Auto Mode
A second model, the classifier, reviews Claude actions before they run, in place of manual confirmations. It blocks anything that goes beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read. Tool results are stripped from what it sees, so a booby-trapped page or file cannot manipulate it directly. Enabled via `--permission-mode auto` or Shift+Tab, and the default starting mode on Pro, Max and Team plans.
Strengths
- Zero interruption for safe actions, smooth workflow without repeated confirmations
- Blocks actions that overstep your request or look driven by hostile content read along the way
- Instant activation, Shift+Tab toggles between modes without restarting Claude
Limitations
- Less granular control, less suitable if you want to approve every action
- Requires trust in the classifier, false positives exist
Best for
- Intensive development sessions where repeated confirmations break focus
- Experienced users who understand what Claude does and trust its judgment