Chapter 5. Permissions, Safety, and Trust Boundaries
Chapter 4 changed the shape of the lyrics-trainer. The app was still small, but the work was no longer casual. State, tests, project memory, and context management turned a doghouse into a cabin.
This chapter is about the question that comes next. Before Claude Code changes something that matters, what is it allowed to do?
Permissions sound like an administrative detail, the sort of thing you configure once and forget. In agentic work they turn out to be part of the design. They determine which parts of the system Claude Code can inspect, which parts it can change, which commands it can run, which services it can contact, and when it has to stop and ask you first.
The default answer in Claude Code is conservative. Reading files and exploring the project are low-friction, while editing files, running shell commands, and reaching out to external systems all require permission unless you’ve granted it ahead of time. That friction is useful, because it slows down the exact moment ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access