Builder tools
Claude Code Permission Prompts: Choose the Smallest Safe Approval
Cihan's view: Classify the requested action, approve only the bounded command you understand, and use /permissions to inspect or remove rules before the next tool call.
What you will make
A small approval note for a fictional Claude Code task. It will record the command, the files it can touch, the approval scope, and the check you will run afterward.
This is a documentation-based troubleshooting guide. Claude Code documents separate permission behavior for file reads, Bash commands, file changes, web access, and tool rules. The example prompt and approval note below are illustrative. They are not the result of a Claude Code run.
The situation
You are in a disposable folder containing weekly-report.csv. You ask Claude Code to inspect the file and create report.md. It asks to run a shell command and later asks to write the report. You want to avoid approving a broad command or a permanent rule by accident.
Use this fictional task brief:
Read weekly-report.csv. Do not edit it. Create report.md with:
1. rows whose status is Missing or Blocked;
2. the total number of rows;
3. a short list of fields that need human review.
Do not install packages, access the network, or modify any other file.
Three steps
1. Classify the prompt before answering
Check what Claude Code is asking to do. A read-only file inspection, a Bash command, and a file write are different permission categories. The official permissions guide says Bash commands and file modifications normally require approval in Manual mode, while read-only file reads do not.
If the prompt contains a long shell pipeline, a package install, a network request, or a path outside the disposable folder, stop and rewrite the task brief before approving it.
2. Ask for a bounded action
Paste this follow-up when the requested action is too broad:
Before running anything, show me:
- the exact command or file change;
- every path it will read or write;
- whether it uses the network or installs a package;
- the smallest one-time approval needed for this step.
Do not combine inspection, file changes, package installation, or network access in one action. Wait for my approval.
Approve a one-time action only after the command matches the task. Do not choose a permanent rule just to remove a prompt. If the prompt offers a comment field, add a note such as Only for this disposable report folder; input must remain unchanged.
3. Check the result and permission rules
After the action, verify that weekly-report.csv still has the same bytes and that report.md is the only new file. Check the report against the task brief: it should contain the requested status rows, a row count, and review fields.
Use /permissions to inspect the active rules. Claude Code documents Allow, Ask, and Deny rules, and says rules are evaluated in the order deny, then ask, then allow. Remove a rule you no longer need before continuing with another task.
What a good output looks like
Illustrative approval note:
Action: read weekly-report.csv and write report.md
Input: weekly-report.csv
Output: report.md
Network: none
Package install: none
Approval: one-time approval for this action
Checks: input hash unchanged; report.md is the only new file
This note is a checklist, not captured tool output. Your actual report must still be checked against the source file.
Acceptance checks
The workflow passes when:
- the approved action names the exact input and output paths;
- no package install or network request is hidden inside the command;
- the source CSV remains unchanged;
report.mdcontains only facts traceable to the CSV;- no approval rule remains broader than the task requires.
If something goes wrong
Claude asks for a broad shell command. Decline it and ask for a read-only inspection or a smaller command. A command that includes curl, package installation, recursive deletion, or an unrelated directory needs separate review.
A permanent approval was saved by mistake. Open /permissions, identify the rule and remove it. The documentation says persistent Bash or web rules can be stored in repository settings, so check the repository settings file before sharing the folder.
Claude edits the wrong file. Stop the session, preserve the original input, and inspect the diff or file list before accepting anything else. Do not treat a successful command as proof that the output is correct.
Limits and privacy
Use a disposable folder and fictional data while learning. Do not paste credentials, customer records, or production paths into this exercise. Permission approval controls whether an action may run. It does not prove that the action is correct or safe for your business process.
Sources
This guide is documentation-based. No Claude Code execution, personal test, benchmark, or customer result is claimed.