Permission lists
Permission state is a set of persisted lists, each overridable per board. Manage them in Settings > Security: Command permissions for shell commands and Tool & MCP permissions for tools. Why the gate exists is in The permission gate.
| List | What it holds |
|---|---|
| Tool allow-list | Tool names allowed with Always allow this tool (or Always allow all of an MCP server’s tools), so future runs never ask for them again. mcp__<name>__* covers a whole MCP server. |
| Command allow-list | Shell command prefixes allowed for Bash, such as uv run or git status: what Always allow this command and Always allow all of a command family add. |
| Deny-lists (tool and command) | Patterns and prefixes the agent may never use, such as git push. A ban is absolute and overrides the allow-list. |
| Ask-lists (tool and command) | Patterns and prefixes that are always routed to a human, even when otherwise allow-listed. |
Together they give every command and tool a level, which the Settings UI shows directly: deny beats ask beats allow.
Per board overrides
Section titled “Per board overrides”A board can replace a list for its own tickets. Open the board menu in the header, choose Board settings…, and find Per-board permissions. Each group (Command permissions and Tool & MCP permissions) shows Inherited and how many global rules apply; click Override for this board to start from a copy of the global rules and edit it, then Save. Inherit drops the override again.
An override replaces the global list for tickets on that board: the two are never merged, so a rule you remove there no longer applies on that board even though it stays in Settings > Security. A group is overridden as a whole (its allow, ask and deny levels together). The built-in baseline is global only.
The built-in baseline
Section titled “The built-in baseline”Under the lists sits a built-in safe baseline of everyday commands (uv, pytest,
ruff, git status, git diff, npm, …), shown as Built-in safe baseline in
Settings > Security. REV0_ALLOWED_CMD_PREFIXES replaces it with a JSON array; a value
saved in Settings wins over both.
Command policy
Section titled “Command policy”REV0_CMD_POLICY decides what a command on none of the lists does:
| Policy | Behaviour |
|---|---|
safe (default) | Any command that is not flagged dangerous runs; only dangerous ones ask. |
allowlist | Only allow-listed commands run; everything else asks. |
Dangerous command detection is built in: recursive deletion, sudo, git push,
git reset --hard, a download piped into a shell, writes into system directories, and
more. REV0_DANGEROUS_CMD_PATTERNS replaces the
patterns with a JSON array, and REV0_DANGEROUS_CMD_DISABLE=1 turns detection off, which
is not recommended. See Configuration.