
11. Securing Autonomous Agents (Permissions, Auto Mode and the Sandbox)
Om avsnittet
In Episode 11 of Beyond Prompting, author Sho Shimoda breaks down the permission and governance architecture that protects your host machine while allowing Claude Code to operate autonomously. As session defaults shift toward classifier-driven execution, understanding how actions are evaluated is essential for safe operation. In this episode, we cover:
- First-Match Resolution Order: How proposed tool calls evaluate in a strict, fixed sequence—Deny rules first, then Ask rules, then Allow rules, before falling through to session permission modes and the classifier.
- The Six Permission Modes: Navigating session postures—Manual, Accept Edits, Plan, Auto, Don't Ask, and Bypass Permissions—and understanding how settings merge additively across scopes rather than replacing team defaults.
- Auto Mode & The Classifier: How a Sonnet 5 classifier evaluates proposed tool calls in real time while enforcing protected paths (like .git, .vscode, and .claude) and critical deletion paths regardless of user allow rules.
- The OS-Level Sandbox Boundary: Distinguishing between client-side permission controls and true operating system isolation (Seatbelt on macOS, bubblewrap on Linux/WSL2) that constrains shell command execution even if prompt injection occurs.
(Note for listeners: This episode covers Chapter 11 of Sho Shimoda's book RUNNING CLAUDE: The Operator’s Guide to Chat, Cowork and Claude Code, available on Amazon as the successor book to Master Claude: Chat, Cowork and Code).
Master Claude Chat, Cowork, Code med MASTER-CLAUDE-CHAT-COWORK-CODE finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.