Settings & permissions
Permissions decide what each crew member may do on its own, what it must ask about, and what it can never do.
Three answers
Every action resolves to one of three answers:
| Answer | What happens |
|---|---|
| Allow | The model does it and logs it |
| Ask | The manager sends you an approval request |
| Block | The action is refused and the model is told why |
Levels
- Folder — read, write or run access per folder. See Workspaces & folders.
- Tool — terminal, browser, Git, package manager, deploy.
- Action — specific commands, for example
npm testallowed,npm publishblocked.
The most specific rule wins. A blocked action stays blocked even if the folder allows writing.
Defaults
| Setting | Default |
|---|---|
| Read files in assigned folders | Allow |
| Edit files on a task branch | Allow |
| Run tests and linters | Allow |
| Run other commands | Ask |
| Deploy | Ask |
| Delete files or branches | Block |
| Internet access | Block |
Per-model overrides
Open a crew member and switch to Permissions to override any default for that member only. A common setup is to let QA run every test command while the engineer has to ask.