LatentCodeUsing LatentCode

Permissions

Decide what the agent may do on its own, what it has to ask about, and what it may never do.

How it works

Before each action (reading a file, editing one, running a command, fetching a URL) LatentCode checks your permission rules. Each rule gives one of three answers:

ActionResult
allowRuns without asking.
askStops and asks you first.
denyBlocked. The agent is told it isn't allowed.

Approving a request

When the agent needs approval, the prompt is replaced by a request like this:

Bash command
git push origin feature/orders

Do you want to proceed?
  1. Yes, allow once
  2. Yes, don't ask again this session for commands starting the same way
  3. No, tell latentcode what to do  (esc)
ChoiceEffect
Yes, allow onceRuns this one action.
Yes, don't ask again this sessionAlso approves matching requests for the rest of this session, including its subagents. The approval is kept in memory only and never written to your config. A rule set to deny still wins.
No, tell latentcode what to doRejects the action and stops the turn so you can type what to do instead. Other requests waiting in the same session are rejected too.

Press 1–3 to choose, or move with the arrow keys and press enter. esc rejects. ctrl+f shows the request full screen, which helps with long commands and diffs. What "matching" covers depends on the request: the same file, the same pattern, commands starting the same way (for example every git push …), or the same URL origin.

Defaults

Out of the box, the agent can read and change your project freely but asks about anything that reaches outside it, touches secrets or is hard to undo:

PermissionDefault
readAllowed, except .env files (.env.example is allowed) and credentials such as ~/.ssh, ~/.aws, *.pem, *.key, .npmrc, .netrc: ask.
editAllowed, except: ask for .env files, .latentcode/, .github/workflows/, package.json and lock files, Dockerfile, docker-compose*.yml, *.tf, *.tfvars and credential files.
bashDepends on the agent (below). Always allowed: pwd, ls, git status, git diff, git log, git show, rg, grep, which, file, stat, wc.
networkAsk. Commands that use the network: curl, wget, ssh, gh, aws, kubectl, git clone/fetch/pull/push, package installs, and so on.
dangerous_commandAsk. sudo, rm -r, git reset --hard, git push, git rebase, git commit --amend, deleting branches, kubectl delete, terraform destroy, docker … prune.
repository_metadataAsk. Git commands that change the repository: git add, commit, checkout, merge, stash, tag, and similar.
external_directoryAsk, for any file or command outside the project directory.
webfetch, websearchAsk.
doom_loopAsk, when the agent calls the same tool with the same input three times in a row.
everything elseAllowed: glob, grep, task, todowrite, skill, MCP tools.

Per agent

AgentDifferences from the defaults
buildAll shell commands are allowed. Network, dangerous and repository-changing commands still ask.
autoAlso allows network commands, web fetch and search, repository-changing git commands and files outside the project. Dangerous commands and sensitive files still ask.
planRead-only. File edits, network, dangerous and repository-changing commands are denied; only the always-allowed shell commands run. You can't loosen this with config.

Switch agents with tab. See Agents.

Configure permissions

Add a permission block to latentcode.json, globally or in a project:

latentcode.json
{
  "permission": {
    "edit": "ask",
    "webfetch": "allow",
    "bash": {
      "*": "ask",
      "npm test*": "allow",
      "git push*": "ask",
      "rm *": "deny"
    },
    "read": {
      "*": "allow",
      "secrets/*": "deny"
    }
  }
}
  • A permission takes one action ("edit": "ask") or an object of patterns.
  • Patterns are matched against the command for bash, and against the path for read, edit and external_directory. * matches anything, ? one character. A pattern ending in " *" also matches the command with no arguments, so "git status *" matches git status.
  • The last matching rule wins. Put "*" first and the exceptions after it. A request that matches nothing asks.
  • ~ and $HOME at the start of a pattern expand to your home directory.
  • "permission": "ask" as a single string applies to everything.

Permission keys

KeyCovers
readReading files and listing directories.
editEvery tool that changes files: edit, write and patch.
bashShell commands, matched against the command text.
networkShell commands that reach the network.
dangerous_commandDestructive or privileged shell commands.
repository_metadataGit commands that change the repository.
external_directoryAnything outside the project directory.
glob, grepFile and content search.
taskStarting subagents, matched against the subagent's name.
skillLoading a skill, matched against its name.
webfetch, websearchFetching URLs and searching the web.
todowriteThe agent's task list.
questionThe agent asking you multiple-choice questions.
doom_loopRepeating the same tool call.
<server>_<tool>An MCP tool, for example github_create_issue. Wildcards work: "github_*": "ask".

Per-agent rules

Rules under an agent apply only to it and override the top-level ones:

JSONC
{
  "agent": {
    "build": {
      "permission": { "bash": { "*": "ask", "npm run *": "allow" } }
    }
  }
}

Command sandbox

On macOS and Linux, shell commands also run inside an operating-system sandbox. A command can read anywhere but can only write inside the project (plus any directories you approved for it), and can only use the network if it was recognized as a network command. This holds even for commands you allowed.

Linux needs bwrap (bubblewrap) installed. Set LATENTCODE_OS_SANDBOX=false to turn the sandbox off.

Without the TUI

latentcode run has nobody to ask, so it rejects every request that would ask, and denies questions and plan mode. Allow what an automated job needs in config, or pass --auto (same as --dangerously-skip-permissions) to approve every request that isn't denied. Only use it in an environment you'd be happy for the agent to change. --auto has no effect in the TUI.

You can also set rules for one process with the LATENTCODE_PERMISSION environment variable, as JSON:

Bash
LATENTCODE_PERMISSION='{"bash":{"*":"allow"},"webfetch":"deny"}' latentcode run "run the tests and fix failures"

FAQ

Why does it ask before editing package.json?

Dependency and CI files are on the default ask list because changes to them run code on other machines. Allow them with "edit": { "*package.json": "allow" }.

Why does a file like app.environment.ts ask to be read?

The default *.env* pattern matches any path containing .env. Add a more specific rule after it, such as "read": { "*.environment.ts": "allow" }.

Can I make "don't ask again" permanent?

Not from the prompt: session approvals end with the session. Add the rule to your config instead.

The agent says a command was denied, but I allowed it.

Check for a later, more specific rule and for agent-level rules: the last match wins, and agent rules come after the top-level ones. In Plan, edits and non-read-only commands are always denied. latentcode agent list prints the resolved rules for every agent.