Skip to content

Controlling Sable

Sable can run an assessment end to end. Use these controls when you need oversight, new work, live redirection, or to stop stale tasks.

Choose a control

Need Use
Review every command before execution User-approve mode
Let Sable continue without per-command approval Autonomous mode
Add a specific work item to the queue Add task
Redirect the agent during an active task Steer
Provide a time-sensitive MFA code Steer
Stop the current task and move forward Skip Task
Update a queued task’s title or details Edit task

Human-in-the-loop approval

  1. Switch the session to User-approve mode.
  2. Review each proposed command.
  3. Approve only the commands that match your scope and risk tolerance.
  4. Switch back to Autonomous when you want Sable to continue without per-command approval.

Use User-approve when:

  • Working near sensitive or production systems
  • Enforcing a strict client scope
  • Reviewing exploitation or high-impact enumeration
  • Training operators on how Sable reasons

Sable asking the operator to approve or deny a proposed command

Review approvals and interactive input

Sable v2 collects pending approval requests in the action inbox. Review the proposed shell action and its assessment context before approving or denying it.

When a shell command requires interactive terminal input, provide the requested value from the same live assessment workflow. Never approve an action or enter a secret unless it matches the authorized scope.

Add tasks

  1. Open the assessment task pane.
  2. Click +.
  3. Write a specific, scoped task.
  4. Submit it to the queue.

Good examples:

  • Enumerate authenticated admin routes with the provided test account.
  • Retest the file upload flow after the extension filter change.
  • Review GraphQL introspection and document exposed mutation paths.
  • Validate whether the reported redirect can lead to credential exposure.

Edit, delete, and skip details: Task Management

Steer during an active task

  1. Open Steer while a task is running.
  2. Give a short redirection for the current work.
  3. Submit the instruction. Sable applies it to the active work or queues it for the next turn when the current shell action must finish first.
  4. Follow the event detail and progress messages to confirm that the guidance was applied.

Use Steer for live redirection. Put scope, out-of-scope systems, and engagement rules in the assessment scope fields, not in Steer.

Use Add task when you need a discrete unit of work with its own result. Use Steer when you need to redirect the task already in progress.

Steer is also the preferred way to provide a short-lived MFA code exactly when Sable reaches an authentication prompt. See Testing a target that uses MFA.

Operator guardrails

  • Keep all instructions inside the authorized target and scope.
  • Define scope and out-of-scope systems in the assessment scope fields.
  • Switch to User-approve before high-impact actions.
  • Use Steer for live guidance; use Methodologies for reusable workflow preferences.
  • Skip or delete tasks that are no longer relevant.

Next