pub enum Permission {
ReadOnly,
Plan,
Edit,
Auto,
Bypass,
}Expand description
Permission posture for a run, mapped onto each agent’s own vocabulary.
§What these do and do not guarantee
These postures constrain each CLI’s built-in tools: its shell, its file writes, its sandbox. They do not constrain MCP servers, plugins or custom tools the agent is configured with. An MCP tool that files an issue, writes to a database or calls a deployment API is a separate tool category in all three CLIs and can still act during a nominally restricted run.
If a run must not cause remote side effects, the containment has to come from the agent’s own configuration (which MCP servers are enabled at all), not from this enum. What is selected here is enforced by the CLI, and what the CLI does not model cannot be enforced from out here.
Variants§
ReadOnly
No writes to the local filesystem, and no shell where the CLI can gate one.
The strongest posture this crate can express, and still not a guarantee of “no side effects”: see the type-level note about MCP tools. Codex enforces it with a read-only sandbox, which blocks writes but still permits command execution.
Plan
Ask the agent to plan rather than act.
Claude and Copilot have a real plan mode. Codex has none, so this maps to its read-only sandbox: writes are blocked, but the model is not instructed to withhold execution the way a true plan mode would.
Edit
Allow file edits, while still gating shell commands where the CLI can.
Auto
Allow the agent’s own default automation.
Bypass
Skip every permission check. For sandboxes.
Trait Implementations§
Source§impl Clone for Permission
impl Clone for Permission
Source§fn clone(&self) -> Permission
fn clone(&self) -> Permission
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more