DocsConfigure
Tool access
The four access modes (Full, Ask first, Ask always, Read only) and per-tool behaviour.
Set per agent in Settings → the agent → Tool access, or per task in the new-task box. Projects used by voice have their own setting; see Projects.
| Mode | The agent… |
|---|---|
| Full (Trust all), the default | Never asks. Edits, runs commands and goes online on its own. |
| Ask first | Asks before commands, deletes, moves, the network, and anything outside the folder. |
| Ask always | Asks before every change and every command. |
| Read only | Reads and searches. Changes nothing; Hover refuses its writes. |
Per-tool notes
- Codex: Ask first uses its
workspace-writemode: it asks to write outside the folder or go online, and its own sandbox decides the rest. Read only isn’t offered for Codex. - Cursor: Hover never passes
--force, so Cursor asks on its own; Full is Hover answering yes. Cursor’s own “allow always” writes a lasting rule into~/.cursor/cli-config.json, which is why Hover’s Trust doesn’t use it. - Trust is Hover’s, for the rest of the session. Only for Codex does Hover also pick the tool’s own allow-always, since that lasts only the session too.
- Kiro Web: every task has full access, so the new-task box and voice’s card show no access pick for it.