system account, restricted workspace roots, and a minimal environment-variable allowlist.
- Keep credentials, private keys, production data, regulated data, and secrets out of prompts, attachments, and accessible directories unless an approved workflow specifically requires them.
- Keep approval enabled for write, command, network, credential, and destructive operations. The iOS notification offers direct Approve / Deny for urgent requests only and requires device authentication; because the alert does not show the full command or diff, use Approve only for a request you independently recognize. Otherwise open the request and review the exact command, paths, and diff first.
- Use a test environment for production-like tasks, review audit history, and revoke the bot token or disconnect the connector if behavior is unexpected.
Actions that must not be approved casually
Do not approve commands that delete or overwrite broad paths, change access controls, install unknown software, expose ports, export data, alter cloud resources, publish or deploy code, spend money, or transmit secrets unless you independently verify the full effect and have authority to do so.
Data and participant notice
Before adding an external AI agent to a channel, the workspace owner must tell participants the agent/provider identity, the intended scope, whether it can access files or execute commands, and the provider’s data terms. Do not add a third-party AI agent to a channel containing personal, confidential, or regulated information without the required notice and consent.
Approval and accountability
Only the bot owner or a designated approver may resolve a request. On iOS, Approve / Deny actions require device authentication and the server verifies the approver and pending request before relaying a decision. The notification warns that it is a remote action, but it is intentionally content-minimized; open the app to review details when uncertain. Approval records are retained for audit. You remain responsible for the actions you authorize and for compliance with your organization’s policies and applicable law.
Emergency response
If you suspect misuse, immediately disconnect the connector, rotate the bot token and affected credentials, revoke access, preserve audit records, and contact tocheers@icloud.com. Report product vulnerabilities privately through the security advisory channel.