Understand agent access and approvals
Choose how an agent handles permissions and respond to approval requests deliberately.
Last updated 16 September 2026
Choose how an agent handles permissions and respond to approval requests deliberately.
Before you start
Check the access control in the composer before sending. Access describes permission behavior; Plan describes the kind of work you are asking for. They are separate controls.
The selected provider’s access menu is separate from the model and Plan controls. Claude uses different labels for its supervised and automatic-edit modes.
Step by step
Open the access menu in the composer and read the available choices. Labels differ by provider, so confirm the selected provider first.
For Codex, Ask for approval requests supervision for operations; Approve for me allows routine trusted actions while asking about actions detected as potentially unsafe. Full access permits unrestricted file and internet access without those prompts.
For Claude, the corresponding labels are Supervised, Auto-accept edits, and Full access. Auto-accept edits permits file edits automatically while other actions can still need a decision.
Choose the mode that matches the work and the supervision you want. A request to inspect code is still a task instruction; it is not the same as selecting a permission boundary.
When an approval card appears, read the actual operation and target. Approve only the requested action you intend to allow, or decline it and explain a suitable alternative.
If work cannot continue, inspect the reported error. Distinguish a denied permission from missing credentials, an unavailable tool, or an incorrect project before choosing the next step.
What to expect
The agent operates under the selected provider’s access behavior and your individual decisions. You remain responsible for reviewing the resulting changes.
Troubleshooting and useful details
Approving a plan permits implementation of an approach; approving an operation permits a specific action. Neither proves the result is correct. Full access does not supply missing credentials or guarantee every integration will run. Provider policies can still affect particular tools, so use the actual error as the starting point for recovery.
