Skip to content
rev0Docs

Permission lists

Permission state is a set of persisted lists, each overridable per board. Manage them in Settings > Security: Command permissions for shell commands and Tool & MCP permissions for tools. Why the gate exists is in The permission gate.

ListWhat it holds
Tool allow-listTool names allowed with Always allow this tool (or Always allow all of an MCP server’s tools), so future runs never ask for them again. mcp__<name>__* covers a whole MCP server.
Command allow-listShell command prefixes allowed for Bash, such as uv run or git status: what Always allow this command and Always allow all of a command family add.
Deny-lists (tool and command)Patterns and prefixes the agent may never use, such as git push. A ban is absolute and overrides the allow-list.
Ask-lists (tool and command)Patterns and prefixes that are always routed to a human, even when otherwise allow-listed.

Together they give every command and tool a level, which the Settings UI shows directly: deny beats ask beats allow.

A board can replace a list for its own tickets. Open the board menu in the header, choose Board settings…, and find Per-board permissions. Each group (Command permissions and Tool & MCP permissions) shows Inherited and how many global rules apply; click Override for this board to start from a copy of the global rules and edit it, then Save. Inherit drops the override again.

An override replaces the global list for tickets on that board: the two are never merged, so a rule you remove there no longer applies on that board even though it stays in Settings > Security. A group is overridden as a whole (its allow, ask and deny levels together). The built-in baseline is global only.

Under the lists sits a built-in safe baseline of everyday commands (uv, pytest, ruff, git status, git diff, npm, …), shown as Built-in safe baseline in Settings > Security. REV0_ALLOWED_CMD_PREFIXES replaces it with a JSON array; a value saved in Settings wins over both.

REV0_CMD_POLICY decides what a command on none of the lists does:

PolicyBehaviour
safe (default)Any command that is not flagged dangerous runs; only dangerous ones ask.
allowlistOnly allow-listed commands run; everything else asks.

Dangerous command detection is built in: recursive deletion, sudo, git push, git reset --hard, a download piped into a shell, writes into system directories, and more. REV0_DANGEROUS_CMD_PATTERNS replaces the patterns with a JSON array, and REV0_DANGEROUS_CMD_DISABLE=1 turns detection off, which is not recommended. See Configuration.