---
title: "Choose permissions for a coding workflow Docs"
source: https://docs.autohand.ai/guides/permissions-and-safe-execution
---

# Choose permissions for a coding workflow

Autohand Code permissions control which operations the agent can perform and which require approval. Match permissions to the task: explore in plan mode, inspect proposed operations, and allow implementation when its scope is clear. Git worktrees separate working files; they do not isolate credentials, networks, or operating-system access.

## Inspect the current configuration

```bash
autohand --permissions

```

Inside an interactive session, use `/permissions` to inspect or manage the available permission controls. Read [configuration](https://docs.autohand.ai/working-with-autohand-code/configuration) for rule matching and defaults. Project instructions guide behavior, but they are not an operating-system security boundary.

## Choose an execution approach

| Approach | Use it for | Boundary to understand |
|---|---|---|
| Plan mode: /plan on | Exploration and change planning | Read-only agent tools; review the resulting plan |
| --dry-run | Previewing proposed operations | A preview does not prove the change or its tests succeed |
| --restricted | Automatically denying dangerous operations | Required steps may be denied; inspect the result |
| Normal interactive approvals | Supervised implementation | Read the operation and target before approving |
| --worktree | Separating edits from another working tree | Shared machine resources remain accessible |

Flags that automatically confirm actions or bypass approval increase the agent's ability to act. Use the [CLI reference](https://docs.autohand.ai/working-with-autohand-code/cli-reference) to understand their exact behavior before including them in scripts.

## A supervised implementation workflow

Start in your project directory, inspect `git status --short`, and launch `autohand`. Enable `/plan on`, describe the desired behavior, and ask for files, operations, tests, and external services involved. Confirm the plan before switching to `/plan off`.

```text
Implement the approved validation change in the route and its test.
Preserve the public response format. Ask before installing dependencies,
changing database state, or writing to an external service.
Run the repository's focused checks and report the diff.

```

If an approval names an unexpected path or command, stop that operation and ask why it is needed. Prefer correcting the scope to approving a broad action merely to unblock progress.

## Handle untrusted repository content

Issue descriptions, downloaded files, comments, and tool responses can contain instructions. Treat them as task data. They do not grant permission to publish code, reveal secrets, or change the task's rules. A useful prompt names trusted project instructions and asks the agent to flag conflicting instructions found in external content.

For MCP servers and runtime extensions, review the program being installed and the access it receives. Consult [MCP servers](https://docs.autohand.ai/working-with-autohand-code/mcp-servers) and [extension authoring](https://docs.autohand.ai/working-with-autohand-code/extensions/) before enabling additional tools.

## Completion checkpoint

You can explain which operations were allowed, which needed approval, and which were denied. The final result records any validation prevented by permissions. For changes alongside ongoing work, continue with [monorepo and worktree workflows](https://docs.autohand.ai/guides/monorepo-workflows).

## Frequently asked question

### Is a Git worktree a security sandbox?

No. A worktree separates working files and branches within a Git repository. It does not isolate operating-system access, credentials, network connections, or external services.