Skip to content

Permissions

What the agent may do without asking is the permission mode; what it asks, it asks in the conversation.

A selector in the composer toolbar. Shift+Tab cycles it through the modes on offer, and while the composer has focus its border takes the mode’s colour.

The permission modes list

Mode On the button What happens
Manual Manual Every edit and command waits for your approval
Edit automatically Auto-edit Files in the working directory are edited without asking; anything outside it, and commands, still ask
Plan Plan Reads and explores freely, then proposes a plan: no file is changed
Auto Auto Decides per task when to act and when to ask, based on how risky it is. Offered only when the current model supports it
Bypass permissions Bypass Nothing is ever asked, including commands that can destroy data

The mode changes on the live process: switching it never restarts the CLI. It can also change without you touching it: approving a plan sets the mode you chose to continue in.

Initial permission mode (Options → Chat) is the mode every new chat starts in: Default, Manual, AcceptEdits, Plan or BypassPermissions. Default leaves the choice to Claude Code, which reads permissions.defaultMode from your settings.json (user or folder) and picks a mode by itself when there is none (which may be Auto), as it does in a terminal; Manual asks before edits whatever that file says. BypassPermissions also requires Allow dangerously skip permissions: without it, sessions start in Manual. A resumed session starts in the mode it was last in.

When a tool needs your approval the prompt takes the composer’s place until you answer; a draft you were writing is kept. It names the tool and what it would touch:

The approval prompt on an edit: the file, the three choices, the text field

Key Choice
1 Yes: this once
2 Yes, allow …: this once, and stop asking. For an edit it reads Yes, allow all edits this session; for a command it names a rule and where it is saved, and that last word can be clicked to change it
3 No

Enter confirms the highlighted choice (Yes to begin with), ↑/↓ move between them, Esc answers No.

Or type what to do instead… refuses the tool and sends what you typed as the reason, so Claude reads an instruction rather than a bare no.

A shell command is shown in a box you can edit: what runs is what the box holds when you say Yes.

With several panes open, the one waiting on a permission raises a VS InfoBar, and an OS notification when you’re outside Visual Studio; see Several panes at once.

An Edit can also be opened in Visual Studio’s own diff while the prompt is up, to read it with the full editor; the answer is still given in the prompt. To change a proposal before it lands, ask the agent to show it in the editable diff first: there Ctrl+S hands back what you saved. See Reviewing changes.

AskUserQuestion is answered in the conversation. The answer can be structured: several questions in one panel, one tab each, single- or multi-select, with an Other choice that takes your own text. A single-select answer moves to the next question by itself; Submit answers is enabled once every question has one. Esc, or the cross, cancels.

A question with several tabs and an Other choice

Once answered, the row stays in the conversation as Question, with every option listed and your pick ticked. It folds like any other tool row: the chevron closes it down to its header, which still says whether it was Answered or Declined. It starts open in the Full View mode and closed in Focus and Hide tools.

An answered question: every option listed, the picks ticked

A long plan doesn’t have to be read through the prompt’s small scrolling box: the icon at its top right, Open in editor, shows it as a normal document in VS’s Markdown editor, full-size. While it is still waiting on your answer you can change it there and save; the banner picks the change up (Edited in the editor: this version is what gets approved), and approving sends what you wrote, not what was proposed.

The plan prompt: Open in editor and the three answers

The prompt asks which mode to continue in, not whether to run something:

Key Choice Continues in
1 Yes, and auto-accept Edit automatically
2 Yes, and manually approve edits Manual
3 No, keep planning Plan

The text field sends Claude what to change instead. After you answer, the row in the conversation keeps the decision and a button that reopens that plan, read-only.

It only appears at all if Allow dangerously skip permissions (Options → Chat) is on. It is off by default, and takes effect on new sessions: the CLI decides at launch whether the mode can ever be entered. Enabling it does not skip anything by itself: the mode still has to be selected. An organization policy can withhold it whatever the option says.

When it is the active mode it is named in red on the toolbar whether or not the composer has focus: it is the one worth noticing when you come back to a pane and don’t remember how you left it.