Can you tell at a glance what a role is allowed to do?

The main change in these releases is clearer FinchStory Loop permissions: whether a role can write files, reach outside the workspace, or run commands without approval is now much easier to understand. A few everyday controls were cleaned up at the same time.

The short answer

Yes. Loop now has Full, Workspace, and Read-only permission levels with the active restrictions shown in role properties. Failures enter Retry correctly, while account shortcuts, composer controls, and cursor feedback are more stable.

Permission levels map directly to real capabilities

Full can read and write across workspaces. Workspace mode can read more broadly but limits writes to the workspace and temporary directories. Read-only blocks writes, requires command approval, and disables network access.

You can see the restrictions without digging through settings

Role properties show the active sandbox and approval policy. If Loop fails, it now enters a clear failed state with Retry available.

A few everyday controls are steadier too

Each OpenAI account gets a top-up entry, composer buttons keep fixed dimensions even with very large text, and cursor feedback returns to standard system pointer / not-allowed behavior.

What's new

Added Full / Workspace / Read-only permission levels to Loop.
Shows sandbox and approval policy in role properties.
Corrected the real read/write boundaries of each permission level.
Loop failures now enter Retry correctly.
Added a top-up entry for OpenAI accounts.
Composer buttons remain stable with very large text.
Restored standard system cursor feedback.
FinchStory 1.0.71–1.0.77 · September 19, 2026