What Claude Code plan mode, auto mode, and bypass mode still allow

Plan mode blocks edits until approval, auto mode classifies risky actions, and bypass still prompts or denies six action classes.

Claude Code's plan mode reads files and explores with read-only shell commands; when auto mode is available, its classifier can approve additional shell commands. In ordinary sessions, source edits stay blocked until you approve the plan. auto removes routine prompts but checks risky actions with a background classifier, while bypassPermissions removes most prompts but still leaves six action classes outside automatic approval.

Claude Code permission modes: key facts

  • With Claude Code v2.1.283 or later, auto is the built-in starting mode for interactive terminal and VS Code sessions.
  • In ordinary plan sessions, edits stay blocked until plan approval. With auto mode available, useAutoModeDuringPlan is on by default and sends eligible shell commands to the classifier.
  • Auto mode pauses after three consecutive or 20 total classifier blocks, then resumes prompting.
  • GitHub issue 99694 reports 227 refusals across 4,302 transcript files dated from 2026-08-06 to 2026-10-05; 62 refusals followed an identical allowed call in the same session.
  • bypassPermissions still prompts or denies six action classes, including explicit ask rules and critical-path removals.
  • In auto and bypass modes, terminal prompts for critical-path removals use a two-minute countdown in Claude Code v2.1.281 or later.

Claude Code permission mode baselines

Claude Code supports six permission modes selectable with --permission-mode:

Mode

Config value

What runs without a routine prompt

Manual

default

Reads and built-in read-only commands in working directories

Edit automatically

acceptEdits

Reads, edits, and common filesystem commands in working directories

Plan

plan

Reads, read-only commands, and classifier-approved commands when auto mode is available

Auto

auto

Routine tool calls, with background safety checks

Don't ask

dontAsk

Reads and pre-approved tools; anything that would prompt is denied

Bypass permissions

bypassPermissions

Most tool calls, including protected-path writes; six categories still prompt or deny

default is the config value shown as Manual. Deny rules still block in every mode, including bypassPermissions. A project-level permissions.defaultMode value of auto or bypassPermissions does not take effect; an explicit launch flag or an allowed user or managed setting is required.

Claude Code plan mode during exploration

Start it with claude --permission-mode plan or the /plan prompt prefix. Claude Code reads files and runs built-in read-only shell commands to explore, then proposes changes without editing source files.

When auto mode is available and useAutoModeDuringPlan is enabled, which the documentation says is the default, the classifier reviews shell commands outside the built-in read-only set. Approved commands run; rejected commands are blocked. Critical-path removals are outside this flow and retain their separate safeguard.

If auto mode is unavailable or useAutoModeDuringPlan is false, commands outside the built-in read-only set prompt for approval. The important exception is an interactive terminal session launched with bypass permissions available: Claude Code does not enforce plan mode's edit and shell blocks there. Plan mode remains blocked in non-interactive runs, Agent SDK sessions, and the VS Code chat panel.

Claude Code auto mode and classifier decisions

Auto mode runs without routine permission prompts. A separate classifier reviews actions such as shell commands and network requests, blocking actions that exceed the request, target unrecognized infrastructure, or appear driven by hostile content Claude read. Explicit permissions.ask rules and permissions.deny rules are evaluated before the classifier.

If the classifier blocks an action three times in a row or 20 times total in a session, auto mode pauses and Claude Code resumes prompting. Approving the prompted action resumes auto mode.

By default, narrow Bash and PowerShell allow rules can run before the classifier. Set autoMode.classifyAllShell: true to send every Bash and PowerShell command through the classifier while auto mode is active; this adds latency and does not replace the critical-path removal safeguard.

GitHub issue 99694: classifier variability

GitHub issue 99694, opened on 2026-10-05, reports differing verdicts for identical commands. The reporter counted local Claude transcript files while using Claude Code 2.1.286, Claude Fable 5.1, Windows 11, Git Bash, and the VS Code extension.

The reported measurements cover 4,302 transcript files from 2026-08-06 through 2026-10-05:

Measure

Reported result

Classifier refusals

227 on 39 days across 6 projects

Refusals where the same session had already run the identical call with permission

62 (27%)

Identical retry allowed within 60 seconds with no operator message between attempts

18; fastest was 4 seconds

Refusals with no named rule

83 (37%)

These numbers describe the issue reporter's transcript set, not a general error rate for every Claude Code installation. They show why an auto-mode decision should be treated as a classifier result, not as a deterministic allowlist.

Claude Code bypassPermissions mode: six exceptions

Start bypass with claude --permission-mode bypassPermissions or --dangerously-skip-permissions. It skips routine prompts and allows protected-path writes, but these six categories remain outside automatic approval:

  1. Tools matched by an explicit permissions.ask rule.
  2. Connector tools that an organization sets to ask.
  3. User-interaction tools: AskUserQuestion and MCP tools marked requiresUserInteraction.
  4. rm and rmdir removals targeting a critical path, such as the filesystem root, a home directory, a working directory, or a parent of one.
  5. Cross-session messaging safeguards.
  6. Reads outside working directories when permissions.blockReadsOutsideWorkingDirectories is enabled. This rule requires Claude Code v2.1.257 or later.

In auto and bypass modes, a terminal prompt for a critical-path removal shows a two-minute countdown. If it expires, Claude Code denies the command; after three expired prompts in one session, later critical-path removals are denied immediately. This handling requires Claude Code v2.1.281 or later. In non-interactive auto-mode runs, the critical-path removal is denied immediately because no terminal prompt is available. Explicit permissions.deny rules also block immediately in every mode.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.