The Archive · CLI · Concepts

Permissions

How the TALOS CLI decides whether an action runs, asks you or is denied — modes, rules, protected folders and headless runs.

Checked on CLI 0.3.3

A newer version is out (CLI 0.5.2): some details may differ.

Every action TALOS takes goes through one decision: it runs, it asks you, or it is denied. Two things feed it — the mode of the session, and the rules you wrote — and a few limits that no mode lifts.

The mode is how actions with no rule of their own are approved. Shift+Tab (or Alt+M) cycles manual, accept edits, plan and Full access in the interactive screen; --permission-mode sets it for one run.

Mode In short
default — Manual Asks before every action no rule allows. The default.
acceptEdits — Accept edits Also allows file edits inside the project, and simple file commands, without asking.
plan — Plan Read only: writing, editing, hooks, plugins and commands that change anything are denied.
auto — Auto A classifier decides for actions no rule covers: allow, deny, or ask you.
dontAsk — Don’t ask Never asks: what would need your approval is denied.
bypassPermissions — Full access Allows what would otherwise ask. Use it only in a disposable environment you can restore.

Each mode in full is on Permissions.

A rule names a tool and a pattern — Bash(npm test), Edit(./src/**), Mcp(github:*) — and goes into permissions.allow, permissions.ask or permissions.deny of a settings file. Rules from every scope are merged: yours, the project’s, and yours for this project. A rule that cannot be read stops TALOS from starting, and says which one. The grammar of each tool’s pattern is on Rules.

When TALOS asks, your answer can become a rule: allow once, allow for this session, always allow (an allow rule is written), or always deny (a deny rule is written).

  • Writing outside the project is denied.
  • A deny rule denies, and an ask rule always asks — even in Full access.
  • Protected folders — .git, .talos-cli, .github, .vscode, .idea, .husky — are never edited by accept edits or Auto.
  • A command with &, |, ;, <, > or parentheses never matches a Bash rule, so it cannot slip through one.

The whole order of the decision, step by step, is on How a decision is made.

A run with -p has no one to ask: an action that would ask is denied, and the run says so. To let a script do more, write the rules it needs, or pick a mode for that run with --permission-mode. See Allow, ask or deny a tool.

Type to search the guides.