Permissions and autonomy#
VOOL distinguishes reading from changing. Reading tools operate inside the workspace you granted. Anything that changes something — writing files, running commands, sending a payment — is governed by the permission system, not by the model's judgement.
What is this for?#
Deciding, before anything runs, which actions need your explicit approval and which refusals are final. The model proposes; the permission controller decides.
How does it work?#
- Read tools (opening a file, listing a folder, searching) run inside the granted workspace without a prompt.
- Changing tools ask first. The approval names the exact action and scope — the file that will be written, the command that will run — and the action happens only after you approve it.
- Modes narrow, never widen. A mode (or a skill's declared tool budget) can reduce what is offered; no mode, skill, or plugin grants anything. See Skills and plugins.
- Spending is its own authority. Approving an action never approves spending; price guards and spend caps refuse before the provider is contacted. See Spending limits.
What permission or connection does it require?#
None to use — the permission system is always on. There is no setting that turns it off, and no recovery link that grants a permission on your behalf.
What can go wrong?#
permission_denied— an action was not permitted, so nothing was changed. The refusal names the governing scope. What to do next: request the action explicitly so it is inside an authorized scope, or change the governing policy deliberately in settings.confinement_refusal— a file change outside the allowed scope was blocked. Nothing outside the scope was touched. If you want the change, request it explicitly.tool_unavailable— a tool this mode offers is not available here; the message names the missing prerequisite (for example, enabling a plugin).- A waiting approval is not a failure. A permission request waiting for you is not an error; the turn waits. Cancelling your answer cancels the action — it does not run half-way.
What do I do next?#
Read what the refusal names, change that one thing, and try again. Refusals never leave partial effects behind: the wording states exactly what did not happen. Full contracts for every code are in the Error Book.