Agent autonomy levels
An autonomy level is the set of actions an agent may take without asking you first. Choosing it is one of the main safety decisions you make before a run.
Updated October 1, 2026 · Other tools described as of October 1, 2026
Short answer. Most agents offer some version of four steps: read only, edit with approval, edit and run commands inside the project, and full access. Pick the lowest level that lets the task finish, and remember that where the agent runs limits the damage more than any prompt does.
The usual levels
- Read only, or plan
- The agent mayList, search and read files; propose a plan
- Use it forQuestions, investigations, a plan you approve before any edit
- Edit with approval
- The agent mayEdit files and run commands after you say yes to each
- Use it forUnfamiliar code, or when you want to watch every step
- Edit and run in the project
- The agent mayEdit and run commands inside the workspace without asking
- Use it forFixes that need trial and error, on a machine where mistakes are cheap
- Full access
- The agent mayAnything your account can do, with no prompts
- Use it forOnly on a throwaway machine with nothing valuable on it
| Level | The agent may | Use it for |
|---|---|---|
| Read only, or plan | List, search and read files; propose a plan | Questions, investigations, a plan you approve before any edit |
| Edit with approval | Edit files and run commands after you say yes to each | Unfamiliar code, or when you want to watch every step |
| Edit and run in the project | Edit and run commands inside the workspace without asking | Fixes that need trial and error, on a machine where mistakes are cheap |
| Full access | Anything your account can do, with no prompts | Only on a throwaway machine with nothing valuable on it |
How the main tools name them
As described on each tool's own site or docs, read on October 1, 2026.
- Codex: sandbox modes read-only, workspace-write (the default) and danger-full-access, combined with approval policies such as on-request and never. Network access is off by default locally.
- Claude Code: asks for permission before it changes files or runs commands, with settings to allow more.
- Conductor: a plan mode that asks the agent for a plan you approve before it edits files.
In Macaron
The macaron CLI asks: before it writes a file it shows the diff, and before it runs a command it shows the command, and both wait for your yes. Pass -y to approve everything, for scripts and CI. It can only touch files inside the folder you started it in.
In the desktop app, Claude Code and Codex keep their own permission settings. Macaron adds limits that don't depend on the agent obeying them: a Computer can't reach your Mac, connectors such as Stripe or Vercel reach a run's commands only when you switch them on, and a sandbox copy only comes back to your Mac through Apply to Mac.
How to choose
- You're asking a question about the code: read only.
- You're in code you don't know well, on your own machine: edit with approval.
- The fix needs the agent to run tests, fail and try again: edit and run in the project, on an isolated machine.
- Full access: only where losing the whole machine wouldn't matter.
Autonomy isn't the only guard
A level limits what an agent can try. It doesn't tell you whether what it did is right. That's what checks before and after, an independent reviewer, per-turn undo and your own reading of the diff are for.
Approval prompts also wear thin: after the twentieth "run npm test?" most people stop reading them. A boundary the agent can't cross, like a separate machine, holds up better than a prompt you click through.
Questions
Which level should I start with?+
Edit with approval on your own machine, or edit and run in the project on an isolated machine. Raise it once you trust the agent on that codebase.
Is read-only mode completely safe?+
Safer, not completely. A read-only agent still sends what it reads to the model provider, so secrets in files it can see can leave your machine.
What does -y do in the macaron CLI?+
It approves every edit and command without asking. Use it in CI or on a machine where that's acceptable.
Do autonomy levels stop an agent from reading my secrets?+
Not by themselves. Keep secrets out of the agent's environment, and pass credentials only for the run that needs them.
Does Macaron override Claude Code's or Codex's permission settings?+
No. Their own settings apply. Macaron's limits are around them: which machine they run on and which credentials they get.
Sources and dates
- Codex approvals and securitylearn.chatgpt.com, read October 1, 2026
- claude.com/product/claude-codeclaude.com, read October 1, 2026
- Conductor docs: agent modesconductor.build, read October 1, 2026
Facts about other products come only from these pages, on the dates shown; prices are as published that day. Macaron's own details are as shipped on October 1, 2026. Products change, so check their sites for the latest.