# Modes V3Code's mode picker changes what the agent is allowed to do with a turn. Your selected model, keys, and project stay the same; the tool and approval boundaries change. Open the picker in the chat composer to switch modes. ## Built-in modes | Mode | What it does | Reach for it when | | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | | **Chat** | Conversation without callable tools. | You want a quick answer or want to discuss attached context without the agent taking action. | | **Read** | Read-only investigation with search, index, memory, and structural tools but no source edits or terminal commands. | You want the agent to inspect the real project and report back. | | **Plan** | Read-only investigation plus Markdown plan documents. | You want a grounded implementation plan before execution. | | **Debug** | Reproduces, localises, proves, fixes, and guards one bug with a bounded tool surface. | A failure needs evidence and a minimal verified repair. See [Debug mode](/editor/debug-mode). | | **Multitask** | Acts as a foreman: plans, dispatches work agents, and reconciles their results. The coordinator does not directly edit source or run terminal commands. | A larger job can be divided into independent pieces. | | **Agent** | Full execution — reads, edits, runs commands, the whole tool set. | You're ready to ship a change end to end. | Custom agents appear below the built-in modes. **Configure Custom Agents** opens the agent setup screen, including compatible ACP agents. See [External agents in native chat](/connect/agent-client-protocol). ## Approvals: what needs your OK Modes control *what class* of action the agent takes; **approvals** control whether a given action runs automatically. Reads are automatic. Actions that change things ask first, grouped into a few classes: - **Edits** — creating, deleting, rewriting, or editing files, renaming symbols, generating images. - **Terminal** — running commands, the test runner, the sandbox, and any git write (commit, push, checkout…). - **Browser & notes** — navigating/typing/clicking in the browser, and saving persistent notes. Read-only tools (reading files, searching, structural lookups, git status/diff) do not prompt. Modes can narrow the available tools further. Debug, for example, allows a small approval-gated repair surface but withholds deletes, git writes, browser mutation, and MCP tools. ## Modes vs. the V3 / IDE layout Don't confuse the agent's modes with the **V3 / IDE** pill in the title bar — that switches the *layout* (full-screen chat vs. classic editor), not the agent's behavior. > Note: > > **Design** and **Cyber Protection** are composer options, not modes. Design activates > the [design workflow](/editor/design-mode); Cyber Protection activates the > [security workflow](/editor/cyber-protection).