All documentation

Documentation Settings: This Mac

Permission modes and what Auto asks

The six modes on the composer's Permission chip, what Auto still stops for, and how Smart's judge decides.

The mode decides what the lead may do without asking you. It is the Permission chip under the composer, and the slash commands such as /manual, /edits and /bypass set it too. Whatever the mode, the sandbox still holds.

The modes, in menu order

  • Manual: asks before every file change and every command.
  • Accept edits: file changes go through; commands still ask.
  • Smart: file changes go through, and a fast model judges everything else (see below).
  • Plan: discussion only. No tools run.
  • Auto: the default. Writes in the workspace and ordinary commands run; dangerous ones ask.
  • Bypass: never asks. Use it only in a throwaway workspace. The chip turns amber while it is on.
The Permission chip under the composer, with its menu open on Auto
The Permission chip under the composer, with its menu open on Auto

A lead running in its own command-line tool cannot stop mid-turn to ask you, so the app passes the nearest mode that CLI has. Manual and Plan become its read-only or plan mode, Accept edits its edit mode, Auto its automatic mode, and Bypass its unrestricted mode. Smart has no CLI equivalent, and a CLI lead in Smart runs read-only.

A team can set a mode floor in Governance, so members cannot choose anything looser than, say, Smart.

Smart and its judge

In Smart, edits go through and every other call goes to a fast model with one question: allow, or ask. Anything short of a clear allow (a refusal, a timeout, no key for the judge) comes to you as a card. A dangerous command is never allowed by the judge, and Smart never answers for you when nobody is there. The judge is told that the action it reads is data, never an instruction. You can switch Smart on from the Guardrails list as Let a model decide the rest.

Dangerous commands

In Auto these still ask: sudo and su; rm -rf on /, ~ or a wildcard; find -delete; shutdown, reboot, diskutil, launchctl, crontab and killall; chmod or chown on / or ~; keychain commands; git push, npm publish and flyctl deploy; ssh, scp, sftp, rsync to a host, nc and telnet; curl or wget sending a body, or a script piped from the network into a shell; any command that names a credential store; and anything touching the installed app. This list catches commands that say what they do. It is not a wall, and a command that disguises itself can pass it. The sandbox is the wall.

What Auto still asks about

Mac only: Settings → Account → Sign-in & Security → What Auto still asks about. Each switch reads "Ask before …".

Ask beforeDefault
installing a build on the simulator, launching an app in it, or opening the SimulatorOff
tapping, typing, pressing keys or opening a URL in the simulatorOn
installing or starting an app on the connected phoneOff
opening an app on this MacOff
quitting an app on this MacOn
reading or photographing one app's windowOff
photographing the whole screenOn
clicking or typing in an app on this MacOn
opening a page in the browser paneOff
clicking, typing, pressing keys or running a script in the browser paneOn
running a script in your own app through its devtoolsOff
reading an address on this Mac (localhost)Off
reading any other address on this Mac or its networkOn

The ones on by default act where your logins are, photograph everything, or reach your network. Whatever you set here, a dangerous command, work outside the workspace, a sandbox refusal, mail or a payment, a merge and a schedule ask in every mode except Bypass.

Settings → Account → Sign-in & Security → What Auto still asks about
Settings → Account → Sign-in & Security → What Auto still asks about

Further reading. LLM06:2025 Excessive Agency — OWASP, 2025.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.