The Archive · Desktop reference

Permissions

What a TALOS Desktop session may do on its own: the four modes, per-tool exceptions, the rules that always ask, and protected files.

Reference for TALOS Desktop 0.1.25 generated from the source of the release · released

Choose the mode for a session in the composer, or send permessi when you start it through the API. It can change while the session runs.

Read only
The agent reads and searches; it cannot write files, run commands or make documents.
Workspace writedefault
The default. The agent writes and runs commands without asking, except where a rule below still asks.
On request
Every write, command and document asks you first (an approval card; the turn waits, without a timeout).
Full access
Like Workspace write, without the check on data leaving (below), and the agent may work on files outside the session’s folder. Per-tool chiedi and nega and the rules that always ask still apply.

For the tools below, a session can set its own rule (permessiPerAttrezzo), over the mode:

Toolsscrivifile_editprovashelldocument_creategenerate_image

sempre
Always allowed, without asking.
chiedi
Ask each time.
nega
Never: the tool is refused in this session.
  1. Plan mode (modalitaOperativa: "piano") refuses every tool that changes or runs something until the plan is approved: the agent explores and asks.
  2. A per-tool nega wins over everything; a per-tool sempre skips the question unless one of the rules below applies.
  3. Reading or running a command on a file of the secret class (keys, credentials, keychains) always asks, even with sempre.
  4. library_context_policy_update always asks, by construction.
  5. The check on data leaving: when a call would join private data, untrusted content and a way to send it out, it asks, even with sempre (not in Full access).
  6. A write by scrivi or file_edit to a control file (below) always asks, in every mode.
  7. A trusted pre_tool_call hook can refuse a tool that changes something (Hooks).

These files and folders steer TALOS itself — hooks, MCP servers, plugins, trust records, provider settings, instructions, skills, memory. A write to one of them asks you first, whatever the mode:

Files, anywhere
.harness-ui-hooks.json.harness-ui-mcp.json.provider-runtime.jsonCLAUDE.mdAGENTS.md
Folders, anywhere
.harness-ui-plugins/.hooks-trust/.mcp-trust/.plugin-trust/.claude/.memory-store/.talos/
At the root of the project
skills/

Type to search the guides.