Docs · permissions

Tool permissions

Use permission modes to decide which actions need approval. Tool switches are tested first: a disabled tool stays unavailable in every mode.

Docs home Install The console Models & seats Permissions The fleet DevAd FAQ

The five modes

Set the mode in the panel, or with /perm in the console. The mode applies to one conversation, and auto is the default.

ModeReadsEditsActs
bypassrunrun run
auto (default) runaskask
editsrunrun ask
manualaskask ask
planrun refusedrefused

A few actions run without asking in every mode except manual, including plan: recalling memory, searching history, asking you a clarifying question, reading a project's notes, listing your own machines, and drawing a checklist. In manual the table above still applies, and each one is asked too.

Tool switches and modes

Modes control approvals, and switches turn individual tools off. For example, you can allow file edits while disabling shell commands. A disabled tool is refused in every mode, including bypass, until you enable it again.

Approval requests

When an action needs approval, the question appears in the conversation in the middle of the turn. It shows the tool, its kind (read / edit / act) and its arguments, and nothing runs until you answer. If you decline, the model is told that you declined. It works around the refusal and does not retry the same call.

Asking you a question

The assistant uses the clarify tool to ask you something in the middle of a task. Unlike a reply that ends with buttons, clarify pauses the turn where it is, and your answer comes back as a tool result. The model then continues from where it paused and keeps everything it had worked out.

A known limit: permission modes are per conversation. A new chat starts in auto. Review the mode before you start work that can change files or run tools.