Working in a project
Permissions
Four modes, from only proposing to working on its own.
Every tool call goes through one check before it runs, built-in tools and extension tools alike.
| Mode | Reads | Edits | Deletes | Commands |
|---|---|---|---|---|
| Plan only | Yes | No | No | No |
| Ask first | Yes | Asks | Asks | Asks |
| Accept edits | Yes | Yes | Asks | Asks |
| Auto | Yes | Yes | Yes | Yes |
Accept edits is the default and the sensible one: every edit shows as a diff and can be undone. Keep Auto for projects you can restore.
Reading never asks
In any mode, plan mode included: reading and listing files, searching them, git status and diffs, web search, your document library, loading a skill, writing the plan.
The card
| Button | Covers |
|---|---|
| Allow once | This call. The next one asks again. |
| Allow for this task | This kind of call for the rest of the reply. |
| Always allow here | Remembered for this project. |
| Don't | Refused. The model carries on without it. |
Settings → Code → Projects lists everything you have allowed, each
with Remove.