Glossary

Agent autonomy levels

An autonomy level is the set of actions an agent may take without asking you first. Choosing it is one of the main safety decisions you make before a run.

Updated October 1, 2026 · Other tools described as of October 1, 2026

Short answer. Most agents offer some version of four steps: read only, edit with approval, edit and run commands inside the project, and full access. Pick the lowest level that lets the task finish, and remember that where the agent runs limits the damage more than any prompt does.

The usual levels

Read only, or plan
The agent mayList, search and read files; propose a plan
Use it forQuestions, investigations, a plan you approve before any edit
Edit with approval
The agent mayEdit files and run commands after you say yes to each
Use it forUnfamiliar code, or when you want to watch every step
Edit and run in the project
The agent mayEdit and run commands inside the workspace without asking
Use it forFixes that need trial and error, on a machine where mistakes are cheap
Full access
The agent mayAnything your account can do, with no prompts
Use it forOnly on a throwaway machine with nothing valuable on it

How the main tools name them

As described on each tool's own site or docs, read on October 1, 2026.

  • Codex: sandbox modes read-only, workspace-write (the default) and danger-full-access, combined with approval policies such as on-request and never. Network access is off by default locally.
  • Claude Code: asks for permission before it changes files or runs commands, with settings to allow more.
  • Conductor: a plan mode that asks the agent for a plan you approve before it edits files.

In Macaron

The macaron CLI asks: before it writes a file it shows the diff, and before it runs a command it shows the command, and both wait for your yes. Pass -y to approve everything, for scripts and CI. It can only touch files inside the folder you started it in.

In the desktop app, Claude Code and Codex keep their own permission settings. Macaron adds limits that don't depend on the agent obeying them: a Computer can't reach your Mac, connectors such as Stripe or Vercel reach a run's commands only when you switch them on, and a sandbox copy only comes back to your Mac through Apply to Mac.

How to choose

  • You're asking a question about the code: read only.
  • You're in code you don't know well, on your own machine: edit with approval.
  • The fix needs the agent to run tests, fail and try again: edit and run in the project, on an isolated machine.
  • Full access: only where losing the whole machine wouldn't matter.

Autonomy isn't the only guard

A level limits what an agent can try. It doesn't tell you whether what it did is right. That's what checks before and after, an independent reviewer, per-turn undo and your own reading of the diff are for.

Approval prompts also wear thin: after the twentieth "run npm test?" most people stop reading them. A boundary the agent can't cross, like a separate machine, holds up better than a prompt you click through.

Questions

Which level should I start with?+

Edit with approval on your own machine, or edit and run in the project on an isolated machine. Raise it once you trust the agent on that codebase.

Is read-only mode completely safe?+

Safer, not completely. A read-only agent still sends what it reads to the model provider, so secrets in files it can see can leave your machine.

What does -y do in the macaron CLI?+

It approves every edit and command without asking. Use it in CI or on a machine where that's acceptable.

Do autonomy levels stop an agent from reading my secrets?+

Not by themselves. Keep secrets out of the agent's environment, and pass credentials only for the run that needs them.

Does Macaron override Claude Code's or Codex's permission settings?+

No. Their own settings apply. Macaron's limits are around them: which machine they run on and which credentials they get.

Sources and dates

Facts about other products come only from these pages, on the dates shown; prices are as published that day. Macaron's own details are as shipped on October 1, 2026. Products change, so check their sites for the latest.

Keep reading