Permissions
What the agent may do without asking is the permission mode; what it asks, it asks in the conversation.
The modes
Section titled “The modes”A selector in the composer toolbar. Shift+Tab cycles it through the modes on offer, and while the composer has focus its border takes the mode’s colour.

| Mode | On the button | What happens |
|---|---|---|
| Manual | Manual | Every edit and command waits for your approval |
| Edit automatically | Auto-edit | Files in the working directory are edited without asking; anything outside it, and commands, still ask |
| Plan | Plan | Reads and explores freely, then proposes a plan: no file is changed |
| Auto | Auto | Decides per task when to act and when to ask, based on how risky it is. Offered only when the current model supports it |
| Bypass permissions | Bypass | Nothing is ever asked, including commands that can destroy data |
The mode changes on the live process: switching it never restarts the CLI. It can also change without you touching it: approving a plan sets the mode you chose to continue in.
Initial permission mode (Options → Chat) is the mode every new
chat starts in: Default, Manual, AcceptEdits, Plan or BypassPermissions. Default leaves
the choice to Claude Code, which reads permissions.defaultMode from your settings.json (user or
folder) and picks a mode by itself when there is none (which may be Auto), as it does in a
terminal; Manual asks before edits whatever that file says. BypassPermissions also requires Allow dangerously skip permissions: without it,
sessions start in Manual. A resumed session starts in the mode it was last in.
Approving a tool
Section titled “Approving a tool”When a tool needs your approval the prompt takes the composer’s place until you answer; a draft you were writing is kept. It names the tool and what it would touch:

| Key | Choice |
|---|---|
| 1 | Yes: this once |
| 2 | Yes, allow …: this once, and stop asking. For an edit it reads Yes, allow all edits this session; for a command it names a rule and where it is saved, and that last word can be clicked to change it |
| 3 | No |
Enter confirms the highlighted choice (Yes to begin with), ↑/↓ move between them, Esc answers No.
Or type what to do instead… refuses the tool and sends what you typed as the reason, so Claude reads an instruction rather than a bare no.
A shell command is shown in a box you can edit: what runs is what the box holds when you say Yes.
With several panes open, the one waiting on a permission raises a VS InfoBar, and an OS notification when you’re outside Visual Studio; see Several panes at once.
An Edit can also be opened in Visual Studio’s own diff while the prompt is up, to read it with the full editor; the answer is still given in the prompt. To change a proposal before it lands, ask the agent to show it in the editable diff first: there Ctrl+S hands back what you saved. See Reviewing changes.
Answering a question
Section titled “Answering a question”AskUserQuestion is answered in the conversation. The answer can be structured: several
questions in one panel, one tab each, single- or multi-select, with an Other choice that takes
your own text. A single-select answer moves to the next question by itself; Submit answers is
enabled once every question has one. Esc, or the cross, cancels.

Once answered, the row stays in the conversation as Question, with every option listed and your pick ticked. It folds like any other tool row: the chevron closes it down to its header, which still says whether it was Answered or Declined. It starts open in the Full View mode and closed in Focus and Hide tools.

Reviewing a plan
Section titled “Reviewing a plan”A long plan doesn’t have to be read through the prompt’s small scrolling box: the icon at its top right, Open in editor, shows it as a normal document in VS’s Markdown editor, full-size. While it is still waiting on your answer you can change it there and save; the banner picks the change up (Edited in the editor: this version is what gets approved), and approving sends what you wrote, not what was proposed.

The prompt asks which mode to continue in, not whether to run something:
| Key | Choice | Continues in |
|---|---|---|
| 1 | Yes, and auto-accept | Edit automatically |
| 2 | Yes, and manually approve edits | Manual |
| 3 | No, keep planning | Plan |
The text field sends Claude what to change instead. After you answer, the row in the conversation keeps the decision and a button that reopens that plan, read-only.
Bypass
Section titled “Bypass”It only appears at all if Allow dangerously skip permissions (Options → Chat) is on. It is off by default, and takes effect on new sessions: the CLI decides at launch whether the mode can ever be entered. Enabling it does not skip anything by itself: the mode still has to be selected. An organization policy can withhold it whatever the option says.
When it is the active mode it is named in red on the toolbar whether or not the composer has focus: it is the one worth noticing when you come back to a pane and don’t remember how you left it.