← Golden Thread Security

Choose a level, approve with your fingerprint, switch on exactly what you want

Golden Thread's security is three layers you control: a level that decides what Claude may run without asking, your fingerprint on the actions that matter, and every protection as its own switch. Everything below comes from gt's own settings registry.

1 · Security level

How much may Claude do without asking?

Type/gt:gt-settings lockdown <level>
Or just saySet my security level to trust local. Switch me to paranoid.

gt writes only its own allow rules into Claude Code's settings, backs the file up first and logs every change. The levels cut prompts; they are not a wall around your computer. Open any level.

strictClaude asks before it runs anything; nothing is allowed ahead of time.
Who it is for
Anyone new to AI assistants, or working with data they cannot afford to expose.
Runs without asking
Only what Claude Code already allows on its own: reading files and answering.
Still asks
Every shell command, every file edit and every network request.
Example
Claude wants to run the tests: it asks you each time.
Trade-off
The most control and the most prompts; a long task stops often for a yes.
/gt:gt-settings lockdown strict
trust localClaude may look around, run your tests and save work in git; it asks for anything outside the project. recommended
Who it is for
Most people: you want Claude to get on with ordinary project work, but not to use the network or other machines unasked.
Runs without asking
List and read files, look at git history, run the project's tests, edit files inside the project folder, and save work with git add and git commit.
Still asks
Anything that uses the network or another computer, sends code anywhere (git push), installs software, deletes files, or edits outside the project.
Example
Claude wants to run the tests: it just runs them. Claude wants to push to GitHub: it asks you.
Trade-off
Far fewer prompts than strict, in exchange for trusting Claude inside the project folder; a mistaken edit there is possible (git history lets you undo it).
/gt:gt-settings lockdown trust-local
trust networkAs trust local, plus the network: other machines, pushing code, downloads and installs.
Who it is for
Developers and administrators who work across servers, want fewer interruptions, and trust the project and the sites involved.
Runs without asking
Everything in trust local, plus ssh and file copies to other machines, git push, pull and fetch, downloads with curl, installing packages, and fetching web pages.
Still asks
Any other shell command, and edits outside the project.
Example
Claude wants to push your branch: it just does. Claude wants to delete a folder: it asks you.
Trade-off
Convenient for real work, but code and data can now leave this machine, and an installed package runs with your permissions, without a prompt.
/gt:gt-settings lockdown trust-network
insecureClaude may run any command and edit any file without asking.
Who it is for
Throwaway machines, test VMs and containers where nothing of value can be damaged.
Runs without asking
Any shell command, any file edit, and web searches.
Still asks
Almost nothing; sending, merging or deleting through LOTR (gt's gateway to GitHub, Jira and Microsoft 365) still asks for your consent.
Example
Claude wants to delete a folder: it just does.
Trade-off
No prompts and no safety net: one wrong command can delete or send anything you can.
/gt:gt-settings lockdown insecure
paranoidStrict, plus locks on gt's own installed code so nothing can change it behind your back.
Who it is for
People whose machine or work makes tampering a real worry: shared computers, sensitive clients, regulated work.
Runs without asking
The same as strict: only what Claude Code already allows on its own.
Still asks
Everything strict asks, and a change to gt's own code or its protection needs you in person (gt unlock, or a typed confirmation at a terminal).
Example
Something tries to edit one of gt's own program files: it is refused, and the attempt is logged.
Trade-off
The most protection and the most friction: updating gt or turning a protection off needs you there. Turning it on needs gt unlock set up first, unless you accept the weaker typed confirmation (paranoid.require_unlock off).
/gt:gt-settings lockdown paranoid

Not sure? Choose trust-local. It removes the prompts for looking at things and running tests, which people click through without reading, and keeps every prompt that matters: the network, installs, deletes and pushes.

2 · Your fingerprint

Sensitive actions wait for you

Typegt_unlock.py enroll touchid
Or just sayHelp me set up gt unlock with Touch ID. Turn on gt unlock.

Set it up in three commands

Enrol your fingerprint (or Windows Hello on Windows, or an authenticator app with enroll totp).gt_unlock.py enroll touchid
Turn gt unlock on. From now on the sensitive actions wait for you.gt_unlock.py policy enable
Check where you stand; it names the next step if there is one.gt_unlock.py status

Add push_fingerprint for a fingerprint before every push from the repos you name, and commit_fingerprint to have every commit signed by a key in your Mac's Secure Enclave. Both are in the switches below.

3 · Every switch

Build your own setup

Type/gt:gt-settings <name> <value>
Or just sayTurn on sandbox mode. Require my fingerprint before every push.

What "follow" means: a Paranoid part or a single-use permit set to follow does whatever its parent switch says. Every Paranoid part follows paranoid, and every permit follows paranoid.action_tokens, which follows paranoid. Set a part to on or off only to override its parent.

The level is a starting point, not a package. Change any switch below and the panel writes the commands for your custom setup. Each is one command, any time; with gt unlock on, loosening one needs you present.

Presence: you approve, in person

unlock

gt unlock: agents need your presence (TOTP + Touch ID / Windows Hello) for LOTR, secrets, publishing and gt's guards.

default off · options: off | on
push_fingerprint

A fingerprint (gt unlock step-up) before every git push from the repos in push_fingerprint_repos.

default off · options: off | on
push_fingerprint_seal_token

With push_fingerprint on, also seal the GitHub push token behind gt:publish (the lock).

default off · options: off | on
commit_fingerprint

A fingerprint on every commit: a Secure Enclave key signs it (gt_sign.py), in the repos in push_fingerprint_repos.

default off · options: off | on
accept_review

How an accept of a #conflict version is reviewed: only the presence dialog, or the whole change shown first and bound to its hash.

default dialog · options: dialog | full

Fences: what Claude's tools can reach

sandbox_mode

gt sandbox mode: fence Claude's shell and file tools off the vault and gt's state; reach the vault through gt's MCP and write queue.

default off · options: off | on
sandbox_vault_reads

Under sandbox mode, whether Claude's shell and file tools may also READ the vault.

default deny · options: deny | allow
protected_paths

Prompt before Write/Edit to core-rules, global-memory, local packs, gt hooks or settings.json; refuse overwriting a Source.

default ask · options: off | ask
symlink_writes_outside_vault

Whether a vault tool may append through a link that points OUTSIDE the vault.

default refuse · options: refuse | allow

Commit and push gates

test_gate

Refuse a `git commit` of code whose tests have not been seen to pass.

default auto · options: off | warn | auto | block
commit_checks

Refuse a `git commit` whose staged content no passing gt_check.py run covers.

default off · options: off | on
foreign_checkout_guard

Deny git commit/push inside a checkout you declared as another machine's.

default on · options: off | on

Paranoid: locks on gt's own code

paranoid

Lock gt's installed code so it cannot be changed behind your back.

default off · options: off | on
paranoid.os_lock

Paranoid part: OS lock on installed gt files.

default off · options: off | on | follow
paranoid.code_write_gate

Paranoid part: presence check before the code is unlocked.

default off · options: off | on | follow
paranoid.bash_guard

Paranoid part: guard for shell commands that write to that code.

default off · options: off | on | follow
paranoid.signed_manifest

Paranoid part: signed list of the code, checked before each hook runs.

default off · options: off | on | follow
paranoid.plugin_dirs

Paranoid part: plugin cache and marketplace under protected paths.

default off · options: off | on | follow
paranoid.require_unlock

Paranoid part: refuse to turn paranoid on until unlock is set up.

default off · options: off | on | follow

Single-use permits: one action, one target, minutes to live

paranoid.action_tokens

Single-use action tokens: the master for every action below.

default off · options: off | on | follow
paranoid.action_tokens.disk_read

Single-use token for disk_read: one disk_read of one file.

default off · options: off | on | follow
paranoid.action_tokens.disk_list

Single-use token for disk_list: one disk_list of one folder.

default off · options: off | on | follow
paranoid.action_tokens.net_fetch

Single-use token for net_fetch: one net_fetch of one URL.

default off · options: off | on | follow
paranoid.action_tokens.disk_write

Single-use token for disk_write: one disk_write of exact content to one path.

default off · options: off | on | follow
paranoid.action_tokens.lotr_read

Single-use token for lotr_read: one LOTR call_read (connection + op + args).

default off · options: off | on | follow
paranoid.action_tokens.lotr_write

Single-use token for lotr_write: one LOTR call_write.

default off · options: off | on | follow
paranoid.action_tokens.lotr_consent

Single-use token for lotr_consent: one LOTR call_consent (consent is still asked as well).

default off · options: off | on | follow
paranoid.action_tokens.vault_read

Single-use token for vault_read: one gt-vault vault_read, vault_search or vault_list.

default off · options: off | on | follow
paranoid.action_tokens.vault_write

Single-use token for vault_write: one queued vault write or batch, or one vault operation tool call.

default off · options: off | on | follow
paranoid.action_tokens.secrets_unseal

Single-use token for secrets_unseal: one secret unseal through gt unlock.

default off · options: off | on | follow
paranoid.action_tokens.git_push

Single-use token for git_push: one git push (repo + refs).

default off · options: off | on | follow
paranoid.action_tokens.git_commit

Single-use token for git_commit: one git commit (repo + tree hash).

default off · options: off | on | follow
paranoid.action_tokens.publish

Single-use token for publish: one release publish step.

default off · options: off | on | follow
paranoid.action_tokens.grant_add

Single-use token for grant_add: creating one timed grant.

default off · options: off | on | follow
paranoid.action_tokens.plan_bound

Single-use token for plan_bound: one confirmation that mints an approved plan's tokens up front.

default off · options: off | on | follow

File and web brokers

io_tools

Offer the I/O brokers' tools (disk_read / disk_list / net_fetch) in the gt-vault MCP server, whatever vault_mcp says (0.21.0; on by default).

default on · options: on | off
io_write_presence

Every disk_write needs a fresh confirmation (or a live timed grant for that repo); this cannot be switched off (0.21.0, item #20 stage 3).

default on · options: on
io_write_ci

Whether disk_write may write CI workflow files (.github/workflows and the like); only you can lift it (0.21.0, item #20 stage 3).

default never · options: never | allow
io_read_allow

Folders the disk-read broker (disk_read / disk_list) opens without a prompt, beside the vault and every project's source.md repo (0.21.0).

default empty · options: a list you choose
io_fetch_allow

Domains the network-fetch broker (net_fetch) opens without a prompt (subdomains included); also where the owner lists localhost or a private address on purpose (0.21.0).

default empty · options: a list you choose
io_read_max_bytes

The most one disk_read call returns (default 1048576 = 1 MB); a bigger file is paged with next_offset (0.21.0).

default 1048576 · options: a list you choose
io_fetch_max_bytes

The most one net_fetch call returns (default 1048576 = 1 MB); the rest is dropped and the result says truncated (0.21.0).

default 1048576 · options: a list you choose
io_write_max_bytes

The most one disk_write call writes (default 1048576 = 1 MB) (0.21.0).

default 1048576 · options: a list you choose

Installed code and the gateway

component_updates

What to do when INSTALLED hooks/scripts differ from what is checked in.

default report · options: off | report | confirm | auto
addon_fixes

What happens to the fixes a checker proposes: ignored, listed for you, or applied.

default propose · options: off | propose | apply
agent_split

LOTR agents: separate reader and writer agents (split), or one read/write agent per task (combined).

default split · options: split | combined