Definition
Permission models govern how AI coding agents authorize file writes, shell commands, and network requests. Modes range from human-in-the-loop (Manual) to autonomous (Auto) with background safety classifiers.
Key Points
-
2026-07-16: Codex full-access-mode failure highlights least-privilege defaults for coding agents
-
claude-code v2.1.200 (July 3, 2026): Renamed default mode to Manual — explicit approval per action
-
Config value remains
default;manualaccepted as alias -
Auto mode: Sonnet 4.6 classifier with background safety checks — now opt-in
-
Anthropic telemetry: 93% of prompts approved reflexively under prior defaults (approval fatigue)
-
Security: v2.1.200 also blocks untrusted
.mcp.jsonserver auto-spawn