Claude Code's plan mode reads files and explores with read-only shell commands; when auto mode is available, its classifier can approve additional shell commands. In ordinary sessions, source edits stay blocked until you approve the plan. auto removes routine prompts but checks risky actions with a background classifier, while bypassPermissions removes most prompts but still leaves six action classes outside automatic approval.
Claude Code permission modes: key facts
- With Claude Code v2.1.283 or later,
autois the built-in starting mode for interactive terminal and VS Code sessions. - In ordinary
plansessions, edits stay blocked until plan approval. With auto mode available,useAutoModeDuringPlanis on by default and sends eligible shell commands to the classifier. - Auto mode pauses after three consecutive or 20 total classifier blocks, then resumes prompting.
- GitHub issue 99694 reports 227 refusals across 4,302 transcript files dated from 2026-08-06 to 2026-10-05; 62 refusals followed an identical allowed call in the same session.
bypassPermissionsstill prompts or denies six action classes, including explicit ask rules and critical-path removals.- In auto and bypass modes, terminal prompts for critical-path removals use a two-minute countdown in Claude Code v2.1.281 or later.
Claude Code permission mode baselines
Claude Code supports six permission modes selectable with --permission-mode:
Mode | Config value | What runs without a routine prompt |
|---|---|---|
Manual |
| Reads and built-in read-only commands in working directories |
Edit automatically |
| Reads, edits, and common filesystem commands in working directories |
Plan |
| Reads, read-only commands, and classifier-approved commands when auto mode is available |
Auto |
| Routine tool calls, with background safety checks |
Don't ask |
| Reads and pre-approved tools; anything that would prompt is denied |
Bypass permissions |
| Most tool calls, including protected-path writes; six categories still prompt or deny |
default is the config value shown as Manual. Deny rules still block in every mode, including bypassPermissions. A project-level permissions.defaultMode value of auto or bypassPermissions does not take effect; an explicit launch flag or an allowed user or managed setting is required.
Claude Code plan mode during exploration
Start it with claude --permission-mode plan or the /plan prompt prefix. Claude Code reads files and runs built-in read-only shell commands to explore, then proposes changes without editing source files.
When auto mode is available and useAutoModeDuringPlan is enabled, which the documentation says is the default, the classifier reviews shell commands outside the built-in read-only set. Approved commands run; rejected commands are blocked. Critical-path removals are outside this flow and retain their separate safeguard.
If auto mode is unavailable or useAutoModeDuringPlan is false, commands outside the built-in read-only set prompt for approval. The important exception is an interactive terminal session launched with bypass permissions available: Claude Code does not enforce plan mode's edit and shell blocks there. Plan mode remains blocked in non-interactive runs, Agent SDK sessions, and the VS Code chat panel.
Claude Code auto mode and classifier decisions
Auto mode runs without routine permission prompts. A separate classifier reviews actions such as shell commands and network requests, blocking actions that exceed the request, target unrecognized infrastructure, or appear driven by hostile content Claude read. Explicit permissions.ask rules and permissions.deny rules are evaluated before the classifier.
If the classifier blocks an action three times in a row or 20 times total in a session, auto mode pauses and Claude Code resumes prompting. Approving the prompted action resumes auto mode.
By default, narrow Bash and PowerShell allow rules can run before the classifier. Set autoMode.classifyAllShell: true to send every Bash and PowerShell command through the classifier while auto mode is active; this adds latency and does not replace the critical-path removal safeguard.
GitHub issue 99694: classifier variability
GitHub issue 99694, opened on 2026-10-05, reports differing verdicts for identical commands. The reporter counted local Claude transcript files while using Claude Code 2.1.286, Claude Fable 5.1, Windows 11, Git Bash, and the VS Code extension.
The reported measurements cover 4,302 transcript files from 2026-08-06 through 2026-10-05:
Measure | Reported result |
|---|---|
Classifier refusals | 227 on 39 days across 6 projects |
Refusals where the same session had already run the identical call with permission | 62 (27%) |
Identical retry allowed within 60 seconds with no operator message between attempts | 18; fastest was 4 seconds |
Refusals with no named rule | 83 (37%) |
These numbers describe the issue reporter's transcript set, not a general error rate for every Claude Code installation. They show why an auto-mode decision should be treated as a classifier result, not as a deterministic allowlist.
Claude Code bypassPermissions mode: six exceptions
Start bypass with claude --permission-mode bypassPermissions or --dangerously-skip-permissions. It skips routine prompts and allows protected-path writes, but these six categories remain outside automatic approval:
- Tools matched by an explicit
permissions.askrule. - Connector tools that an organization sets to
ask. - User-interaction tools:
AskUserQuestionand MCP tools markedrequiresUserInteraction. rmandrmdirremovals targeting a critical path, such as the filesystem root, a home directory, a working directory, or a parent of one.- Cross-session messaging safeguards.
- Reads outside working directories when
permissions.blockReadsOutsideWorkingDirectoriesis enabled. This rule requires Claude Code v2.1.257 or later.
In auto and bypass modes, a terminal prompt for a critical-path removal shows a two-minute countdown. If it expires, Claude Code denies the command; after three expired prompts in one session, later critical-path removals are denied immediately. This handling requires Claude Code v2.1.281 or later. In non-interactive auto-mode runs, the critical-path removal is denied immediately because no terminal prompt is available. Explicit permissions.deny rules also block immediately in every mode.
Sources
- Choose a permission mode: https://code.claude.com/docs/en/permission-modes (read 2026-10-06)
- Configure permissions: https://code.claude.com/docs/en/permissions (read 2026-10-06)
- Configure auto mode: https://code.claude.com/docs/en/auto-mode-config (read 2026-10-06)
- GitHub issue 99694: https://github.com/anthropics/claude-code/issues/99694 (read 2026-10-06)
Last verified: 2026-10-06.