# Permission modes

> Choose how often agents ask before commands and edits. This is separate from how Winskel routes work.

- Canonical page: https://www.winskel.com/docs/permission-modes
- Applies to: Winskel public download 0.7.0-alpha.1 (alpha channel), Apple Silicon, macOS 12 or later
- Content updated: 2026-10-06
- Agent reference: https://www.winskel.com/agents.md

## Two different controls

- Orchestration control decides which models do the work and how it is split through Autopilot, Preferences, or Custom. See [choosing models](https://www.winskel.com/docs/choosing-models).
- Agent permissions, Ask Me, Smart Auto, and Autonomous, decide which commands and edits an agent may run without asking you.

They are independent. Autopilot does not grant extra shell access, and Autonomous does not change how work is routed.

## Three permission modes

- Ask Me: ask before routine edits and commands.
- Smart Auto, the default: allow routine project work while sensitive actions still ask.
- Autonomous: allow routine development more freely, such as development servers and local tools. Installs, network access, credentials, and composed shell commands still ask, and destructive, privileged, and outside-project actions stay restricted.

## Defaults and project overrides

Choose the mode for an objective with the Agent permissions control in the composer. A project can set a fallback, and so can your account in Settings. Remembered grants apply to a class of action, Project checks, Repository edits, or Development server, rather than an arbitrary shell prefix, and can be removed per project. Destructive actions ask every time, even with a grant.

## Hard boundaries

Some actions are blocked in every mode, such as sudo, git reset --hard, force push, deleting your home folder, and paths outside the trusted worktree. Permission rules reduce risk, but agents still run under your local user account and are not inside an operating system sandbox.
