Docs · 5 min read

An AI on your server, safely: change windows, modes, approvals and a lock on the server

What your AI may do on its own, what needs you, how long access lasts, and how to stop everything.

Nothing changes until you open a window

Every server has a change window, closed by default. While it is closed your AI can read logs, run reports and plan, and anything that would change the server is refused with a link for you. Open changes on the Servers page, the dashboard or from that link, for 1, 2, 4 or 8 hours: there is no way to leave them open for good. A countdown shows where you are and you can close them early. Think of it as sudo: the right to change a server is granted for a while, not left on. An approval you press still runs once while changes are closed, because you pressed it, and AskYourStack's own daily and site checks never need the window.

Every action has a risk level

Reading (logs, files, status) runs at once. Changes (installing packages, editing config) run after /etc is saved. Destructive actions (deleting folders, dropping databases, changing SSH or the firewall, removing packages, deleting users or plugins) wait for your approval. A few things are never allowed, such as reading the agent's own key.

Approving

  1. Your AI gives you a link, and you get an email.
  2. Open it signed in to askyourstack.com and read exactly what will run.
  3. Approve and run once, or Deny. Tell your AI it is approved; it repeats the call with the approval id.
  4. An approval runs once, only with exactly the arguments you saw, within 30 minutes.

Approving needs you signed in, which your AI never is. Text planted in a log file or web page cannot approve anything.

The page says in plain words what the action does, what could go wrong and how to undo it. Before an approved statement that deletes database tables, or an approved removal of whole folders, AskYourStack saves a copy first when the command names them plainly, and says where it is.

For a job with several risky steps your AI asks once, with a plan: you see every risky step and approve them together; each still runs once, exactly as shown, when your AI reaches it. And while you are watching a big job, an approval page lets you stop the questions on that server for 30 or 60 minutes; they come back by themselves.

Modes per server

Read-only: your AI can only look. Normal: the default described above. Full trust: nothing asks, everything is still logged; use it when you are watching a big job. Change modes on the Servers page.

Stop

Pause one server or everything on the Servers page. Disconnect stops the agent for good. On the server itself: systemctl disable --now askyourstack-agent.

The lock, and what runs on your server

On the server, askyourstack-agent lock makes the agent answer only its own read operations (files, logs, reports, read-only database queries) and refuse everything else, whatever your AI asks and whatever the dashboard says, until someone with a shell on it runs askyourstack-agent unlock. It is the one check that does not depend on us. The agent itself is open source (github.com/shopwhizzy/askyourstack-agent): every release names the commit it was built from, and verify.sh in the repository rebuilds it and compares the hash with the binary on your server. By default the agent runs as an ordinary Linux user and manages only that user's sites and files, a boundary Linux itself enforces; run the install line as root only when you want it to run the whole server. The security page lists each claim with the address that checks it.

Try it on your own server

Free connects one server in read-only mode: your AI can look, read logs and explain what is wrong.

Connect your server
Next guide
Undo what your AI changed: snapshots, rollback and backups