Line A · Authorship

Whose words these are

Stet is a plugin for Claude Code. You mark the lines you wrote, and the agent stops being able to touch them. Not by being asked. By being refused.

Every file carries three answers. Who wrote it. What may still be done to it. Which sentences are yours rather than the machine's.

One

Three states, three behaviours

So what makes a page yours? Reading it and accepting it. Not time. Not the writing being good. Not you having typed every word of it. Until you accept it, it belongs to the agent that wrote it.

Approved and authored are both closed. The difference is who did the typing, and it shows up when you ask for a rebuild. An approved page can be rebuilt. An authored one is yours to replace and nobody else's.

State Wrote it Edit the words? Regenerate it?
draftAn agentYesYes
approvedAn agent, accepted by a personNoOnly if asked, each time
authoredA personNoNever
Two

One sentence at a time

A file's state covers the whole file. Under it sits a list of the sentences a person wrote. Not line numbers. The words themselves.

That is the whole trick. Keep a line number and the lock breaks the moment a paragraph lands above it. Keep the words and the lock holds while the section moves, the voice changes and the page is rebuilt.

Rewrite the sentence yourself and the lock comes off. That is right. They are different words now.

Most pages end up mixed. The agent wrote nearly all of it. Three lines are yours. The agent works around those three.

Agent

The studio was founded in 2019 and works with clients in publishing and retail.

Yours · held

We started this because a client asked us to change one word and got back a page nobody recognised.

Agent

The team is based in Glasgow and takes on four projects a year.

Edit around them. Nothing in the record moves when the agent rewrites the two grey lines.

Three

Policy is a separate question

State says whose the words are. Policy says what may still happen to them once they are closed.

The one worth knowing

Authored plus refresh. These are my words. Keep the numbers in them true. Change the figure, leave the sentence.

Ask policy about any file and it tells you in plain English. It works the answer out by calling the same code the hook calls, so what it tells you and what the hook will do cannot drift apart.

StatePolicyWhat an agent may do
draftanyRewrite freely. Nobody has accepted it
approved or authoredno policy, or frozenNothing, including figures that moved
approved or authoredrefreshUpdate the named figures. Change no other word
approved or authoredopenRewrite the words. Ownership does not move
Four

It refuses. It does not advise.

Put the rule in a prompt and it holds until it does not, and nothing tells you which turn that was. This exists because we watched an agent break its own written rules inside one session, while telling us it was following them.

So the rule is a PreToolUse hook instead. It reads the record before the edit lands and answers before the file moves. It does not advise.

A file nobody has claimed gets a no. So does that mean it starts refusing edits all over your project? No, and here is exactly where it stops. A project with no stet.config.json is not using Stet, and the hook does nothing at all. Installing it changes nothing until you say so. Only the paths you list as content are considered. Your code passes straight through. A file that does not exist yet is new writing, so it is always allowed.

Inside those lines the no is the safe answer. The first thing ingest does in a new project is read what is already there and mark it as yours, because a person wrote it and that person was not the agent.

A file with an owned sentence in it

“site/index.html contains a sentence the author wrote. Those words are theirs, character for character. Everything else in this file is still open to you: edit around them.”

permissionDecision: deny
A file nobody has claimed

“docs/history.md is content and it is unclaimed. Content with no record belongs to whoever wrote it, and that was not you.”

permissionDecision: deny
Five

Getting the hook out of your way

Sooner or later you will want an agent to edit a closed file. Does that mean turning the whole thing off? No. You open one file.

admin unlock opens one file, and it will not do it without a reason. admin relock shuts it again. While a file is open, admin status says which one, since when, and why.

There is a global off switch. admin off will not fire without a reason, and once it has, admin status opens with THE HOOK IS OFF and the reason you gave, every time you run it, until you turn it back on. Opening one file is almost always what you actually wanted.

“Improve this page” is not permission to rewrite a locked line inside it. The agent improves what it may, then tells you what it left alone. If every line on the page is yours, it says so and stops.

The escape hatch, with its record
stet admin unlock README.md \
     --for "the price changed"

# edit, then:
stet admin relock README.md

Both land in .stet/admin.json, which the hook reads before it reads state.