LatentCodeUsing LatentCode
Permissions
Decide what the agent may do on its own, what it has to ask about, and what it may never do.
How it works
Before each action (reading a file, editing one, running a command, fetching a URL) LatentCode checks your permission rules. Each rule gives one of three answers:
| Action | Result |
|---|---|
| allow | Runs without asking. |
| ask | Stops and asks you first. |
| deny | Blocked. The agent is told it isn't allowed. |
Approving a request
When the agent needs approval, the prompt is replaced by a request like this:
Bash command
git push origin feature/orders
Do you want to proceed?
1. Yes, allow once
2. Yes, don't ask again this session for commands starting the same way
3. No, tell latentcode what to do (esc)| Choice | Effect |
|---|---|
| Yes, allow once | Runs this one action. |
| Yes, don't ask again this session | Also approves matching requests for the rest of this session, including its subagents. The approval is kept in memory only and never written to your config. A rule set to deny still wins. |
| No, tell latentcode what to do | Rejects the action and stops the turn so you can type what to do instead. Other requests waiting in the same session are rejected too. |
Press 1–3 to choose, or move with the arrow keys and press enter. esc rejects. ctrl+f shows the request full screen, which helps with long commands and diffs. What "matching" covers depends on the request: the same file, the same pattern, commands starting the same way (for example every git push …), or the same URL origin.
Defaults
Out of the box, the agent can read and change your project freely but asks about anything that reaches outside it, touches secrets or is hard to undo:
| Permission | Default |
|---|---|
| read | Allowed, except .env files (.env.example is allowed) and credentials such as ~/.ssh, ~/.aws, *.pem, *.key, .npmrc, .netrc: ask. |
| edit | Allowed, except: ask for .env files, .latentcode/, .github/workflows/, package.json and lock files, Dockerfile, docker-compose*.yml, *.tf, *.tfvars and credential files. |
| bash | Depends on the agent (below). Always allowed: pwd, ls, git status, git diff, git log, git show, rg, grep, which, file, stat, wc. |
| network | Ask. Commands that use the network: curl, wget, ssh, gh, aws, kubectl, git clone/fetch/pull/push, package installs, and so on. |
| dangerous_command | Ask. sudo, rm -r, git reset --hard, git push, git rebase, git commit --amend, deleting branches, kubectl delete, terraform destroy, docker … prune. |
| repository_metadata | Ask. Git commands that change the repository: git add, commit, checkout, merge, stash, tag, and similar. |
| external_directory | Ask, for any file or command outside the project directory. |
| webfetch, websearch | Ask. |
| doom_loop | Ask, when the agent calls the same tool with the same input three times in a row. |
| everything else | Allowed: glob, grep, task, todowrite, skill, MCP tools. |
Per agent
| Agent | Differences from the defaults |
|---|---|
| build | All shell commands are allowed. Network, dangerous and repository-changing commands still ask. |
| auto | Also allows network commands, web fetch and search, repository-changing git commands and files outside the project. Dangerous commands and sensitive files still ask. |
| plan | Read-only. File edits, network, dangerous and repository-changing commands are denied; only the always-allowed shell commands run. You can't loosen this with config. |
Switch agents with tab. See Agents.
Configure permissions
Add a permission block to latentcode.json, globally or in a project:
{
"permission": {
"edit": "ask",
"webfetch": "allow",
"bash": {
"*": "ask",
"npm test*": "allow",
"git push*": "ask",
"rm *": "deny"
},
"read": {
"*": "allow",
"secrets/*": "deny"
}
}
}- A permission takes one action (
"edit": "ask") or an object of patterns. - Patterns are matched against the command for
bash, and against the path forread,editandexternal_directory.*matches anything,?one character. A pattern ending in" *"also matches the command with no arguments, so"git status *"matchesgit status. - The last matching rule wins. Put
"*"first and the exceptions after it. A request that matches nothing asks. ~and$HOMEat the start of a pattern expand to your home directory."permission": "ask"as a single string applies to everything.
Permission keys
| Key | Covers |
|---|---|
| read | Reading files and listing directories. |
| edit | Every tool that changes files: edit, write and patch. |
| bash | Shell commands, matched against the command text. |
| network | Shell commands that reach the network. |
| dangerous_command | Destructive or privileged shell commands. |
| repository_metadata | Git commands that change the repository. |
| external_directory | Anything outside the project directory. |
| glob, grep | File and content search. |
| task | Starting subagents, matched against the subagent's name. |
| skill | Loading a skill, matched against its name. |
| webfetch, websearch | Fetching URLs and searching the web. |
| todowrite | The agent's task list. |
| question | The agent asking you multiple-choice questions. |
| doom_loop | Repeating the same tool call. |
| <server>_<tool> | An MCP tool, for example github_create_issue. Wildcards work: "github_*": "ask". |
Command sandbox
On macOS and Linux, shell commands also run inside an operating-system sandbox. A command can read anywhere but can only write inside the project (plus any directories you approved for it), and can only use the network if it was recognized as a network command. This holds even for commands you allowed.
Linux needs bwrap (bubblewrap) installed. Set LATENTCODE_OS_SANDBOX=false to turn the sandbox off.
Without the TUI
latentcode run has nobody to ask, so it rejects every request that would ask, and denies questions and plan mode. Allow what an automated job needs in config, or pass --auto (same as --dangerously-skip-permissions) to approve every request that isn't denied. Only use it in an environment you'd be happy for the agent to change. --auto has no effect in the TUI.
You can also set rules for one process with the LATENTCODE_PERMISSION environment variable, as JSON:
LATENTCODE_PERMISSION='{"bash":{"*":"allow"},"webfetch":"deny"}' latentcode run "run the tests and fix failures"FAQ
Why does it ask before editing package.json?
Dependency and CI files are on the default ask list because changes to them run code on other machines. Allow them with "edit": { "*package.json": "allow" }.
Why does a file like app.environment.ts ask to be read?
The default *.env* pattern matches any path containing .env. Add a more specific rule after it, such as "read": { "*.environment.ts": "allow" }.
Can I make "don't ask again" permanent?
Not from the prompt: session approvals end with the session. Add the rule to your config instead.
The agent says a command was denied, but I allowed it.
Check for a later, more specific rule and for agent-level rules: the last match wins, and agent rules come after the top-level ones. In Plan, edits and non-read-only commands are always denied. latentcode agent list prints the resolved rules for every agent.