Skip to the page
Conch
DocsGitHub

Reference

Permission modes

How much your assistant may do without asking. Pick one per chat, and a default for new ones.

Change it from the composer, or with /mode. A provider that can't honour a mode doesn't offer it.

Ask first
Asks before editing files or running commands.
Auto
Safe actions go ahead; anything risky still asks.
Edit freelyMore room
Changes files in this folder without asking; anything more needs your OK.
Plan only
Reads and plans but doesn’t change anything.
Full trustAsks you to confirm
Can do anything without asking — and a web page or file it reads could trick it. Only in a folder you can afford to lose.

In every mode but Full trust, anything that sends, spends or deletes asks first once the chat has read something from outside; Always allow on that question lets it through for the rest of the chat. A command that wants out of the sealed box (to clone a repository or install something) asks too, with Always allow, except in Full trust. Whatever the mode, anything significant in the browser asks.