Permissions and Confirmations
The two permission modes, which entry point uses which, and how confirmation prompts are routed.
Permission mode
| Mode | Behavior |
|---|---|
single-confirm |
Each non-ReadOnly tool call requires user confirmation (the TUI default) |
always-allow |
Tools auto-execute; the LLM is instructed to invoke ask_user first for seven categories of truly irreversible operations |
The seven irreversible categories that still require explicit ask_user under always-allow:
- Filesystem —
rm -rf/rm -r, deleting directories or existing files not produced by this task - Database —
DROP DATABASE/DROP TABLE/TRUNCATE,DELETE/UPDATEwithoutWHERE, any production DSN - Git —
reset --hard,push --forceto main/master, deleting shared branches,clean -fdx - System —
chmod 777/chown -R, edits under/etc//usr//System, launchctl / systemd changes, sudo escalation - Overwrite — an unread non-empty existing file,
.env/ credentials / lock files /.git/index - Cloud & infra —
gcloud/aws/kubectl delete,terraform destroy - Process —
shutdown/reboot,kill -9on system service PIDs
Ordinary writes (edit_file, build and test commands, git status / add / commit, read-only shell) proceed directly. The gate is enforced by the system prompt (configs/prompts/system_prompt/permission/always_allow.md), not by hardcoded Go-side filters.
Mode by entry point
The active permission mode (single-confirm vs always-allow) is decided by entry point:
| Entry | Mode |
|---|---|
| TUI | single-confirm, toggled per session with Shift+Tab |
POST /v1/send |
single-confirm; confirms are answered through the web dashboard. The allow_all request field was removed |
POST /v1/chat/completions |
always-allow |
| Telegram | single-confirm (confirm gate uses a Telegram inline-keyboard select) |
| Discord | single-confirm (confirm gate uses a Discord select menu) |
| Resumed pending task | Keeps the mode stored with the task |
| Subagent | Inherits parent ctx |
The mode is rendered into the system prompt under ## Permission Mode. Commands on the read-only list skip the gate in every mode.
Tool mode gating
A tool that carries a mode is gated by it: list / read / search are treated as read-only and skip confirmation, while remove / restore always confirm even on an otherwise auto-approved tool.
Origin-routed confirmations
Every interactive request carries an origin prefix — cli-, chat-, tg-, or dc-. CLI confirmations are consumed only by the TUI, web requests by the web confirmation stream, and Telegram or Discord requests by their matching channel listeners. A confirmation from a channel other than the TUI that is left unanswered for five minutes is skipped and the task is kept as pending (since v1.1.1 TUI confirmations wait without a time limit), so one channel can neither intercept nor indefinitely hold another channel's prompt.