Claude Code

Auto-mode policy reference

Availability, classifier configuration, trusted infrastructure, allow/deny rules, shell classification, denial reviews and cache effects.

Auto mode reduces routine approvals using a classifier after ordinary permissions. Explicit ask/deny rules apply first; remaining actions are checked against intent, infrastructure trust and hostile-content influence.

Put unconditional prohibitions in permissions.deny, the hard gate before classification, not only autoMode.hard_deny.

#Availability

ConditionRequirement
Client versionRecent version; pin a minimum for rollout
Anthropic APINormally available, subject to account/model/policy
Cloud providers/apps gatewayCLAUDE_CODE_ENABLE_AUTO_MODE=1 adds it to mode cycling
Passion8/LLM gatewayCompatible paths may not need the switch; verify actual upstream
Default modeUser/managed defaultMode:auto; project default ignored
DisableManaged disableAutoMode:disable

Enable for cloud-provider paths:

~/.claude/settings.json
{
  "env": {
    "CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
  },
  "permissions": {
    "defaultMode": "auto"
  }
}

#Classifier configuration sources

SourceAppropriate content
CLAUDE.mdProject conventions, force-push prohibitions, release and production rules
User settingsTrusted services, buckets and default mode
Local project settingsPersonal project exceptions
Managed settingsOrganizational infrastructure and sensitive targets
--settings / SDK inlineOne-off automation boundaries

Shared project settings do not supply autoMode, preventing repositories from relaxing their own rules.

#Trusted infrastructure

autoMode.environment defines trusted internal infrastructure and sensitive targets.

{
  "autoMode": {
    "environment": [
      "$defaults",
      "Organization: acme-corp. Primary use: software development and internal automation",
      "Source control: github.example.com/acme-corp and all repos under it",
      "Cloud provider(s): AWS and GCP",
      "Trusted cloud buckets: s3://acme-build-artifacts, gs://acme-ml-datasets",
      "Trusted internal domains: *.corp.example.com, api.internal.example.com",
      "Key internal services: Jenkins at ci.example.com, Artifactory at artifacts.example.com",
      "Internal package registry: npm.corp.example.com and pypi.corp.example.com",
      "Sensitive remote targets: prod Kubernetes namespaces, production databases, prod Redis",
      "Protected IaC scopes: terraform/prod and pulumi production stacks"
    ]
  }
}

Use natural language, not regex, as though explaining infrastructure to a new colleague.

#allow、soft_deny、hard_deny

FieldPurposeExample
allowExceptions to soft blocksStaging or scratch-bucket writes
soft_denyRequires explicit intentDependencies, internet, tickets or staging changes
hard_denyUnconditional classifier blockSource export or production changes
permissions.denyPreclassifier hard gateSecret reads, deletion or production database writes

Include "$defaults" in each array to preserve built-in rules:

{
  "autoMode": {
    "allow": [
      "$defaults",
      "Writing to s3://acme-scratch/ is allowed. It is an ephemeral bucket with a 7-day lifecycle policy"
    ],
    "soft_deny": [
      "$defaults",
      "Do not run database migrations outside the migrations CLI, even against dev databases"
    ],
    "hard_deny": [
      "$defaults",
      "Never send repository contents to third-party code review APIs"
    ]
  }
}

Omitting defaults replaces that whole rule set. Do so only when deliberately owning the complete replacement.

#Classify every shell command

Narrow Bash allow rules may normally resolve before classification. To classify every Bash/PowerShell command, enable:

{
  "autoMode": {
    "classifyAllShell": true
  }
}

This adds classifier work and latency but suits strict enterprise policy. Low-risk personal projects may leave it off.

#Review effective configuration

CommandPurposeCache effect
auto-mode defaultsPrint built-in rulesLocal; no main-model call expected
auto-mode configPrint merged policyLocal; no prompt-cache change
auto-mode critiqueModel review of ambiguity/redundancy/false positivesModel request with provider TTL
Recently denied in /permissionsReview classifier/permission denialsRetried tools add context

Repeated denials often indicate missing environment descriptions. Clarify the target and inspect effective configuration.

#Enterprise rollout template

{
  "env": {
    "CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
  },
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Read(./**/*private_key*)",
      "Bash(curl * | sh)",
      "Bash(rm -rf *)",
      "Bash(git push *)",
      "mcp__prod_database__write_*"
    ],
    "disableBypassPermissionsMode": "disable"
  },
  "autoMode": {
    "environment": [
      "$defaults",
      "Source control: github.example.com/acme-corp and all repos under it",
      "Trusted internal domains: *.corp.example.com",
      "Sensitive remote targets: prod Kubernetes namespaces and production databases"
    ],
    "classifyAllShell": true,
    "soft_deny": [
      "$defaults",
      "Installing dependencies from public registries requires explicit user intent"
    ],
    "hard_deny": [
      "$defaults",
      "Never send source code, logs, or customer data to unapproved external services"
    ]
  }
}

#Cache effects

ActionEffect
Enter auto modeNot necessarily a miss; fewer pauses can grow history faster
Change environmentClassifier changes; main cache still depends on request content
CritiqueModel request may reuse nearby provider cache
classifyAllShellExtra classifications, distinct from main-response caching
Retry after denialExecuted calls/results extend context
Passion8Trust actual forwarded usage, not assumed subscription parity

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.