Claude Code's Permission Modes, Explained With Examples

Manual, acceptEdits, plan, auto, dontAsk and bypassPermissions: what each Claude Code permission mode does when it tries to delete a file or push to git.

Claude Code's Permission Modes, Explained With Examples

Claude Code has six permission modes: default (labeled “Manual” in the CLI), acceptEdits, plan, auto, dontAsk, and bypassPermissions. Each one decides something very specific: what Claude can do without asking you first.

If you just installed it, it’s probably already surprised you that it doesn’t always ask the same way. Sometimes it edits a file without a word, other times it stops before a plain mkdir. It’s not random, it depends on the active mode. Let’s go through them one by one with the same scenario each time, so the difference is obvious: Claude wants to run rm -rf build/, do a git push, and edit a file.

Manual (default): asks about everything

The most conservative mode. Only reads get auto-approved: opening a file or running a grep doesn’t interrupt anything. Everything else (editing a file, a shell command that isn’t read-only, a network request, or a web search) stops and asks yes or no.

With our example: the rm -rf build/ asks for confirmation, so does the git push, and so does the edit. Three prompts, one per action. This is the mode for sensitive code or a repo you don’t know well yet.

acceptEdits: automates files, not commands

Here Claude edits and creates files without asking, and also approves a narrow set of filesystem commands like mkdir, touch, mv, or cp inside your working directory. The idea is you review the changes afterward, with git diff, instead of approving edit by edit.

rm isn’t on that list, and git push isn’t a file edit or one of those commands either: it’s still a regular shell command, so both ask the same way they would in Manual. The only thing that changes is the file edit, which now goes through directly.

Plan mode: investigate first, don’t touch anything

Claude reads files and runs read-only shell commands to understand the code, but never touches anything. It writes a plan and shows it to you before moving a finger. Neither the rm, nor the git push, nor the edit run here: they stay as a proposal until you approve the plan and switch modes to execute it. It’s the one I use to walk into an unfamiliar repo when I want to understand what’s there before changing anything.

Auto: approves with a background review

This is what changed on August 14, 2026: on Pro, Max, and Team plans, a new session in the terminal or VS Code now starts directly in auto mode instead of Manual. Claude approves practically everything without stopping you, but a background classifier reviews each action against what you asked for before letting it through. Anthropic announced that same day that, in a test with 1,053 paid testers, humans caught only 13.6% of dangerous commands planted in a session, versus 89% caught by the classifier.

With our example, the rm -rf build/, the git push, and the edit all run without an explicit prompt, unless the classifier decides the action doesn’t match what you asked for, in which case it still stops to ask. How to tune that criteria with your own rules is exactly the subject of the advanced permission rules guide: that’s where I get into the deny→ask→allow evaluation order and how to describe your infrastructure so the classifier gets it right more often.

dontAsk: never asks, denies instead

Built for CI and locked-down scripts. dontAsk doesn’t show a single prompt: any action that would normally need your confirmation and isn’t pre-approved (an allow rule or via /permissions) gets denied outright, without running. So if you haven’t pre-approved the rm, the git push, or the edit, all three get rejected on their own. Silent, but safe by default: if you didn’t say yes beforehand, the answer is no.

bypassPermissions: no prompts, except what’s untouchable

The mode with no safety net. It skips every permission check, including writes to protected paths like .git or .claude. Anthropic’s own documentation is blunt about it: it only makes sense inside isolated containers or virtual machines, never on your working machine. Here the rm -rf build/, the git push, and the edit all run without asking anything. One exception survives even this mode: an rm or rmdir targeting a critical system path never gets auto-approved, not by an allow rule and not by a hook that says yes.

When to use each one

For normal work in a repo you know, Manual or acceptEdits depending on how much you want to review each edit. To explore a new project without risk, plan mode. For long tasks where you don’t want to babysit every step, auto mode, knowing there’s a classifier watching in the background. For CI, dontAsk with an explicit allowlist. And bypassPermissions only inside a disposable container.

If your own agent also has to decide for itself when to ask for permission and when not to, across a multi-step flow, that discipline of “what it can do unsupervised and what it can’t” is exactly what’s covered in the agentic patterns course: applied there to agents you design yourself, not just to Claude Code.

Frequently Asked Questions

What’s Claude Code’s default mode?

It depends on how you run it. In the terminal or VS Code with a Pro, Max, or Team plan, it starts in auto (since August 14, 2026). With claude -p, the Agent SDK, an Enterprise plan, or a Claude Console API key, it starts in Manual (default).

How do I switch modes while I’m working?

Press Shift+Tab to cycle through Manual, acceptEdits, and plan; auto and bypassPermissions join the cycle when they’re available. You can also set the starting mode with permissions.defaultMode in your settings.json, or pass --permission-mode when launching Claude Code.

Are plan mode and auto mode just two names for the same thing?

No. Plan mode never edits anything until you approve an explicit plan. Auto mode does execute, edits included, relying on the classifier instead of your manual approval. One holds back every action, the other lets them through with an automated check.

Does acceptEdits let a git push through without asking?

No: it still asks for confirmation, same as in Manual.