# Privileged mode gates system-file writes The application starts read-only and permits changes to `/etc/hosts` only after sudo access has been validated and a timestamped backup has been created. All privileged writes go through `HostsManager` during that mode. This makes the authorization boundary visible to the user and guarantees a pre-edit safety snapshot; the temporary backup is not a user-facing recovery system.