# What Tade will not do, and why not

> Ten refusals that are the design rather than a backlog, including the three that will cost somebody something and the one that is only true if they choose tmux.

Published 2026-09-28 · by The Tade project · tagged design, safety, refusals.
Published at https://tade.sh/blog/what-tade-will-not-do-and-why-not/ — part of https://tade.sh/blog/.

---

Every tool in this category publishes what it does. The list nobody publishes
is the other one, and it is the list that decides whether the thing is usable
on work that matters.

So here it is, with the reasoning, and with the parts that cost something said
plainly rather than dressed up as a principle.

## It does not contain your agents

This is the first thing to know and the one most likely to matter.

**Agents run as you.** Nothing in Tade contains them, nothing asks before a
command unless approvals are turned on, and an agent can read and change
whatever you can. That includes `~/.tade/config.yaml`, where every key pasted
into Tade is kept — so **any agent you run can read every key you have given
it**.

Containing an agent is its harness's business, not Tade's. What Tade does about
it is three things and no more: approvals exist and are yours to turn on; every
command an agent runs is written down either way; and a key you would rather
Tade never wrote down can stay in an environment variable, which always wins
over the file.

> **A screen from Tade — `watching-an-agent`.** The Tade window: agents down the left with what each has cost, the changes, the files, an agent at work in the middle asking to run a command, and the orchestrator below.
>
> Approvals: every command the agent is about to run, and the two ways to answer.
> Off by default, and each command is written down whichever way it goes.

That default is a real decision with a real cost. Approvals on every command
makes a team of agents unusable; approvals off makes an agent able to do
anything you can. Tade picks the second, and the README's first section is
about it — above the window it is selling, under the heading *Agents run as
you*.

## It does not merge anything

`extensions.review.merge` is `never` by default. The tool that could merge
refuses outright while it is:

```console
Tade does not merge: `extensions.review.merge` is `never`. Change it in
Settings if that is what you want, or merge it yourself.
```

Set to `when green and approved` it still only ever merges when somebody asked
for exactly that. No watch, no schedule and no judge can reach it.

## It does not delete anything of yours

There is no tool that removes a worktree, deletes a branch or deletes a folder,
and asking explicitly does not produce one. Closing a project leaves the
folder, the branches and the journal exactly where they are.

That is a person with git in a terminal, and it is meant to be. The cost is
that a machine which has run forty agents accumulates forty task folders — and
forty branches too, where the project gives each agent a worktree — and nothing
in Tade tidies any of it.

## A judge answers; it never decides

Jev may only ever **add caution**. It never approves, never merges, never
closes, never unholds and never shortens anything. A finding reaches the agent
that wrote the change as *material to judge*, never as instruction — and the
same is true of a review comment, because text a model wrote about somebody's
code carries no permission with it.

A finding is closed by a verdict, and a verdict is the orchestrator's or a
person's — never the writing agent's about its own change. Nothing ages a
finding into an outcome either way.

## There is no daemon, and nothing hot-reloads

Schedules and watches run only while a window is open. What came due while it
was closed is caught up once when it opens, or skipped, as the schedule says.

An extension turned on loads the **next time Tade starts**, never as a hot
reload, because importing one runs it.

Both of those have a consequence worth stating outright, because this site's
own journal shows it. The window running Tade's watches has been open since
07:20 on 26 September. A fix that landed at 11:05 that morning is not in it,
and the old code has been making the same pointless request to GitHub every ten
minutes ever since — 185 of them. The window is the program, and `git pull` is
the upgrade. Nothing changes under you, including the things you would like to.

## It remembers nothing, which cuts both ways

What an agent *is* — working, idle, waiting on you, failed, finished — is read
back from git and the processes every time anybody looks. Tade owns no state of
its own, which is why closing it is harmless and why nothing drifts.

It also means Tade cannot tell you anything about a repository it cannot
currently read, cannot answer about a machine that is off, and cannot show you
what an agent was doing last Tuesday beyond what the journal happens to hold.

The single exception is notes: the one thing Tade is told rather than derives,
kept word for word in a file you own, and never summarised into something
shorter.

## Your agents probably do not outlive the window

The refusal people quote is *closing the window and stopping the work are two
different acts*, and it is true — with the tmux driver, whose whole reason for
existing is that lanes outlive Tade: close it, open it again, and the agents
are still running.

The default driver is `pty`, and under it they do not. Asking for tmux on a
machine without tmux falls back and **says so loudly**, in the config's own
words, *because agents that quietly stop outliving the window is exactly the
kind of thing you find out about at the worst moment*.

## It does not send your work anywhere

Tade reports its own trouble and never your work. What you said, what an agent
wrote, task titles, prompts and notes are never in its telemetry. Paths are
scrubbed to `~` and anything shaped like a secret is replaced before anything
leaves — by shape rather than by a list of issuers somebody thought of, since
Tade now holds keys for anything that asks.

Speech stays on this machine by default, and there is no account, no server and
no cloud component.

What that sentence does **not** cover is an extension somebody turned on. Jev
is sent the diffs and logs it is pointed at; that is the whole of what it does,
and with no key it is never turned on and nothing is read. The search box has
one optional ask of its own, and it is a switch at the door — off, a choice
carries its name and where it is and nothing else — because a rule living in the
code that reads the text bounds one reader while a rule at the door bounds every
reader. Tade's own telemetry is the thing that never carries your work. An
extension you turned on is a decision you made, and the page where you make it
says what leaves.

## It will not make a check look green

`unknown` is first-class. A check nobody ran is not a check that passed, and
absent is not fine.

What a project checks is read out of what the project already says — its commit
hook and its workflows — and **reading may only ever narrow what Tade claims**.
A step it cannot place is *named* rather than run, so the failure mode is
"Tade checked less than CI does, and said so". Where a project says nothing at
all, Tade invents no gate: `unknown` stands, and the agent has to work out what
checking means, run it, and say what it ran.

> **A screen from Tade — `what-an-agent-has-done`.** The ACTIONS tab: the commits this agent made, what is not committed, the review it is out for, and each of the project’s own checks with what it ran, how long it took and what it counted — with the tests red.
>
> What an agent did: its own commits, what is not committed, the review it is out
> for, and each check with the command it ran and what it counted. Red at the
> commit in hand, and it says which commit.

## And no browser, no server, no build step

One terminal. No web UI to keep in step with it, nothing listening on a port,
and no build to run before the program works.

The cost is obvious: no dashboard to share, nothing to open on a phone, and
every machine running its own copy with its own journal.

## The three honest numbers

A post about refusals should include the ones that bite.

**39 of 130 commits last week read as nobody's** — and not one of them is
missing the trailer. Of the last sixty commits in `tade`, twenty-two read as
unattributed and all twenty-two have `Tade-Task:` in the message. What breaks
them is a blank line before the `Co-Authored-By:` underneath, which puts the
trailer outside the block `git log --format='%(trailers:key=Tade-Task)'` will
parse — and that is how Tade reads it back.

Attribution is a string in a commit message rather than a table Tade keeps, so
it survives a clone and a force-push. It also fails silently when the string is
one blank line out of place. Every commit that carries these eight posts was
rewritten before they were published, for exactly that reason.

**34 of 43 judged findings were false positives.** The judge's loudest question
was right two times in twenty. That is on a page rather than in somebody's
memory, and it is why the question was reworded, but it is a real cost in
somebody's attention this week.

**425 of 1,447 watch looks could not look at all.** 142 because a host was
unreachable, 76 because the judge refused an ask that was too large, 17 because
a look ran over its minute, 5 because the judge itself could not be reached —
and 185 because of the stale window above.

None of those is a roadmap item. They are what the thing is right now, and the
whole argument of this project is that a tool which keeps books you can check
is worth more than one that tells you it is fine.

```sh
npm i -g tade-sh
```

The front page states its own ten in [one screen](/#wont-do), and the
invariants behind all of them are `AGENTS.md` in
[the repository](https://github.com/mujacica/tade).
