Blog · · Dimitris Kyriakakis

Claude Code keeps asking for permission? Stop the prompts you don't need

Since 25 September I have answered 103 prompts from coding agents on my Mac, and 43 of them were Bash commands. Some of them were the same commands in the same projects, asked again in a new session, like git checkout and git branch.

Claude Code asks before it does anything it can't take back, and that's the right default. Most of the repeats can go, though, and the tools for that are already built in.

What runs without asking

Reads never prompt. Claude Code also has a built-in list of read-only commands it runs without a prompt in every mode: ls, cat, echo, pwd, head, tail, grep, find, wc, which, diff, stat, du, cd and the read-only forms of git. That list isn't configurable, so everything else is up to your rules and your mode.

"Yes, and don't ask again"

When a Bash command or a web fetch prompts, the third option writes a rule for you. It goes into .claude/settings.local.json at the root of the git repository, so it holds for that project only and stays out of what you share with your team.

Keep in mind it doesn't work the same way for file edits: an approved edit only holds until the session ends.

Writing the rules yourself

For anything you allow in every project, a rule in your own settings file saves the prompt everywhere. We'll allow the test and build scripts, and keep pushes behind a prompt:

{
  "permissions": {
    "allow": ["Bash(npm run *)", "Bash(git log *)"],
    "ask": ["Bash(git push *)"],
    "deny": ["Bash(rm -rf *)"]
  }
}
  1. Bash(npm run *) matches npm run build and npm run test --watch, and not npm install.
  2. The space before the trailing * is part of the rule. The older Bash(npm run:*) form still works and means the same.
  3. Rules are checked in the order deny, then ask, then allow, so git push keeps prompting even if a broader allow would match it.

Where the rule lives decides who it applies to:

  1. ~/.claude/settings.json: you, in every project.
  2. .claude/settings.json in the repo: everyone who clones it.
  3. .claude/settings.local.json: you, in this repo only. This is the file "don't ask again" writes to.

A local file beats the shared one, and both beat your user file. Managed settings from an organisation and the --settings flag sit above all three.

💡 **/permissions lists every rule and the file it comes from**, which is the quickest way to find out why something still prompts, or why it doesn't.

Permission modes

Rules are per command. A mode changes how the whole session asks, and Shift+Tab cycles through them while you work:

  1. Manual (default): only reads run without asking.
  2. acceptEdits: file edits and common file commands like mkdir, mv and cp run too.
  3. plan: Claude explores and plans without changing anything.
  4. auto: a second model, the classifier, reviews actions instead of you. Since Claude Code 2.1.283 it's the mode interactive sessions start in.

You can also start a session in a mode with claude --permission-mode plan, or set defaultMode in your settings.

⚠️ bypassPermissions runs everything with no checks at all. The docs say it is for isolated containers and VMs only, and they mean it.

A lot of my sessions run in auto mode now, and the prompts that still reach me are the ones worth reading: a git push, a plan to approve, a question with options.

The prompts that are left

The prompts you still want are the ones that need your judgement, and the catch is noticing them. A prompt in a terminal tab you aren't looking at stops that agent until you happen to switch back.

That is what I built AgentNod for. Every prompt from Claude Code, Codex and Cursor lands in one queue on the Mac, with the exact command or diff, and you answer it with a keystroke. Always on a card does what "don't ask again" does: AgentNod writes the same Bash(npm test:*) entry into the project's .claude/settings.local.json, so the terminal stops asking too. 7 of my 103 decisions were answered by rules like that before I saw them.

Start with /permissions in your busiest project and look at what's already there. Enjoy!