DocsConfigure

Tool access

The four access modes (Full, Ask first, Ask always, Read only) and per-tool behaviour.

Set per agent in Settings → the agent → Tool access, or per task in the new-task box. Projects used by voice have their own setting; see Projects.

ModeThe agent…
Full (Trust all), the defaultNever asks. Edits, runs commands and goes online on its own.
Ask firstAsks before commands, deletes, moves, the network, and anything outside the folder.
Ask alwaysAsks before every change and every command.
Read onlyReads and searches. Changes nothing; Hover refuses its writes.

Per-tool notes

  • Codex: Ask first uses its workspace-write mode: it asks to write outside the folder or go online, and its own sandbox decides the rest. Read only isn’t offered for Codex.
  • Cursor: Hover never passes --force, so Cursor asks on its own; Full is Hover answering yes. Cursor’s own “allow always” writes a lasting rule into ~/.cursor/cli-config.json, which is why Hover’s Trust doesn’t use it.
  • Trust is Hover’s, for the rest of the session. Only for Codex does Hover also pick the tool’s own allow-always, since that lasts only the session too.
  • Kiro Web: every task has full access, so the new-task box and voice’s card show no access pick for it.
Last updated October 6, 2026. Something missing or wrong?Open an issue