Can you tell at a glance what a role is allowed to do?
The main change in these releases is clearer FinchStory Loop permissions: whether a role can write files, reach outside the workspace, or run commands without approval is now much easier to understand. A few everyday controls were cleaned up at the same time.
Yes. Loop now has Full, Workspace, and Read-only permission levels with the active restrictions shown in role properties. Failures enter Retry correctly, while account shortcuts, composer controls, and cursor feedback are more stable.
Permission levels map directly to real capabilities
Full can read and write across workspaces. Workspace mode can read more broadly but limits writes to the workspace and temporary directories. Read-only blocks writes, requires command approval, and disables network access.
You can see the restrictions without digging through settings
Role properties show the active sandbox and approval policy. If Loop fails, it now enters a clear failed state with Retry available.
A few everyday controls are steadier too
Each OpenAI account gets a top-up entry, composer buttons keep fixed dimensions even with very large text, and cursor feedback returns to standard system pointer / not-allowed behavior.