What the agent can do
The agent can read your systems and, when you allow it, change them - comment on a ticket, move it to In Review, open a pull request. This page lists what it can reach and what controls a write.
A connector can read and cannot write until you turn Write on for it. Even then, each change made from chat is shown to you before it happens.
The three gates
Every write from chat passes all three.
1. Permission, per connector
Settings → Connections, then the connector. Jira, Confluence and Bitbucket each have two switches:
| Switch | Allows | Default |
|---|---|---|
| Read | Searching and reading that system live, from chat and from an attached MCP client. What you have indexed stays searchable with Read off | On |
| Write | Creating, updating and deleting content there on your behalf | Off |
Turning Write off takes effect immediately. It does not undo changes already made. A connector's tools work only on a license tier that includes that connector.
Subversion has no Write switch because it is read-only. Adding or removing indexed sources has its own permission, separate from any connector's switches.
2. Ask, Auto or Read-only
Beside the model in the chat box, choose how the agent treats a change. It starts at Ask each time you open Proxyma.
| Mode | Effect |
|---|---|
| Ask | Each change stops in the conversation and waits for you. |
| Auto | Changes proceed without asking. Write still has to be on. |
| Read-only | Every change in the chat is refused. Reading works as usual. |
In Ask, a change shows you the tool and its arguments:
| Choice | Effect |
|---|---|
| Allow once | This change proceeds; the next one asks again. |
| Allow for this conversation | Remaining changes in this conversation proceed without asking. |
| Deny | The change does not happen, and the agent carries on. |
If you do not answer within five minutes, the page denies the change for you. If the page is closed, the change is denied after 30 minutes.
An MCP client can run write tools while Write is on, and nobody is asked to approve the change.
3. Your own credentials
Every action runs with the access token you saved in Settings.
- With your token, the agent cannot do anything you could not do yourself. If Jira would refuse you, it refuses the agent.
- An edit is attributed to the token's owner. With your token, a comment the agent writes appears under your name.
Sharing a source lets colleagues search it. They need their own token before the agent will act for them.
What it can reach
Jira, Confluence, Bitbucket and Subversion reads need Read on. The Changes column needs Write on and, in chat in Ask mode, your approval.
Jira
| Reads | Changes |
|---|---|
| Search with JQL, read an issue in full with its comments, list projects, list fix versions, list the fields the server has, list a project's issue types and the fields each one takes | Create an issue; edit summary, description, priority, assignee, labels, fix versions, components, due date and custom fields; move it through a workflow transition; add, edit and delete comments; set time estimates; log work; link and unlink issues; attach a file; create a fix version; delete an issue. Any issue type the project has - Epic, Story, Task, Bug, Sub-task or your own - and a Story can be put under an Epic |
Confluence
| Reads | Changes |
|---|---|
| Search with CQL, read a page, list spaces | Create, update, move and delete a page; add and remove labels; attach a file; add, edit and delete comments |
Bitbucket
| Reads | Changes |
|---|---|
| List branches, tags and commits; read a pull request with its discussion; read the diff of a pull request or a commit; list and read files in a repository without cloning it; download a whole repository at a branch, tag or commit (MCP clients only) | Open a pull request; comment on it, on a file or on one line of its diff, and reply to a comment; approve it or request changes; merge it; create and delete a branch; create a tag |
Merging and approving a pull request cannot be reversed from Proxyma, and an approval counts toward the repository's merge checks under your name. In Ask mode, both ask for your approval first - read the pull request before you grant it. In Auto they do not.
Subversion
Read-only. The agent lists folders and reads files from the server without a checkout. It never commits.
It needs your own SVN username and password saved in Settings. On a VisualSVN server with Windows Authentication the username is domain-qualified; with Subversion Authentication it is the name from the server's user list.
Files, websites and the public web
| Reads | Changes |
|---|---|
| Everything you have indexed, by meaning and by keyword together; a page or file at any URL; a search of the public web, which needs no setup | Add and remove indexed sources - a folder, a website to crawl, a Jira project, a Confluence space, a repository |
The agent never changes the documents you index; it reads them where they lie.
Office files. Ask and the agent creates or edits Word, Excel and PowerPoint files, charts included. On Home Server and Enterprise Server it works on attached files in an isolated container. On Desktop it can also save to your computer, and asks you first each time unless you chose Allow for this conversation or Auto.
Anything else those systems can do
The agent can also call any endpoint of the Jira, Confluence and Bitbucket APIs directly - for example watchers, page restrictions or repository settings.
In chat, a read (GET) needs Read on and runs without asking; any other call needs Write on and, in Ask mode, your approval. From an MCP client, a read needs Read on and a change needs Write on. It cannot reach a system you have not configured, or do anything there that the token it uses could not.
Sub-agents
The agent hands parts of a task to sub-agents: further agents, each with a context of its own. They use the agent's model and limits unless you choose others in Settings → Agents → Sub-agents; a cheaper model there keeps long reading off the agent's price. A sub-agent has the agent's tools and passes the same three gates. In Ask mode its changes wait for your approval, and the prompt names the sub-agent.
Sub-agents run in the background, so you can go on chatting while they work; the agent waits for one only when its next step needs the answer. It tells you what each found when it reports. Each sub-agent has a panel in the thread showing what it is doing, with its own Stop, and the panel folds once the sub-agent ends.
The button beside the model under the message box opens the agents window: every agent in the conversation, finished ones included, and what each has used and cost. Total time there counts the time any agent was working, and clicking a sub-agent shows its steps. While sub-agents work, a robot for each takes the button's place, up to three; click one to go to its panel in the thread. Past three, +N opens the agents window. On Enterprise Server administrators see them.
When the provider's rate limit is reached, which is likely with many sub-agents at once, agents wait and retry for up to 10 minutes. A sub-agent that still cannot continue tells the agent why.
Memory
The agent saves facts it learns and your preferences, and checks them before it searches your sources. Settings → Memory lists everything it has saved: edit an entry, move it between About you and Knowledge, or tick several and delete them. On Enterprise Server each user sees only their own.
How long it keeps working
An iteration is one model call and the tool calls it makes. Settings → Agents → Max agent iterations caps them per answer: 20, 50 (the default), 100 or Unlimited. At the limit the agent stops and asks: Continue gives it as many iterations again, and Stop here has it answer with what it has. Max sub-agent iterations caps each sub-agent: the agent's limit unless you set another, with the same choices. A sub-agent at its limit reports what it has. Sub-agent time limit stops a sub-agent after 5 to 120 minutes (30 by default) and asks it once for what it has found; time spent waiting for your approval is not counted. Settings → Search → Search time limit gives one search of your sources 1 to 15 minutes (5 by default); other tools stop after one minute. On Enterprise Server a Super Admin sets all four.
Press Stop to end a run at any time. More iterations mean more model calls, and more cost.
With an Anthropic provider, or an OpenAI-compatible one with Send cache instructions on (OpenRouter, in front of Claude, Qwen or Gemini models), Settings → Agents → Prompt cache keeps the conversation cached for the next turn. Auto (the default) keeps 5 minutes, and 1 hour while sub-agents work in the background or when you pause longer between turns; 1 hour costs more to write. Sub-agent prompt cache follows it unless you choose another.
What it will not do
- Write anything while Write is off. The tools refuse.
- Act without asking in chat, unless you chose Auto, or Allow for this conversation earlier in that same conversation. MCP clients are not asked.
- Use anybody else's credentials.
- Let a sub-agent skip the gates. A sub-agent's changes take the same permission, mode and approval as the agent's own.
- Send your documents anywhere you did not configure. Its web searches still go to DuckDuckGo, or to Google if you add a Google search key in Settings → Search → Web search, even with a local model - see the questions and answers.
If something goes wrong
A refused action reports the reason given by the system - for example a missing Jira permission, an invalid transition, or a merge blocked by a check. The agent is instructed to relay it rather than work around it.
Every change appears under the token owner's name in Jira's history, Confluence's page versions and Bitbucket's activity.
Checking that everything works
- In Chat, ask: Run a self test.
- Choose Reads only, or Reads and writes and name a test Jira project, Confluence space or Bitbucket repository. Nothing is written anywhere else, and what the test creates is deleted at the end.
- Attach a PDF or Word file when asked.
- Read the report: each check is PASS, FAIL, SKIPPED (not in your edition or license, or not set up) or NEEDS YOU, with the fix for each failure.
- Go through the short list of checks it gives you at the end - the ones only a person can do in the app.
To report a problem, ask it to save the report, then attach the file to Send feedback.