Working in a project

Permissions

Four modes, from only proposing to working on its own.

Every tool call goes through one check before it runs, built-in tools and extension tools alike.

ModeReadsEditsDeletesCommands
Plan onlyYesNoNoNo
Ask firstYesAsksAsksAsks
Accept editsYesYesAsksAsks
AutoYesYesYesYes

Accept edits is the default and the sensible one: every edit shows as a diff and can be undone. Keep Auto for projects you can restore.

Draggy's Code preferences: model, thinking and web access, and the four permission modes a new project can start in, with Accept edits chosen.

Reading never asks

In any mode, plan mode included: reading and listing files, searching them, git status and diffs, web search, your document library, loading a skill, writing the plan.

The card

ButtonCovers
Allow onceThis call. The next one asks again.
Allow for this taskThis kind of call for the rest of the reply.
Always allow hereRemembered for this project.
Don'tRefused. The model carries on without it.

Settings → Code → Projects lists everything you have allowed, each with Remove.