# Tool access

Set per agent in **Settings → the agent → Tool access**, or per task in the new-task box. Projects used by voice have their own setting; see [Projects](https://tryhover.co/docs/projects.md).

| Mode | The agent… |
| --- | --- |
| **Full** (Trust all), the default | Never asks. Edits, runs commands and goes online on its own. |
| **Ask first** | Asks before commands, deletes, moves, the network, and anything outside the folder. |
| **Ask always** | Asks before every change and every command. |
| **Read only** | Reads and searches. Changes nothing; Hover refuses its writes. |

## Per-tool notes

- **Codex**: Ask first uses its `workspace-write` mode: it asks to write outside the folder or go online, and its own sandbox decides the rest. Read only isn't offered for Codex.
- **Cursor**: Hover never passes `--force`, so Cursor asks on its own; Full is Hover answering yes. Cursor's own "allow always" writes a lasting rule into `~/.cursor/cli-config.json`, which is why Hover's Trust doesn't use it.
- **Trust** is Hover's, for the rest of the session. Only for Codex does Hover also pick the tool's own allow-always, since that lasts only the session too.
- **Kiro Web**: every task has full access, so the new-task box and voice's card show no access pick for it.

---

Part of the [Hover docs](https://tryhover.co/docs.md) (Configure). HTML version: https://tryhover.co/docs/access. Index for agents: https://tryhover.co/llms.txt