Auto-mode policy reference
Availability, classifier configuration, trusted infrastructure, allow/deny rules, shell classification, denial reviews and cache effects.
Auto mode reduces routine approvals using a classifier after ordinary permissions. Explicit ask/deny rules apply first; remaining actions are checked against intent, infrastructure trust and hostile-content influence.
Put unconditional prohibitions in permissions.deny, the hard gate before classification, not only autoMode.hard_deny.
#Availability
| Condition | Requirement |
|---|---|
| Client version | Recent version; pin a minimum for rollout |
| Anthropic API | Normally available, subject to account/model/policy |
| Cloud providers/apps gateway | CLAUDE_CODE_ENABLE_AUTO_MODE=1 adds it to mode cycling |
| Passion8/LLM gateway | Compatible paths may not need the switch; verify actual upstream |
| Default mode | User/managed defaultMode:auto; project default ignored |
| Disable | Managed disableAutoMode:disable |
Enable for cloud-provider paths:
{
"env": {
"CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
},
"permissions": {
"defaultMode": "auto"
}
}#Classifier configuration sources
| Source | Appropriate content |
|---|---|
| CLAUDE.md | Project conventions, force-push prohibitions, release and production rules |
| User settings | Trusted services, buckets and default mode |
| Local project settings | Personal project exceptions |
| Managed settings | Organizational infrastructure and sensitive targets |
| --settings / SDK inline | One-off automation boundaries |
Shared project settings do not supply autoMode, preventing repositories from relaxing their own rules.
#Trusted infrastructure
autoMode.environment defines trusted internal infrastructure and sensitive targets.
{
"autoMode": {
"environment": [
"$defaults",
"Organization: acme-corp. Primary use: software development and internal automation",
"Source control: github.example.com/acme-corp and all repos under it",
"Cloud provider(s): AWS and GCP",
"Trusted cloud buckets: s3://acme-build-artifacts, gs://acme-ml-datasets",
"Trusted internal domains: *.corp.example.com, api.internal.example.com",
"Key internal services: Jenkins at ci.example.com, Artifactory at artifacts.example.com",
"Internal package registry: npm.corp.example.com and pypi.corp.example.com",
"Sensitive remote targets: prod Kubernetes namespaces, production databases, prod Redis",
"Protected IaC scopes: terraform/prod and pulumi production stacks"
]
}
}Use natural language, not regex, as though explaining infrastructure to a new colleague.
#allow、soft_deny、hard_deny
| Field | Purpose | Example |
|---|---|---|
| allow | Exceptions to soft blocks | Staging or scratch-bucket writes |
| soft_deny | Requires explicit intent | Dependencies, internet, tickets or staging changes |
| hard_deny | Unconditional classifier block | Source export or production changes |
| permissions.deny | Preclassifier hard gate | Secret reads, deletion or production database writes |
Include "$defaults" in each array to preserve built-in rules:
{
"autoMode": {
"allow": [
"$defaults",
"Writing to s3://acme-scratch/ is allowed. It is an ephemeral bucket with a 7-day lifecycle policy"
],
"soft_deny": [
"$defaults",
"Do not run database migrations outside the migrations CLI, even against dev databases"
],
"hard_deny": [
"$defaults",
"Never send repository contents to third-party code review APIs"
]
}
}Omitting defaults replaces that whole rule set. Do so only when deliberately owning the complete replacement.
#Classify every shell command
Narrow Bash allow rules may normally resolve before classification. To classify every Bash/PowerShell command, enable:
{
"autoMode": {
"classifyAllShell": true
}
}This adds classifier work and latency but suits strict enterprise policy. Low-risk personal projects may leave it off.
#Review effective configuration
| Command | Purpose | Cache effect |
|---|---|---|
| auto-mode defaults | Print built-in rules | Local; no main-model call expected |
| auto-mode config | Print merged policy | Local; no prompt-cache change |
| auto-mode critique | Model review of ambiguity/redundancy/false positives | Model request with provider TTL |
| Recently denied in /permissions | Review classifier/permission denials | Retried tools add context |
Repeated denials often indicate missing environment descriptions. Clarify the target and inspect effective configuration.
#Enterprise rollout template
{
"env": {
"CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
},
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)",
"Read(./**/*private_key*)",
"Bash(curl * | sh)",
"Bash(rm -rf *)",
"Bash(git push *)",
"mcp__prod_database__write_*"
],
"disableBypassPermissionsMode": "disable"
},
"autoMode": {
"environment": [
"$defaults",
"Source control: github.example.com/acme-corp and all repos under it",
"Trusted internal domains: *.corp.example.com",
"Sensitive remote targets: prod Kubernetes namespaces and production databases"
],
"classifyAllShell": true,
"soft_deny": [
"$defaults",
"Installing dependencies from public registries requires explicit user intent"
],
"hard_deny": [
"$defaults",
"Never send source code, logs, or customer data to unapproved external services"
]
}
}#Cache effects
| Action | Effect |
|---|---|
| Enter auto mode | Not necessarily a miss; fewer pauses can grow history faster |
| Change environment | Classifier changes; main cache still depends on request content |
| Critique | Model request may reuse nearby provider cache |
| classifyAllShell | Extra classifications, distinct from main-response caching |
| Retry after denial | Executed calls/results extend context |
| Passion8 | Trust actual forwarded usage, not assumed subscription parity |
#Official references
#Related pages
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

