Permissions Deep Dive
Three tiers of risk — with fine-grained rule syntax.
Notes
Deny rules are absolute
A deny rule always wins, regardless of where it's defined. This makes
guardrails reliable: a project-level deny cannot be overridden by a more
permissive user setting.
Start strict, relax selectively
Begin with Ask Every Time for unfamiliar repos. As you learn which
commands and edits are safe, add allow rules for those specific patterns.
Never start permissive and try to lock down later.
Where to go next
- Permission Modes & Settings — pick the right comfort level and learn how settings cascade
- Working Directories & Scope — Claude operates from where you launch it; scope tight