The Archive · CLI · Guides

Allow, ask or deny a tool

Write permission rules for the TALOS CLI, check what a rule would decide before you rely on it, and answer when TALOS asks.

Checked on CLI 0.3.3

A newer version is out (CLI 0.5.2): some details may differ.

How modes and rules fit together is explained in Permissions. Here is how to write the rules.

The approval card offers, by number:

  1. Allow once;
  2. Allow for this session;
  3. Always allow — an allow rule is written for that operation;
  4. Deny, and the turn goes on;
  5. Always deny — a deny rule is written (in the full review, opened with v).

Esc denies and stops the turn.

Rules go in permissions.allow, permissions.ask or permissions.deny, one Tool(pattern) each:

Terminal window
talos config set permissions.allow '["Bash(npm test)", "Bash(npm run:*)", "Edit(./src/**)"]' --scope project
talos config set permissions.deny '["Bash(rm:*)"]' --scope project-user
  • project — shared with whoever uses the project;
  • project-user — yours, for this project, kept outside it;
  • user — yours, for every project.

Rules from every scope are merged. The pattern of each tool — commands matched word by word, paths relative to the project — is on Rules.

Terminal window
talos config permissions dry-run --tool Bash --command "npm run build"

It says which rule would allow, ask or deny that action, without running it. talos config origins shows which file each value comes from.

Type to search the guides.