Ask vs Auto vs Yolo Tool Permission Modes in Reasonix: A Complete Guide
Reasonix provides three tool permission modes—Ask, Auto, and Yolo—that control how the AI approves controlled tools like file writes and shell commands, ranging from manual approval for every action to fully autonomous execution with minimal interruption.
The esengine/DeepSeek-Reasonix repository implements a sophisticated permission subsystem that governs how the AI assistant interacts with your filesystem and external systems. Understanding the difference between Ask, Auto, and Yolo tool permission modes in Reasonix is essential for balancing productivity against safety when automating code edits, shell commands, and other high-impact operations.
Understanding the Three Permission Modes
Reasonix distinguishes between ordinary permissions (routine reads, writes, and commands) and high-impact permissions (global memory changes, destructive Bash operations, and forget commands). The three modes determine how strictly the system enforces human approval before executing controlled tools.
Ask Mode
Ask is the default permission mode that enforces a human-in-the-loop for every tool call requiring permission. When operating in this mode, Reasonix displays an approval card for each sensitive operation, allowing you to allow once, allow for the entire session, always allow, or deny the request.
According to the source code in internal/cli/cli.go (lines 509-516), the CLI defaults to ask unless explicitly overridden. This mode is implemented in the tool-permission subsystem to ensure fail-closed behavior, meaning even headless runs such as reasonix run will halt for approval unless you supply --auto or -y flags.
Use Ask mode when working with unfamiliar repositories, making high-risk edits, or handling production-critical work where step-by-step review is necessary. It is less ideal for repeated low-risk operations or trusted automation workflows.
Auto Mode
Auto mode auto-approves ordinary tool calls while retaining safety checks for explicit ask or deny rules, plan confirmations, and high-impact categories such as new global memory creation, forget operations, and nested Bash execution.
This mode accelerates daily code reading, small fixes, tests, and routine implementation in trusted workspaces by removing the friction of repetitive approvals. However, it still respects the permission policy defined in the tool-permission subsystem, ensuring that destructive or sensitive operations remain gated by human confirmation.
Activate Auto mode via the command line:
reasonix run my_task.py --permission-mode=auto
Yolo Mode
Yolo mode skips ordinary permission prompts entirely, allowing writes and commands to continue with minimal interruption. While this enables the fastest execution path, it still enforces explicit deny rules, plan confirmation stages, and forced fresh approvals for sensitive operations.
This mode is designed for temporary branches, disposable work-trees, and bulk mechanical edits after a confirmed plan. The validation logic in internal/config/edit.go (line 663) recognizes yolo as a valid permission-mode string alongside ask and auto.
Avoid using Yolo in production environments, with sensitive files, or for operations involving delete/publish/push actions where requirements might be unclear.
How to Configure Permission Modes
Command Line Interface
The --permission-mode flag defined in internal/cli/cli.go accepts three primary values: ask, auto, and yolo. The default value is ask, providing maximum safety for new users.
Switch between modes using the following syntax:
# Default Ask mode - every write/command asks for approval
reasonix run my_task.py
# Auto mode - ordinary tools auto-approved
reasonix run my_task.py --permission-mode=auto
# Yolo mode - ordinary tool prompts suppressed
reasonix run my_task.py --permission-mode=yolo
Desktop Composer UI
In the desktop application, the permission mode is exposed through the UI label defined in workers/crash-report/src/stats.ts (line 232). To change modes graphically:
- Open the Composer pane in the Reasonix desktop client.
- Locate the Tool Permission toggle displaying the current mode (Ask / Auto / Yolo).
- Select the desired mode; changes take effect immediately for the current session.
Technical Implementation Details
The permission architecture is documented comprehensively in docs/TOOL_APPROVAL_MODES.md and implemented across several key files:
docs/TOOL_APPROVAL_MODES.md: Defines the semantic behavior and safety guarantees of each mode.internal/cli/cli.go(lines 509-516): Declares the--permission-modeCLI flag and allowed values.internal/config/edit.go(line 663): Validates permission-mode strings during configuration parsing.workers/crash-report/src/stats.ts(line 232): Provides the UI label for the desktop client interface.
The policy engine distinguishes between ordinary tool calls and high-impact operations, ensuring that even in Yolo mode, certain destructive actions remain protected by the permission subsystem.
When to Use Each Mode
Choose your permission mode based on the trust level of your workspace and the criticality of your operations:
- Ask: Use for unfamiliar codebases, production deployments, or when learning Reasonix capabilities. Every file write and shell command requires explicit consent.
- Auto: Ideal for daily development workflows in trusted repositories where you want speed without sacrificing safety nets for truly dangerous operations.
- Yolo: Reserve for scratch branches, automated refactoring scripts, or temporary environments where you have confirmed the plan and accept the risk of rapid autonomous execution.
Summary
- Ask mode requires manual approval for every controlled tool call, making it the safest default for critical work.
- Auto mode auto-approves ordinary operations while preserving checks for high-impact actions and explicit rules.
- Yolo mode minimizes interruptions by skipping ordinary prompts, though explicit
denyrules and sensitive operation checks remain enforced. - Configure modes via the
--permission-modeflag ininternal/cli/cli.goor through the desktop Composer UI. - The permission subsystem validates settings in
internal/config/edit.goand surfaces UI labels viaworkers/crash-report/src/stats.ts.
Frequently Asked Questions
What is the default permission mode in Reasonix?
Ask mode is the default. As implemented in internal/cli/cli.go (lines 509-516), the --permission-mode flag defaults to ask, ensuring that new users and headless runs fail-closed unless explicitly configured otherwise. This prevents accidental destructive operations when first using the tool.
Can I override permission modes for specific tools?
Yes, explicit rules override the global mode. Even in Auto or Yolo mode, you can force an approval prompt for specific tools by defining explicit ask rules in your Reasonix plan files. Conversely, deny rules are respected across all modes, preventing specific tools from executing regardless of the permission mode setting.
Is Yolo mode safe for production use?
No, Yolo mode is not recommended for production. According to the documentation in docs/TOOL_APPROVAL_MODES.md, Yolo is designed for temporary branches, disposable work-trees, and bulk mechanical edits where speed outweighs risk. Production environments, sensitive files, and operations involving deletes or publishes should use Ask or Auto mode to maintain appropriate safety checks.
How do permission modes interact with high-impact operations?
High-impact operations are always protected. Regardless of whether you select Ask, Auto, or Yolo, the tool-permission subsystem maintains checkpoints for high-impact categories including new global memory creation, forget commands, and nested Bash execution. These operations require explicit confirmation even in Yolo mode, ensuring that the most dangerous actions remain gated by human approval.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →