Skip to content
Start here

POPULAR GUIDES

    FROM THE DOCUMENTATION

    Open this guide ↗
    ↑ ↓ select ↵ open esc closeV3Code Docs
    The editoreditor

    Permissions and approvals

    ↗ View as Markdown

    Understand what the native agent is asking to do before allowing it.

    Review file paths, commands, and service access before approving an action. A permission request is not proof that an operation is safe. Decline requests outside the task.

    The native tool registry separates file edits, terminal commands, MCP tools, computer control, and project changes. For example, opening a project changes the active editor context; terminal approval also covers Git writes and persistent command execution.

    Read and Plan offer a narrower workflow than Agent. Debug has a bounded repair tool set. Subagents inherit the relevant execution profile and approval boundaries; delegation should not be treated as a way to bypass them.

    Memory updates are not source-code edits and do not use the same approval category. Read-only investigation can still produce memory notes.

    Review each MCP connector before enabling it. Browser access can include authenticated pages. An ACP agent’s own permissions and runtime also matter; native-mode restrictions should not be assumed to govern every external agent.

    A tool confirmation does not mean every command runs in a fully isolated operating system. Do not assume a universal network block or filesystem sandbox. Work only in trusted projects, keep credentials out of prompts, and use separate environments for untrusted code.

    See Privacy, MCP, and Other agents.