Permissions: what the agent may do without asking you
Lesson 1 of the module "Put guardrails in place that hold" in the course "Work with Claude Code on a real project: context, planning, review".
Lesson objective
By the end of this lesson, you will be able to choose a permission mode suited to the task, write allow, ask and deny rules in the right settings file according to your repository's risks, and know what those rules don't cover.
Where it fits
Put guardrails in place that hold
What can the agent do without asking me, and how do I enforce what must never happen?
Lessons in this module
- Permissions: what the agent may do without asking you (this lesson)
- Hooks: rules that always apply
What you will learn in the course
This lesson is part of the course Work with Claude Code on a real project: context, planning, review
- Explain what fills Claude Code's context window and manage it (/context, /clear, /compact, resuming and naming sessions), taking cost into account.
- Write a short, useful CLAUDE.md placed at the right level of the hierarchy (user, project, local, subdirectory, path-scoped rules), with imports if needed.
- Run a task on existing code as explore, plan, code, commit, with plan mode, verification criteria and Git rather than checkpoints alone.
- Choose and justify the right mechanism for a need (CLAUDE.md, skill or command, subagent, MCP server, hook) and set it up in the repository.
- Choose a permission mode and write allow, ask and deny rules suited to the project's risks, in the right settings file.
- Write simple hooks as deterministic guardrails (block, format, verify) and know their risks and limits.
- Review the agent's work with a checklist (scope, tests, secrets, migrations, dependencies) and an independent review, and know when to automate it in non-interactive mode or in GitHub Actions.
Related courses
- Build and ship a web app with an AI coding agentJunior · ~2 hr 45 min
- Add a database, authentication and payments to your appAdvanced · ~4 hr
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min