The Archive · CLI · Concepts
Permissions
How the TALOS CLI decides whether an action runs, asks you or is denied — modes, rules, protected folders and headless runs.
Checked on CLI 0.3.3
A newer version is out (CLI 0.5.2): some details may differ.
Every action TALOS takes goes through one decision: it runs, it asks you, or it is denied. Two things feed it — the mode of the session, and the rules you wrote — and a few limits that no mode lifts.
The mode is how actions with no rule of their own are approved. Shift+Tab (or Alt+M) cycles manual, accept
edits, plan and Full access in the interactive screen; --permission-mode sets it for one run.
| Mode | In short |
|---|---|
default — Manual |
Asks before every action no rule allows. The default. |
acceptEdits — Accept edits |
Also allows file edits inside the project, and simple file commands, without asking. |
plan — Plan |
Read only: writing, editing, hooks, plugins and commands that change anything are denied. |
auto — Auto |
A classifier decides for actions no rule covers: allow, deny, or ask you. |
dontAsk — Don’t ask |
Never asks: what would need your approval is denied. |
bypassPermissions — Full access |
Allows what would otherwise ask. Use it only in a disposable environment you can restore. |
Each mode in full is on Permissions.
A rule names a tool and a pattern — Bash(npm test), Edit(./src/**), Mcp(github:*) — and goes into
permissions.allow, permissions.ask or permissions.deny of a settings file. Rules from every scope are merged:
yours, the project’s, and yours for this project. A rule that cannot be read stops TALOS from starting, and says
which one. The grammar of each tool’s pattern is on Rules.
When TALOS asks, your answer can become a rule: allow once, allow for this session, always allow (an allow rule is
written), or always deny (a deny rule is written).
What no mode lifts
Section titled “What no mode lifts”- Writing outside the project is denied.
- A
denyrule denies, and anaskrule always asks — even in Full access. - Protected folders —
.git,.talos-cli,.github,.vscode,.idea,.husky— are never edited by accept edits or Auto. - A command with
&,|,;,<,>or parentheses never matches aBashrule, so it cannot slip through one.
The whole order of the decision, step by step, is on How a decision is made.
Headless runs
Section titled “Headless runs”A run with -p has no one to ask: an action that would ask is denied, and the run says so. To let a script do more,
write the rules it needs, or pick a mode for that run with --permission-mode. See
Allow, ask or deny a tool.