Skip to content
Documentation

Protect & operate

Keep discovery inside a useful root.

Prevent broad scans from turning a project task into a home-directory crawl.

AvailableReviewed September 2026

Root guard and PathJail do different jobs

Root guard protects project discovery and indexing from overly broad or sensitive roots. PathJail validates file access against the effective allowed boundaries.

A root accepted for indexing is not authorization to read everything on the machine.

Start in the project

Launch the host and LeanCTX from the repository or intended workspace. Check that the detected root matches your task before building an index.

On a monorepo, choose the appropriate project root and use include/exclude settings to narrow indexing. Do not solve a refused broad scan by disabling the entire access boundary.

Diagnose a refusal

Read the exact refused path and compare it with the working directory, configured project root and allowed roots. Resolve symlinks and shared directories deliberately.

lean-ctx status
lean-ctx doctor
lean-ctx config path

If a legitimate task needs another repository, use a documented multi-root or provider path and grant only the required access.

Keep resource use bounded

A narrow root improves relevance and limits index work. Pair it with the file and thread limits in performance tuning.

Sources & versions2 references Reviewed
Core checkout
0ce2207ee4
Installed runtime
3.10.2
SDK release
1.1.0

Separate baselines for source, CLI/configuration and SDK contracts. Review does not certify every platform or integration.

Versions & compatibility