What AI may write
The reach of one confirmation card: which objects it edits, how it validates, how it commits.
What one confirmation card can do
Every write the agent performs goes through the same card: 1–8 atomic operations, confirmed once, applied once, undone once. Grouped by object:
- Characters: create, edit fields (name, aliases, gender, age, occupation, character arc, appearance note, phase state, importance tier, factions), delete.
- Character relationships: create (a shared label, or two directional labels plus a note), delete.
- Locations / props / lore / foreshadows / timeline: create, edit fields, delete for each; lore additionally supports replacing a whole description; timeline covers a plotline’s name, colour, mode and axis range.
- Script: text patches (line identities preserved), and chapter / scene / scene setting structure fields—create, edit, delete.
What it verifies before you confirm
- Every referenced chapter, scene, scene setting and content block must exist and sit at the right level; foreshadow and timeline anchors are held to the same rule.
- A time span must end after it starts; enum fields may only take existing tiers (importance, narrative weight, foreshadow technique and importance, lore category, and so on).
- Deletions compute their impact and show the counts on the card: appearances, relationships, child-location subtrees, inbound links, events inside the lane, script anchors. Removing a chapter or scene also clears the foreshadow and timeline anchors pointing at it, leaving no dangling reference.
- Where factions are involved the card states both “which faction cards will be created” and “which factions this character ends up in”. An ambiguous name or a card that moved on refuses the whole card—members are never quietly emptied.
What if the project moves while you decide
The card carries a fingerprint of the content it was built from. On confirmation the runtime recomputes and compares it target by target: a vanished target refuses the card as “not found”, changed content refuses it the same way. There is no case where it computes against an old draft and presses it over your newer work. A card left too long reads “Proposal expired”; “Update and continue” rereads and regenerates.
How it commits after you confirm
- Editing locks“Applying AI changes” appears; ordinary edits during that window are not written, so two truths never race.
- Old edits drain firstPending ordinary saves commit before the lock re-checks identity and fingerprints.
- One commitAll operations apply in order and the whole set is written to authoritative storage at once; only after that succeeds do the in-memory view, versions and derived files update.
- A way backThe full pre-write snapshot goes onto the project undo stack—one undo returns you to before the confirmation. On a transient failure the candidate never entered your project and the card stays retryable.
Images do not ride this card
Portraits, prop and location images follow another chain: the agent drafts a prompt from the record, you edit the wording, the image generates, and only “use” puts it into the record. The Direct path skips the draft and renders your own description without layering the project’s default visual style. Results come back as references and then land in the project; image bytes never enter the chat history. The project’s visual style lives in project settings and serves only as the default basis for generation.
Limits and troubleshooting
- One card cannot both “create a plotline” and “hang a new event on that new line”: the lane’s id exists only after the first write, so do it in two steps.
- A malformed tool call is retried by the model at most twice; permission, cancellation, or version problems stop immediately with a stated reason.
- Images already generated are not voided by a later step failing.
- Every AI write is billed to your account; call and credit history is in Account.
The mechanism end to end: AI collaboration overview.