The Archive · Desktop · Concepts
Permissions
How much TALOS Desktop may do without asking — the session permission, the rule of each tool, and the gaps they leave.
Checked on Desktop 0.1.19
A newer version is out (Desktop 0.1.25): some details may differ.
Two gates decide whether TALOS acts on its own or stops to ask you: the permission of the session, and the rule of each tool. When the tool’s rule is narrower, it wins.
The session permission
Section titled “The session permission”It answers one question: how much may TALOS do without asking? You choose it when you open a session, it is shown under each of your messages while the session works, and you can change it while the session is open; the change applies from then on. A new session never inherits it silently: it starts from the choice you make.
| Permission | What it means | Risk |
|---|---|---|
Read only |
Reads the project and runs commands that change nothing. Every write is refused. | Lowest |
Workspace write |
Writes only inside the session’s folder. Commands and tests go through the checks. The recommended choice. | Recommended |
On request |
Asks you before every action that leaves a trace: writes, commands, network. | Controlled |
Full access |
Files and network without the ordinary checks. Only when you already know what it is about to do. | High |
The exact rules of each one are on Permissions in the reference.
Full access, in full
Section titled “Full access, in full”It is the only choice that asks for an explicit confirmation before it applies, and the only one that lifts the checks outside the folder you are working on.
- Where it reads widens. No longer the session’s folder only: the whole drive that folder is on. That is the point of it, when the work spans several folders.
- Where it saves does not. A document or an image made during the session still lands in the folder the session started from — the one you chose.
- It adds no ability. It removes questions. With
On requestthe agent can do the same things; it asks first.
The rule of each tool
Section titled “The rule of each tool”Besides the session permission, some tools have a rule of their own: Capability in the sidebar lists the tools, what each does to your computer, how much it weighs in the conversation, and how often it was used in the open session. For a tool whose rule can be set, there are four choices:
- As the session — follows the session permission. The starting value.
- Always allow — runs without asking, even when the session would ask.
- Always ask — asks first, even when the session would not.
- Deny — never used.
A rule changes whether the tool asks, never what it does. A tool on “always ask” is highlighted in the list. Each tool also shows two descriptions on purpose: one says what it does to your computer, the other is the text the model receives.
The gaps, said plainly
Section titled “The gaps, said plainly”- Closing writes does not close every way to write. A command in the terminal, the creation of a document and the generation of an image can still leave a file on disk when the write tool is denied. To close that path for real, restrict the terminal too.
- It is not a sandbox. The permission does not isolate the rest of your computer.
- Some rules sit outside both gates. Files that steer TALOS itself — hooks, MCP servers, plugins, instructions — always ask before the agent writes them. See Control files.
When a write is refused
Section titled “When a write is refused”Check two things, in this order: the session permission, then the rule of that tool. If you changed the permission during a session and the agent still behaves as before, open a new session with the permission you want.