Safety & review
A room is instructions your Dot follows using your accounts, so rooms get checked twice. Automatic checks run before a room can be published. Then the front desk, the people who review rooms, checks it while it's live.
A room's journey
Front desk
Automatic checks
These run when an author clicks Publish. If any fails, the room stays a draft until it's fixed.
| Check | Why |
|---|---|
| Every required field is filled in and within its length limit | Rooms stay complete and readable |
| No invisible, direction-changing or control characters | These are a classic way to hide instructions from the person reading them |
| Titles, summaries, rules and access items fit on one line | A line break could fake an extra rule or section in an exported file |
| At least one Block rule | Guests always know what the room will never do |
| Master key rooms have at least one Require approval rule | Real actions always keep a person in the loop |
| Lobby pass rooms don't draft anything | The key card has to match the access list |
Review flags
The front desk also sees automatic flags on each room. They point out things worth a closer look:
- phrases that look like prompt injection ("ignore previous instructions")
- long encoded strings and links in the instructions
- mentions of passwords, keys or card details
- copying or sending data in bulk
- spending money, deleting things or messaging other people without a matching approval or block rule
- a key card that looks too low for what the room does
What reviewers check
For every live version they review, the front desk confirms:
| Checklist id | The reviewer confirms |
|---|---|
access_matches | Access list matches what the instructions actually do |
no_hidden_actions | No hidden or undisclosed actions |
no_injection | No prompt tricks, encoded text or suspicious links |
approval_for_risky | Money, external messages and record changes are behind approval |
keycard_right | Key card level is right |
Then they decide:
| Decision | What happens |
|---|---|
| Approve | The version gets the Reviewed stamp |
| Request changes | The author gets a note. The room stays live |
| Reject | The room is taken down. The author can fix it and publish again |
Reviewers can't review their own rooms. When a room gets a new version, the stamp resets until the new version is reviewed.
Reporting a room
Spot something wrong? Use Report on the room's page. You don't need to be signed in. Pick a reason:
reason | Meaning |
|---|---|
overreach | Asks for more access than it needs |
hidden_action | Does something it doesn't disclose |
prompt_injection | Contains prompt tricks |
spam | Spam or advertising |
broken | Doesn't work as described |
other | Something else |
The front desk resolves the report, dismisses it, or unpublishes the room.
Your part
- Read the door before you check in, especially the Custom Rules.
- Prefer reviewed rooms for anything that touches money, other people or important records.
- Disconnect apps a room no longer needs.
- See the full House rules.