Permission modes
Permission modes act like a safety guardrail, deciding whether Aureink must get your confirmation before performing a sensitive operation. Actions like writing files, running commands, and going online carry some risk, and the guardrail lets you find the right balance between “let it run freely” and “ask me about everything.”
1 · Overview
While Aureink works, it runs into some sensitive operations. Permission modes decide whether it should stop and ask you before executing. They govern “whether to ask,” not “how far it can reach” — the latter is handled by Security Center and the sandbox.
2 · The two permission modes
Use the “Your scenario → Recommended” table below to choose:
| Your situation | Recommended mode | What happens |
|---|---|---|
| Everyday use / unsure of the risk | Ask when needed (default) | Pops up for your consent before writing files, running commands, or going online |
| Trusted batch tasks / want fewer interruptions | Auto within sandbox | Automatically allows actions within the sandbox’s scope; still asks when they go beyond it |
In a nutshell: “Ask when needed” is safer, “Auto within sandbox” is more hands-off, and neither breaks the sandbox’s boundary.
3 · The permission confirmation dialog
When you need to confirm, a permission confirmation dialog pops up, with three choices:
〔Figure: the permission confirmation dialog, highlighting “Allow once,” “Allow for this session,” “Deny,” and the AI Analysis area〕
- Allow once — allow just this one operation.
- Allow for this session — stop asking for the same kind of operation within this session.
- Deny — don’t perform the operation.
For high-risk operations, there’s also a second confirmation and a countdown lock to prevent misclicks; inside the dialog you can view the risk analysis and recommendation from AI Analysis to help you decide whether to allow it.
4 · Relationship with Security Center
Permission modes decide “whether to ask you,” while the sandbox decides “how far it can reach.” The two stack: even if you pick “Auto within sandbox,” Aureink can only auto-allow within the boundary the sandbox permits, and anything beyond it is still blocked. To learn how the boundary is set, see “Security Center.”
5 · Important notes
Important notes
- Permission boundary: permission modes only affect “whether to ask,” not the reach the sandbox sets.
- Security tip: before switching to “Auto within sandbox,” confirm the task is trusted and the sandbox boundary is tightened; for tasks of unknown origin, keep “Ask when needed.”
- Usage tip: allow high-risk operations with care, and make good use of the AI Analysis and countdown lock in the dialog before deciding.
Last updated · July 2026 | Next: Security Center →
