Access levels
The access level decides what your agent may do without asking you first. Pick it under the chat's message box, in Access. You can change it for any message.
The three levels
Auto: recommended. The agent's own automatic review handles its permission requests, where it has one. See below.
Ask before shell: every shell command asks first. Editing notes and Niv's own note tools run without asking.
Full access: no questions and no sandbox, including shell and web tools. Use it only for a task you trust.
<!-- screenshot: the Access menu under the message box -->
Auto is a little different for each agent
What Auto does depends on the agent:
Claude Code and Codex: Auto uses the agent's own automatic review for permission requests.
Cursor and Grok: Auto turns on the agent's own automatic mode. Niv hasn't checked how it reviews.
OpenCode: has no automatic review, so Auto asks you before shell commands, edits and imported tools.
Antigravity: Auto runs it in its default mode, with no automatic reviewer.
If the agent's own reviewer blocks something, the chat says so. Switching to Ask before shell lets you decide instead.
Codex also follows your own Codex settings, which may approve some things automatically.
When the agent asks
The question appears in the chat, with the exact command and the folder it would run in:
Allow runs it once.
Allow for this chat lets simple commands that start the same way run without asking until the chat ends. Pipes, redirections and extra actions still ask.
Deny, or Deny with a reason… to tell the agent why.
If nobody answers in time, the command doesn't run.
Tools from MCP servers
Tools from your own MCP servers follow the same levels. With Ask before shell, each tool call asks first; with Full access, they run without asking.