# Ask vs Auto vs Yolo Tool Permission Modes in Reasonix: A Complete Guide

> Understand Ask vs Auto vs Yolo tool permission modes in Reasonix. Learn how AI approves file writes and shell commands from manual to autonomous execution.

- Repository: [YHH/DeepSeek-Reasonix](https://github.com/esengine/DeepSeek-Reasonix)
- Tags: deep-dive
- Published: 2026-08-08

---

**Reasonix provides three tool permission modes—Ask, Auto, and Yolo—that control how the AI approves controlled tools like file writes and shell commands, ranging from manual approval for every action to fully autonomous execution with minimal interruption.**

The `esengine/DeepSeek-Reasonix` repository implements a sophisticated permission subsystem that governs how the AI assistant interacts with your filesystem and external systems. Understanding the difference between Ask, Auto, and Yolo tool permission modes in Reasonix is essential for balancing productivity against safety when automating code edits, shell commands, and other high-impact operations.

## Understanding the Three Permission Modes

Reasonix distinguishes between **ordinary permissions** (routine reads, writes, and commands) and **high-impact permissions** (global memory changes, destructive Bash operations, and `forget` commands). The three modes determine how strictly the system enforces human approval before executing controlled tools.

### Ask Mode

**Ask** is the default permission mode that enforces a human-in-the-loop for every tool call requiring permission. When operating in this mode, Reasonix displays an **approval card** for each sensitive operation, allowing you to allow once, allow for the entire session, always allow, or deny the request.

According to the source code in [`internal/cli/cli.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/cli/cli.go) (lines 509-516), the CLI defaults to `ask` unless explicitly overridden. This mode is implemented in the tool-permission subsystem to ensure fail-closed behavior, meaning even headless runs such as `reasonix run` will halt for approval unless you supply `--auto` or `-y` flags.

Use **Ask** mode when working with unfamiliar repositories, making high-risk edits, or handling production-critical work where step-by-step review is necessary. It is less ideal for repeated low-risk operations or trusted automation workflows.

### Auto Mode

**Auto** mode auto-approves ordinary tool calls while retaining safety checks for explicit `ask` or `deny` rules, plan confirmations, and high-impact categories such as new global memory creation, `forget` operations, and nested Bash execution.

This mode accelerates daily code reading, small fixes, tests, and routine implementation in trusted workspaces by removing the friction of repetitive approvals. However, it still respects the permission policy defined in the tool-permission subsystem, ensuring that destructive or sensitive operations remain gated by human confirmation.

Activate Auto mode via the command line:

```bash
reasonix run my_task.py --permission-mode=auto

```

### Yolo Mode

**Yolo** mode skips ordinary permission prompts entirely, allowing writes and commands to continue with minimal interruption. While this enables the fastest execution path, it still enforces explicit `deny` rules, plan confirmation stages, and forced fresh approvals for sensitive operations.

This mode is designed for temporary branches, disposable work-trees, and bulk mechanical edits after a confirmed plan. The validation logic in [`internal/config/edit.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/config/edit.go) (line 663) recognizes `yolo` as a valid permission-mode string alongside `ask` and `auto`.

Avoid using **Yolo** in production environments, with sensitive files, or for operations involving delete/publish/push actions where requirements might be unclear.

## How to Configure Permission Modes

### Command Line Interface

The `--permission-mode` flag defined in [`internal/cli/cli.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/cli/cli.go) accepts three primary values: `ask`, `auto`, and `yolo`. The default value is `ask`, providing maximum safety for new users.

Switch between modes using the following syntax:

```bash

# Default Ask mode - every write/command asks for approval

reasonix run my_task.py

# Auto mode - ordinary tools auto-approved

reasonix run my_task.py --permission-mode=auto

# Yolo mode - ordinary tool prompts suppressed

reasonix run my_task.py --permission-mode=yolo

```

### Desktop Composer UI

In the desktop application, the permission mode is exposed through the UI label defined in [`workers/crash-report/src/stats.ts`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/workers/crash-report/src/stats.ts) (line 232). To change modes graphically:

1. Open the **Composer** pane in the Reasonix desktop client.
2. Locate the **Tool Permission** toggle displaying the current mode (*Ask / Auto / Yolo*).
3. Select the desired mode; changes take effect immediately for the current session.

## Technical Implementation Details

The permission architecture is documented comprehensively in [`docs/TOOL_APPROVAL_MODES.md`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/docs/TOOL_APPROVAL_MODES.md) and implemented across several key files:

- **[`docs/TOOL_APPROVAL_MODES.md`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/docs/TOOL_APPROVAL_MODES.md)**: Defines the semantic behavior and safety guarantees of each mode.
- **[`internal/cli/cli.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/cli/cli.go)** (lines 509-516): Declares the `--permission-mode` CLI flag and allowed values.
- **[`internal/config/edit.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/config/edit.go)** (line 663): Validates permission-mode strings during configuration parsing.
- **[`workers/crash-report/src/stats.ts`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/workers/crash-report/src/stats.ts)** (line 232): Provides the UI label for the desktop client interface.

The policy engine distinguishes between ordinary tool calls and high-impact operations, ensuring that even in **Yolo** mode, certain destructive actions remain protected by the permission subsystem.

## When to Use Each Mode

Choose your permission mode based on the trust level of your workspace and the criticality of your operations:

- **Ask**: Use for unfamiliar codebases, production deployments, or when learning Reasonix capabilities. Every file write and shell command requires explicit consent.
- **Auto**: Ideal for daily development workflows in trusted repositories where you want speed without sacrificing safety nets for truly dangerous operations.
- **Yolo**: Reserve for scratch branches, automated refactoring scripts, or temporary environments where you have confirmed the plan and accept the risk of rapid autonomous execution.

## Summary

- **Ask mode** requires manual approval for every controlled tool call, making it the safest default for critical work.
- **Auto mode** auto-approves ordinary operations while preserving checks for high-impact actions and explicit rules.
- **Yolo mode** minimizes interruptions by skipping ordinary prompts, though explicit `deny` rules and sensitive operation checks remain enforced.
- Configure modes via the `--permission-mode` flag in [`internal/cli/cli.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/cli/cli.go) or through the desktop Composer UI.
- The permission subsystem validates settings in [`internal/config/edit.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/config/edit.go) and surfaces UI labels via [`workers/crash-report/src/stats.ts`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/workers/crash-report/src/stats.ts).

## Frequently Asked Questions

### What is the default permission mode in Reasonix?

**Ask mode is the default.** As implemented in [`internal/cli/cli.go`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/internal/cli/cli.go) (lines 509-516), the `--permission-mode` flag defaults to `ask`, ensuring that new users and headless runs fail-closed unless explicitly configured otherwise. This prevents accidental destructive operations when first using the tool.

### Can I override permission modes for specific tools?

**Yes, explicit rules override the global mode.** Even in **Auto** or **Yolo** mode, you can force an approval prompt for specific tools by defining explicit `ask` rules in your Reasonix plan files. Conversely, `deny` rules are respected across all modes, preventing specific tools from executing regardless of the permission mode setting.

### Is Yolo mode safe for production use?

**No, Yolo mode is not recommended for production.** According to the documentation in [`docs/TOOL_APPROVAL_MODES.md`](https://github.com/esengine/DeepSeek-Reasonix/blob/main/docs/TOOL_APPROVAL_MODES.md), **Yolo** is designed for temporary branches, disposable work-trees, and bulk mechanical edits where speed outweighs risk. Production environments, sensitive files, and operations involving deletes or publishes should use **Ask** or **Auto** mode to maintain appropriate safety checks.

### How do permission modes interact with high-impact operations?

**High-impact operations are always protected.** Regardless of whether you select **Ask**, **Auto**, or **Yolo**, the tool-permission subsystem maintains checkpoints for high-impact categories including new global memory creation, `forget` commands, and nested Bash execution. These operations require explicit confirmation even in **Yolo** mode, ensuring that the most dangerous actions remain gated by human approval.