# Claude Code Auto-mode policy reference

> Claude Code: Availability, classifier configuration, trusted infrastructure, allow/deny rules, shell classification, denial reviews and cache effects.

URL: https://docs.passion8.cc/en/docs/claude-code/auto-mode-policy
Language: en
Publisher: Passion8

Auto mode reduces routine approvals using a classifier after ordinary permissions. Explicit ask/deny rules apply first; remaining actions are checked against intent, infrastructure trust and hostile-content influence.




Put unconditional prohibitions in permissions.deny, the hard gate before classification, not only autoMode.hard_deny.




## Availability

| Condition | Requirement |
| --- | --- |
| Client version | Recent version; pin a minimum for rollout |
| Anthropic API | Normally available, subject to account/model/policy |
| Cloud providers/apps gateway | CLAUDE_CODE_ENABLE_AUTO_MODE=1 adds it to mode cycling |
| Passion8/LLM gateway | Compatible paths may not need the switch; verify actual upstream |
| Default mode | User/managed defaultMode:auto; project default ignored |
| Disable | Managed disableAutoMode:disable |

Enable for cloud-provider paths:

```json title="~/.claude/settings.json"
{
  "env": {
    "CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
  },
  "permissions": {
    "defaultMode": "auto"
  }
}
```

## Classifier configuration sources

| Source | Appropriate content |
| --- | --- |
| CLAUDE.md | Project conventions, force-push prohibitions, release and production rules |
| User settings | Trusted services, buckets and default mode |
| Local project settings | Personal project exceptions |
| Managed settings | Organizational infrastructure and sensitive targets |
| --settings / SDK inline | One-off automation boundaries |

Shared project settings do not supply autoMode, preventing repositories from relaxing their own rules.

## Trusted infrastructure

autoMode.environment defines trusted internal infrastructure and sensitive targets.

```json
{
  "autoMode": {
    "environment": [
      "$defaults",
      "Organization: acme-corp. Primary use: software development and internal automation",
      "Source control: github.example.com/acme-corp and all repos under it",
      "Cloud provider(s): AWS and GCP",
      "Trusted cloud buckets: s3://acme-build-artifacts, gs://acme-ml-datasets",
      "Trusted internal domains: *.corp.example.com, api.internal.example.com",
      "Key internal services: Jenkins at ci.example.com, Artifactory at artifacts.example.com",
      "Internal package registry: npm.corp.example.com and pypi.corp.example.com",
      "Sensitive remote targets: prod Kubernetes namespaces, production databases, prod Redis",
      "Protected IaC scopes: terraform/prod and pulumi production stacks"
    ]
  }
}
```

Use natural language, not regex, as though explaining infrastructure to a new colleague.

## allow、soft_deny、hard_deny

| Field | Purpose | Example |
| --- | --- | --- |
| allow | Exceptions to soft blocks | Staging or scratch-bucket writes |
| soft_deny | Requires explicit intent | Dependencies, internet, tickets or staging changes |
| hard_deny | Unconditional classifier block | Source export or production changes |
| permissions.deny | Preclassifier hard gate | Secret reads, deletion or production database writes |

Include "$defaults" in each array to preserve built-in rules:

```json
{
  "autoMode": {
    "allow": [
      "$defaults",
      "Writing to s3://acme-scratch/ is allowed. It is an ephemeral bucket with a 7-day lifecycle policy"
    ],
    "soft_deny": [
      "$defaults",
      "Do not run database migrations outside the migrations CLI, even against dev databases"
    ],
    "hard_deny": [
      "$defaults",
      "Never send repository contents to third-party code review APIs"
    ]
  }
}
```

Omitting defaults replaces that whole rule set. Do so only when deliberately owning the complete replacement.

## Classify every shell command

Narrow Bash allow rules may normally resolve before classification. To classify every Bash/PowerShell command, enable:

```json
{
  "autoMode": {
    "classifyAllShell": true
  }
}
```

This adds classifier work and latency but suits strict enterprise policy. Low-risk personal projects may leave it off.

## Review effective configuration

| Command | Purpose | Cache effect |
| --- | --- | --- |
| auto-mode defaults | Print built-in rules | Local; no main-model call expected |
| auto-mode config | Print merged policy | Local; no prompt-cache change |
| auto-mode critique | Model review of ambiguity/redundancy/false positives | Model request with provider TTL |
| Recently denied in /permissions | Review classifier/permission denials | Retried tools add context |

Repeated denials often indicate missing environment descriptions. Clarify the target and inspect effective configuration.

## Enterprise rollout template

```json
{
  "env": {
    "CLAUDE_CODE_ENABLE_AUTO_MODE": "1"
  },
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Read(./**/*private_key*)",
      "Bash(curl * | sh)",
      "Bash(rm -rf *)",
      "Bash(git push *)",
      "mcp__prod_database__write_*"
    ],
    "disableBypassPermissionsMode": "disable"
  },
  "autoMode": {
    "environment": [
      "$defaults",
      "Source control: github.example.com/acme-corp and all repos under it",
      "Trusted internal domains: *.corp.example.com",
      "Sensitive remote targets: prod Kubernetes namespaces and production databases"
    ],
    "classifyAllShell": true,
    "soft_deny": [
      "$defaults",
      "Installing dependencies from public registries requires explicit user intent"
    ],
    "hard_deny": [
      "$defaults",
      "Never send source code, logs, or customer data to unapproved external services"
    ]
  }
}
```

## Cache effects

| Action | Effect |
| --- | --- |
| Enter auto mode | Not necessarily a miss; fewer pauses can grow history faster |
| Change environment | Classifier changes; main cache still depends on request content |
| Critique | Model request may reuse nearby provider cache |
| classifyAllShell | Extra classifications, distinct from main-response caching |
| Retry after denial | Executed calls/results extend context |
| Passion8 | Trust actual forwarded usage, not assumed subscription parity |

## Official references

- [Configure auto mode](https://code.claude.com/docs/en/auto-mode-config.md)
- [Permission modes](https://code.claude.com/docs/en/permission-modes.md)
- [Settings](https://code.claude.com/docs/en/settings.md)
- [Environment variables](https://code.claude.com/docs/en/env-vars.md)
- [Permissions](https://code.claude.com/docs/en/permissions.md)
- [Server-managed settings](https://code.claude.com/docs/en/server-managed-settings.md)

## Related pages



- [Permissions and modes](https://docs.passion8.cc/en/docs/claude-code/permissions): Modes and allow/ask/deny rules.
- [Enterprise controls](https://docs.passion8.cc/en/docs/claude-code/enterprise-controls): Managed settings, MCP, auto mode, analytics and compliance.
- [Enterprise rollout](https://docs.passion8.cc/en/docs/claude-code/enterprise-rollout): Integrate auto mode into a 30/60/90-day rollout.

