Chapter 08 · CLI
Permission modes: default, plan, acceptEdits, auto, dontAsk and bypass
The permission mode decides how much freedom the tool has to edit files and run commands without asking. Choosing between default, plan, acceptEdits, auto and bypass balances speed against safety.
Video
Steps
- Choose default when you want oversight. It allows reads without a prompt; existing permission rules can allow or block other actions.
- Use plan to research and propose changes without editing your source. Approval options choose the execution mode; planning does not remove permission checks.
- acceptEdits approves edits and common filesystem commands within the working directory or additionalDirectories. Other commands and protected paths still require approval.
- auto uses a separate safety classifier and keeps explicit ask rules. dontAsk denies actions that would need a prompt. bypassPermissions skips routine prompts, but explicit deny and ask rules still apply. Use bypass only in a trusted, isolated environment.
Mechanism animation (illustration)
Common pitfall: Do not treat auto as bypass, or assume acceptEdits asks about every command. Check the current mode, scopes and permission rules before running a task.
Hands-on exercise: Run the same editing task in default and acceptEdits and record the experience difference. Try plan mode before a big change and reject or approve the plan.
Filmed demo · Video is added in the media phase
Recap
Comprehension check
What does plan mode do?
Recap
- Modes set the baseline; rules still matter
- acceptEdits also allows scoped filesystem commands
- auto safety checks differ from bypass