Configure
Permissions
Decide what agents may do: allow, ask, deny.
#Tiers
- allow — runs immediately, no prompt.
- ask — pauses for your approval first.
- deny — always blocked, even if wrapped or rephrased.
#Per-command bash
codey.json
{
"permissions": {
"bash": {
"git status": "allow",
"git push": "ask",
"rm -rf": "deny"
}
}
}- Most specific wins — per-command entries beat the blanket tier.
- Project overrides global — repo policy tightens or loosens the default.
- Subagents inherit — delegated agents run isolated with your policy intact.
Deny survives wrapping. Blocked commands stay blocked through pipes, flags, and rephrasing. Full policy in the security docs.