Before submitting
Problem or opportunity
A successful global profile apply is irreversible. runProfilesPanelAction writes models.json with a plain write (no backup, no atomic rename), replaces materialized routing for every omitted agent, and the existing revertClaim compensation only runs on failure. Nothing snapshots the pre-apply state, so an operator who approves a dialog without fully parsing it loses the previous routing with no recovery path from the tool (manual export/restore via /gentle:models x/r is the only workaround). This is the general form of #1349: the confirmation mitigates it, but a mistake after confirming is still unrecoverable.
Proposed outcome
Before a successful apply, snapshot the pre-apply state (global routing, materialized routing, and the active-profile marker, similar to what revertClaim already knows how to restore) and expose an undo path from the profiles panel (for example, a revert action or notification-anchored undo for the most recent apply). The apply notification could then honestly claim reversibility.
Alternatives considered
Additional context
Raised by @jonathanludena in #1349 ("A successful apply is irreversible"); PR #1384 confirmations and follow-ups address the pre-approval side. Related: #1349, #1384, #1557.
Before submitting
Problem or opportunity
A successful global profile apply is irreversible.
runProfilesPanelActionwritesmodels.jsonwith a plain write (no backup, no atomic rename), replaces materialized routing for every omitted agent, and the existingrevertClaimcompensation only runs on failure. Nothing snapshots the pre-apply state, so an operator who approves a dialog without fully parsing it loses the previous routing with no recovery path from the tool (manual export/restore via/gentle:modelsx/ris the only workaround). This is the general form of #1349: the confirmation mitigates it, but a mistake after confirming is still unrecoverable.Proposed outcome
Before a successful apply, snapshot the pre-apply state (global routing, materialized routing, and the active-profile marker, similar to what
revertClaimalready knows how to restore) and expose an undo path from the profiles panel (for example, a revert action or notification-anchored undo for the most recent apply). The apply notification could then honestly claim reversibility.Alternatives considered
.bakfiles, but leaves discovery to the operator.Additional context
Raised by @jonathanludena in #1349 ("A successful apply is irreversible"); PR #1384 confirmations and follow-ups address the pre-approval side. Related: #1349, #1384, #1557.