Claude Code permission prompts: what asks, what doesn't, and how to change it
Every time Claude Code stops to ask, that is a permission prompt. Knowing what triggers them is the difference between a session that runs for an hour and one that waits for you every two minutes.
The RoamAI teamPublished September 9, 2026
What asks by default
- Never: reading files, listing directories, and searching (the Read, Glob and Grep tools).
- Always, until you say otherwise: editing or creating files (Edit, Write) and every shell command (Bash).
When it asks, you can approve once, or approve for the rest of the session for that tool or that command pattern. An approval for a specific command such as npm test can be saved to the project's settings so it never asks again.
Permission modes
- default: as above.
- acceptEdits: file edits inside the project are accepted automatically. Shell commands still ask.
- plan: read-only. Claude can look and propose, but not change anything.
- bypassPermissions: nothing asks. The flag is --dangerously-skip-permissions, and the name is accurate.
Switch modes with Shift+Tab inside a session, or start with --permission-mode <mode>. Set a default in settings with permissions.defaultMode.
Allow and deny rules
Rules live in .claude/settings.json in the project (shared with the team), .claude/settings.local.json (yours only), or ~/.claude/settings.json (every project). Each rule names a tool and, optionally, a pattern:
{
"permissions": {
"allow": ["Bash(npm test)", "Bash(git diff:*)", "Edit"],
"deny": ["Read(./.env)", "Bash(rm -rf:*)"]
}
}Bash(npm test) allows exactly that command. Bash(git diff:*) allows anything that starts with git diff. A bare tool name allows the whole tool. Deny rules win over allow rules. Running /permissions inside a session edits the same lists.
Deciding programmatically with hooks
A PreToolUse hook runs a command of yours before each tool call. It receives the tool name and its input as JSON on stdin, and can approve, deny, or leave the decision to the normal prompt. This is how teams enforce rules that a pattern cannot express, such as allowing git push only to branches with a certain prefix.
The root restriction
Claude Code refuses to start with --dangerously-skip-permissions when running as root, and exits with status 1. On a server, run it as an ordinary user. Verified on 2.1.x in August 2026.
The problem when you are not there
A prompt blocks the session until someone answers it. In a terminal on a server, that means the session sits idle until you ssh back in and notice. Turning prompts off fixes the waiting and gives up the safety.
RoamAI keeps the prompts and moves the answering. A session that stops on a permission goes to the top of the list, the request appears as buttons, and you get a push notification. Approvals and the emergency stop.
Sessions that stay up, without the server work
RoamAI runs Claude Code on a hosted machine or on a server you connect, and tells you when a session needs you. Signing up is free. Workspaces are $9 / month.
Get started