Skip to content

Approvals & sandboxing

/approvals switches between three presets:

Preset Asks before Can write
Read Only anything that isn’t reading nothing
Agent (default) actions outside the workspace the workspace
Agent (full access) nothing everything

Sandboxing is enforced by the operating system, not by prompt discipline: Landlock + seccomp on Linux, Seatbelt on macOS, restricted tokens on Windows. nori sandbox <platform> <cmd> runs any command inside the same sandbox the agent gets — useful for testing what the agent can and can’t touch.

--dangerously-bypass-approvals-and-sandbox (alias --yolo) disables both. The name is the warning.

Config keys: approval_policy (always / on-request / never) and sandbox_mode (read-only / workspace-write / danger-full-access) in config.toml.

this page as markdown: /cli/guides/approvals.md· index for agents: /llms.txt