Docs · permissions
Tool permissions
Use permission modes to decide which actions need approval. Tool switches are tested first: a disabled tool stays unavailable in every mode.
The five modes
Set the mode in the panel, or with /perm in the console. The mode applies to one conversation, and auto is the default.
| Mode | Reads | Edits | Acts |
|---|---|---|---|
| bypass | run | run | run |
| auto (default) | run | ask | ask |
| edits | run | run | ask |
| manual | ask | ask | ask |
| plan | run | refused | refused |
A few actions run without asking in every mode except manual, including plan: recalling memory, searching history, asking you a clarifying question, reading a project's notes, listing your own machines, and drawing a checklist. In manual the table above still applies, and each one is asked too.
Tool switches and modes
Modes control approvals, and switches turn individual tools off. For example, you can allow file edits while disabling shell commands. A disabled tool is refused in every mode, including bypass, until you enable it again.
Approval requests
When an action needs approval, the question appears in the conversation in the middle of the turn. It shows the tool, its kind (read / edit / act) and its arguments, and nothing runs until you answer. If you decline, the model is told that you declined. It works around the refusal and does not retry the same call.
Asking you a question
The assistant uses the clarify tool to ask you something in the middle of a task. Unlike a reply that ends with buttons, clarify pauses the turn where it is, and your answer comes back as a tool result. The model then continues from where it paused and keeps everything it had worked out.