Modes
Change mid-session:
default
The starting mode. Reading, searching, and globbing happen freely; every write
and every command prompts:
accept-edits
File edits stop prompting; commands still ask. This is the mode to switch to
once you’ve seen a plan you agree with and just want it executed.
plan
Read-only. 9p investigates and proposes but cannot touch the working tree. Use
it for “what would you change and why” — and note that plan mode also tells the
router to treat the turn as complex, so you get a stronger model.
bypass
No prompts at all. Appropriate for a scratch repo or a container, not for
anything you care about.
Guardrails that always apply
These hold in every mode, includingbypass:
- Read before write.
writeandeditrefuse to touch a file the agent hasn’t read in this session, so it can’t clobber content it never saw. - Sub-agent spawning is gated. Starting a sub-agent is treated as an exec-class action, because it’s an agent that runs unattended.
- Sub-agent depth is capped at 2. Sub-agents cannot recurse indefinitely.
- Explore sub-agents get read-only tools. They physically cannot edit.
Practical advice
Start in plan mode for anything large
Start in plan mode for anything large
/mode plan, ask for the approach, read it, then switch to accept-edits
and let it run. Catching a wrong plan costs one turn; catching it after 30
file edits costs a lot more.Keep bash gated
Keep bash gated
accept-edits is a good default for real work precisely because edits are
reviewable in git while commands are not.Use git as the real safety net
Use git as the real safety net
Commit before a big task. The permission prompts reduce surprises; a clean
working tree is what actually lets you undo one.

