Configure auto mode changedauto-mode-config
Nearest release: v2.1.284, published 2 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 28 Sep 2026 19:33 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 23:37 UTC.
Upstream edited
Recorded here
Lines+9added
Lines−9removed
From line
47
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits19to this page, all time
The whole hunk
from line 47, old and new numbered
/
from line 47
4747
4848Pick the mechanism that matches how firm the boundary needs to be:
4949
50| Boundary | Mechanism | Behavior in auto mode |
51| :-------------------------------- | :--------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
52| Prompt before the action | `permissions.ask` | Always prompts for a command that matches a content-scoped rule like the recipe above. The classifier cannot auto-approve a matching action. |
53| Never run the action | `permissions.deny` | Blocks before the classifier is consulted. Neither the classifier nor user intent can override it. |
50| Boundary | Mechanism | Behavior in auto mode |
51| :- | :- | :- |
52| Prompt before the action | `permissions.ask` | Always prompts for a command that matches a content-scoped rule like the recipe above. The classifier cannot auto-approve a matching action. |
53| Never run the action | `permissions.deny` | Blocks before the classifier is consulted. Neither the classifier nor user intent can override it. |
5454| One-off boundary for this session | State it in conversation, like "don't push until I review" | The classifier blocks matching actions, but the boundary can be lost if [context compaction](/docs/en/costs#reduce-token-usage) removes the message that stated it. Use an ask or deny rule for a durable guarantee. |
5555
5656## Where the classifier reads configuration
from line 59
5959
6060For rules that apply across projects, such as trusted infrastructure or organization-wide deny rules, use the `autoMode` settings block. The classifier reads `autoMode` from the following scopes:
6161
62| Scope | File | Use for |
63| :----------------------------- | :---------------------------------------------- | :--------------------------------------------------- |
64| One developer | `~/.claude/settings.json` | Personal trusted infrastructure |
65| Organization-wide | [Managed settings](/docs/en/server-managed-settings) | Trusted infrastructure distributed to all developers |
66| `--settings` flag or Agent SDK | Inline JSON | Per-invocation overrides for automation |
62| Scope | File | Use for |
63| :- | :- | :- |
64| One developer | `~/.claude/settings.json` | Personal trusted infrastructure |
65| Organization-wide | [Managed settings](/docs/en/server-managed-settings) | Trusted infrastructure distributed to all developers |
66| `--settings` flag or Agent SDK | Inline JSON | Per-invocation overrides for automation |
6767
6868The classifier doesn't read `autoMode` from project settings in `.claude/settings.json` or `.claude/settings.local.json`. Both files live in the repo directory, so a checked-in repo or a build step could otherwise inject its own allow rules. Move any `autoMode` block in `.claude/settings.local.json` to `~/.claude/settings.json`.
6969
No line in this hunk matches that.