# Permissions and Confirmations

The two permission modes, which entry point uses which, and how confirmation prompts are routed.

## Permission mode

| Mode | Behavior |
|---|---|
| `single-confirm` | Each non-ReadOnly tool call requires user confirmation (the TUI default) |
| `always-allow` | Tools auto-execute; the LLM is instructed to invoke `ask_user` first for seven categories of truly irreversible operations |

The seven irreversible categories that still require explicit `ask_user` under `always-allow`:

1. Filesystem — `rm -rf` / `rm -r`, deleting directories or existing files not produced by this task
2. Database — `DROP DATABASE` / `DROP TABLE` / `TRUNCATE`, `DELETE` / `UPDATE` without `WHERE`, any production DSN
3. Git — `reset --hard`, `push --force` to main/master, deleting shared branches, `clean -fdx`
4. System — `chmod 777` / `chown -R`, edits under `/etc` / `/usr` / `/System`, launchctl / systemd changes, sudo escalation
5. Overwrite — an unread non-empty existing file, `.env` / credentials / lock files / `.git/index`
6. Cloud & infra — `gcloud` / `aws` / `kubectl delete`, `terraform destroy`
7. Process — `shutdown` / `reboot`, `kill -9` on system service PIDs

Ordinary writes (`edit_file`, build and test commands, `git status` / `add` / `commit`, read-only shell) proceed directly. The gate is enforced by the system prompt (`configs/prompts/system_prompt/permission/always_allow.md`), not by hardcoded Go-side filters.

## Mode by entry point

The active permission mode (`single-confirm` vs `always-allow`) is decided by entry point:

| Entry | Mode |
|---|---|
| TUI | `single-confirm`, toggled per session with `Shift+Tab` |
| `POST /v1/send` | `single-confirm`; confirms are answered through the web dashboard. The `allow_all` request field was removed |
| `POST /v1/chat/completions` | `always-allow` |
| Telegram | `single-confirm` (confirm gate uses a Telegram inline-keyboard select) |
| Discord | `single-confirm` (confirm gate uses a Discord select menu) |
| Resumed pending task | Keeps the mode stored with the task |
| Subagent | Inherits parent ctx |

The mode is rendered into the system prompt under `## Permission Mode`. Commands on the read-only list skip the gate in every mode.

## Tool `mode` gating

A tool that carries a `mode` is gated by it: `list` / `read` / `search` are treated as read-only and skip confirmation, while `remove` / `restore` always confirm even on an otherwise auto-approved tool.

## Origin-routed confirmations

Every interactive request carries an origin prefix — `cli-`, `chat-`, `tg-`, or `dc-`. CLI confirmations are consumed only by the TUI, web requests by the web confirmation stream, and Telegram or Discord requests by their matching channel listeners. A confirmation from a channel other than the TUI that is left unanswered for five minutes is skipped and the task is kept as pending (since v1.1.1 TUI confirmations wait without a time limit), so one channel can neither intercept nor indefinitely hold another channel's prompt.
