The three levels
By default ChEddi works on the records in your draft workspace. Changes there are invisible to visitors until you publish them, see Draft or live. Independently of that, every tool call is classified into one of three levels, and the level decides whether you are asked first.
| Level | What happens |
|---|---|
| Read-only | Runs straight away, without asking. Searching, reading, listing |
| Write | Is shown to you and needs a click on “Execute” |
| Hard to reverse | Needs a second, confirming click. The button first says “Execute permanently” and then asks “Really execute permanently?” |
With “Decline” you discard a single call, with “Decline all” the whole group. Your decisions stay visible in the conversation and are therefore traceable.
Where the classification comes from
The classification comes exclusively from what the tool itself declares, from the same hints every external MCP client sees. There is no guessing by name and no heuristic.
The key point: a tool that declares nothing counts as a write and asks. An unannotated tool can therefore never change records silently.
There is one exception: if a generation, translation or image tool is called without a model, it is only listing which models it could use. That counts as read-only and costs no credits.
What you see before confirming
Before confirming you see what the call would do, including a preview of the old and the new value. If a call costs credits, that is shown as a badge. Hard-to-reverse calls additionally carry the marker “hard to reverse”. Through “Technical details” you can inspect the full call.
If a call contains invalid records, it is blocked and cannot be confirmed.
Cap on tool calls
So that ChEddi does not get lost in a loop, the number of tool calls per request is capped. From 20 calls you get a warning, at 40 the turn is aborted. The counter starts over with every new message from you.
If that happens, the task is usually too large or phrased too vaguely. Break it into smaller steps.