Quick answer
For a long time, Claude Code asked your permission before almost every shell command or file edit. By default, that's over. Since August 14, 2026, auto mode is the default permission mode for new sessions on Pro, Max and Team plans.
The current docs go further: from v2.1.283, auto mode is the starting mode for interactive terminal and VS Code sessions on every plan and provider.
If ⏵⏵ auto mode on showed up in your status bar without you touching anything, that's why.
Auto mode in one picture
In manual mode, you're the guard at the door: every action goes past you. In auto mode, a second model, the classifier, takes that post. It reviews actions before they run and blocks those that go beyond your request, target infrastructure it doesn't recognize, or seem driven by hostile content Claude read.
The guard hasn't disappeared. It just changed shape: fewer buzzes for you, but still a check.
Not a guarantee
Anthropic's docs are clear: auto mode reduces permission prompts but doesn't guarantee safety. Use it for tasks where you trust the general direction, not as a replacement for review on sensitive operations.
What's blocked by default
The classifier trusts your working directory and the git remotes configured when the session started. Everything else is treated as external. Here's part of what it blocks by default:
- Downloading and executing code, like
curl | bash - Sending sensitive data to external endpoints
- Production deploys and migrations
- Force push
- Commands that destroy uncommitted work:
git reset --hard,git checkout -- .,git clean -fd,git stash drop terraform destroyand equivalents- Printing a live credential or token into the transcript or a file
- Merging a pull request no human has approved, or disabling CI checks
- Running a command with a flag that disarms a safety guard, like
--insecure
To print the full rule lists as JSON:
claude auto-mode defaults
A remote added mid-session with git remote add isn't trusted. It's a simple protection against a classic exfiltration scenario.
Recent hardening
Several rules were added over the summer:
- Week of August 31: the classifier also blocks requesting credentials from the cloud instance-metadata endpoint, and connecting to sibling containers Claude didn't start. Claude Code also asks you before the first read of a file outside your working directories.
- Same week: a
defaultModeset to"bypassPermissions"in a project's.claude/settings.jsonno longer takes effect. The session starts in manual mode. A cloned repo can no longer turn off your protections behind your back. - Week of September 7: when the classifier blocks an action, the reason Claude receives usually names the matching rule, such as
[Data Exfiltration].
Your instructions count
A lesser-known point: the classifier reads what you say in the conversation. If you write "don't push" or "wait for my review before deploying", it blocks matching actions even when the default rules would allow them.
There's an important limit. These boundaries aren't stored as rules: the classifier rereads them from the transcript on each check. If context compaction removes the message where you stated them, they can be lost. For a hard guarantee, write a deny rule.
{"permissions": {"deny": ["Bash(git push *)"]}}
Staying in control
Switch modes mid-session
Shift+Tab cycles through modes. From auto, the first press switches to manual (default), then the cycle goes to acceptEdits, plan, and back to default.
Pick your starting mode
If you'd rather start in manual mode, set defaultMode in your user settings. If you had already set another mode, it's kept: Claude Code asks you once, and nothing changes if you decline.
{"permissions": {"defaultMode": "default"}}
For organizations
An admin can remove auto mode entirely by setting permissions.disableAutoMode to "disable" in managed settings.
What it costs
On Pro, Max and Team plans, the classifier's calls no longer count toward your usage limits.
Supported models
Auto mode doesn't work with every model. On the Anthropic API, you need Claude Opus 4.6 or later, Sonnet 4.6 or later, or a Fable model. On Bedrock, Google Agent Platform and Foundry, only Sonnet 5, Opus 4.7 or later, and the Fable models. Haiku isn't supported. If the model doesn't qualify, the session starts in manual mode.
Our take
For most developers, this change is good news: fewer clicks, and a safety net smarter than a static allowlist. But it shifts responsibility. Before, you approved each action. Now, you need to know what the classifier lets through, for example pushes to branches of the current repo, which go through without a prompt unless you say otherwise.
Three simple habits: deny rules for what must never happen, a sandbox or container for sensitive projects, and a review of diffs before merging.
Next steps
- Permissions and sandbox: fine-tune what Claude can do
- Don't give your API keys to Claude Code: limit the possible damage
- Security best practices: the full checklist
- Why Claude Code sometimes switches models mid-session: the other classifier, for cyber and bio safeguards