The outcome
Build a reusable Roo mode whose purpose, files, tools, provider, budget, and approval boundary are easy to audit.
Step by step
A workflow you can repeat.
- 01
Define one recurring role, its inputs and outputs, permitted paths, required evidence, prohibited actions, and escalation conditions.
- 02
Create a custom mode with concise instructions and only the tool groups needed, keeping terminal, browser, MCP, and edits unavailable unless essential.
- 03
Add versioned project rules that describe commands and architecture without secrets, personal data, or temporary implementation details.
- 04
Test the mode against routine, ambiguous, adversarial, destructive, and out-of-scope requests with auto-approval off and a disposable branch.
- 05
Document owners and limits, review provider and MCP data flows, and update or retire the mode whenever permissions or repository practices change.
Working standard
What good use looks like.
- One role per mode.
- Deny unused tool groups.
- Test refusal and escalation behavior.
Official references