Workspace access and AI modes
Understand the difference between filesystem access and mutation approval policy.
Guides follow the current project source. Check the release notes for your installed version.
Access mode
- Read-only: all writes are rejected
- Read/write: compatible writes may proceed to the change-policy layer
AI Review
Supported mutations are prepared and persisted for local Accept/Reject. Stale-file validation is repeated before an approved change is applied.
AI Auto
Compatible mutations can apply immediately, but project boundaries, protected paths, command sandboxing and explicit Git-push permission remain enforced.
Read-only always wins
A read-only workspace cannot be modified by AI file tools, regardless of whether the UI currently shows AI Auto or AI Review. The scope of access is the approved workspace, not the entire home folder.
Editing policy determines how a permitted write is finalized: AI Review queues a change for human approval, while AI Auto applies compatible changes and records them in history.
Validate with a safe test
Test in a disposable repository: ask for a read, a proposed change and a current change-history lookup. Inspect whether the action was refused, queued or applied according to your chosen policies.
Keep command execution policy separate from file-editing policy. AI Review does not permit remote MCP self-approval of pending actions.