Docs › Agent
Approvals and permissions
The three approval modes, what each one asks about, and the commands that always need a human.
The agent asks before it changes anything. How much it asks is up to you, from the mode control under the composer.
| Mode | Asks before |
|---|---|
| Ask (default) | Every edit, every command, every connector call. |
| Auto-approve reads | Edits, commands and connector calls. Reading and searching happen without asking. |
| Bypass permissions | Nothing, except the cases below. |
What always asks
Some actions need a human even in Bypass mode. Bypass means "do not ask me about edits and builds". It does not mean "do not ask me before force-pushing".
- Downloading a script and piping it straight to a shell.
rm -rfon a path outside the workspace, where checkpoints cannot undo it.- Force-pushing, history rewrites, and hard resets.
- Anything that writes credentials or changes system settings.
- Reading a file that usually holds secrets (
.env, Terraform state, private keys, credentials files), printing one from the shell, orterraform output -json. What the agent reads is sent to the model provider, and Terraform state holds every password in plain text. - Changing real infrastructure:
terraform applyordestroy,pulumi up, andkubectlorhelmcommands that change a cluster. See Infrastructure as code.
Saving a memory always asks too, in every mode. A memory goes into the system prompt of every future session in that project, so an unreviewed one is a standing instruction you never agreed to.
Undoing a run
Every run can be reverted from its summary card, which puts each file back to what it was before the run started. Checkpoints go further: they snapshot the whole workspace, so you can return to any earlier point.
All documentation
Get started
Agent
- Agent overview
- Approvals and permissions
- Plan mode
- What the agent can do
- Running commands
- Browser tools
- Checkpoints and undo
- Infrastructure as code
- Running several agents at once