# Access levels

The access level decides what your agent may do without asking you first. Pick it under the chat's message box, in **Access**. You can change it for any message.

## The three levels

- **Auto**: recommended. The agent's own automatic review handles its permission requests, where it has one. See below.
- **Ask before shell**: every shell command asks first. Editing notes and Niv's own note tools run without asking.
- **Full access**: no questions and no sandbox, including shell and web tools. Use it only for a task you trust.

![The Access menu under the message box: Auto, Ask before shell and Full access](https://niv.md/docs-media/access-menu.dark.png)

## Auto is a little different for each agent

What **Auto** does depends on the agent:

- **Claude Code** and **Codex**: Auto uses the agent's own automatic review for permission requests.
- **Cursor** and **Grok**: Auto turns on the agent's own automatic mode. Niv hasn't checked how it reviews.
- **OpenCode**: has no automatic review, so Auto asks you before shell commands, edits and imported tools.
- **Antigravity**: Auto runs it in its default mode, with no automatic reviewer.

If the agent's own reviewer blocks something, the chat says so. Switching to **Ask before shell** lets you decide instead.

Codex also follows your own Codex settings, which may approve some things automatically.

## When the agent asks

The question appears in the chat, with the exact command and the folder it would run in:

- **Allow** runs it once.
- **Allow for this chat** lets simple commands that start the same way run without asking until the chat ends. Pipes, redirections and extra actions still ask.
- **Deny**, or **Deny with a reason…** to tell the agent why.

If nobody answers in time, the command doesn't run.

## Tools from MCP servers

Tools from your own MCP servers follow the same levels. With **Ask before shell**, each tool call asks first; with **Full access**, they run without asking.

---

Published with [Niv](https://niv.md/) in the Space Docs.
