---
url: https://bishop.agentdeployment.co/reference/limits.md
description: What this version of Bishop doesn't do.
---

# Limits

What this version of Bishop doesn't do.

* **One agent per process.** One Bishop directory runs one agent, and there's no agent registry. Run a second Bishop from a second directory for a second agent.
* **Threads share a working directory unless worktree mode is on.** [Worktree mode](/running/worktrees) keeps concurrent threads out of each other's files by convention, and needs a git repository. The [sandbox](/running/sandbox) keeps the agent out of Bishop's own state and other threads' shared files, but not out of other threads' checkouts.
* **No approval flow.** Permission decisions are the harness's, and a conversation has no way to ask a person for one.
* **No way to turn Bishop's own tools off.** Bishop serves them on `127.0.0.1`, on an ephemeral port, authenticated with a credential minted per turn and destroyed when the turn ends. Nothing is reachable from off the machine, but anything running on it can reach the port and will be refused.
* **No health signal for a dead Slack connection.** Bishop notices neither a revoked Slack app nor a dead socket, so a supervised process can look healthy while receiving nothing. Restart it if the agent goes quiet.
* **Group chat files in Teams are untested.** A direct chat and a channel are the two that are known to work.
* **No sandbox in the container image**, since it doesn't include nono.
