The Archive · Desktop · Concepts

Permissions

How much TALOS Desktop may do without asking — the session permission, the rule of each tool, and the gaps they leave.

Checked on Desktop 0.1.19

A newer version is out (Desktop 0.1.25): some details may differ.

Two gates decide whether TALOS acts on its own or stops to ask you: the permission of the session, and the rule of each tool. When the tool’s rule is narrower, it wins.

It answers one question: how much may TALOS do without asking? You choose it when you open a session, it is shown under each of your messages while the session works, and you can change it while the session is open; the change applies from then on. A new session never inherits it silently: it starts from the choice you make.

Permission What it means Risk
Read only Reads the project and runs commands that change nothing. Every write is refused. Lowest
Workspace write Writes only inside the session’s folder. Commands and tests go through the checks. The recommended choice. Recommended
On request Asks you before every action that leaves a trace: writes, commands, network. Controlled
Full access Files and network without the ordinary checks. Only when you already know what it is about to do. High

The exact rules of each one are on Permissions in the reference.

It is the only choice that asks for an explicit confirmation before it applies, and the only one that lifts the checks outside the folder you are working on.

  • Where it reads widens. No longer the session’s folder only: the whole drive that folder is on. That is the point of it, when the work spans several folders.
  • Where it saves does not. A document or an image made during the session still lands in the folder the session started from — the one you chose.
  • It adds no ability. It removes questions. With On request the agent can do the same things; it asks first.

Besides the session permission, some tools have a rule of their own: Capability in the sidebar lists the tools, what each does to your computer, how much it weighs in the conversation, and how often it was used in the open session. For a tool whose rule can be set, there are four choices:

  • As the session — follows the session permission. The starting value.
  • Always allow — runs without asking, even when the session would ask.
  • Always ask — asks first, even when the session would not.
  • Deny — never used.

A rule changes whether the tool asks, never what it does. A tool on “always ask” is highlighted in the list. Each tool also shows two descriptions on purpose: one says what it does to your computer, the other is the text the model receives.

  • Closing writes does not close every way to write. A command in the terminal, the creation of a document and the generation of an image can still leave a file on disk when the write tool is denied. To close that path for real, restrict the terminal too.
  • It is not a sandbox. The permission does not isolate the rest of your computer.
  • Some rules sit outside both gates. Files that steer TALOS itself — hooks, MCP servers, plugins, instructions — always ask before the agent writes them. See Control files.

Check two things, in this order: the session permission, then the rule of that tool. If you changed the permission during a session and the agent still behaves as before, open a new session with the permission you want.

Type to search the guides.