[{"data":1,"prerenderedAt":466},["ShallowReactive",2],{"navigation_docs":3,"-concepts-permission-gate":270,"-concepts-permission-gate-surround":461},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":48,"body":272,"description":454,"extension":455,"links":456,"meta":457,"navigation":458,"path":49,"seo":459,"stem":50,"__hash__":460},"docs\u002F2.concepts\u002F4.permission-gate.md",{"type":273,"value":274,"toc":443},"minimark",[275,283,288,291,295,315,319,322,343,349,359,375,379,390,394,409,413,425,429],[276,277,278,279,282],"p",{},"A Kraft worker runs with nobody watching, so a permission prompt has nobody to\nanswer it. This page explains why Kraft answers those prompts itself, and why\nit does that differently for each harness. For what the gate does and how to\nconfigure it, see ",[280,281,202],"a",{"href":203},".",[284,285,287],"h2",{"id":286},"the-problem-with-an-unattended-prompt","The problem with an unattended prompt",[276,289,290],{},"Left to a harness's own judgment, an unattended agent does one of two things.\nIt stalls on a tool it is unsure about, or it runs the tool anyway because\nnobody is watching. Neither is acceptable when you want to know what a worker\nwas allowed to do.",[284,292,294],{"id":293},"the-third-option","The third option",[276,296,297,298,302,303,306,307,310,311,314],{},"Kraft's permission gate is a third option. The worker asks Kraft, Kraft\nanswers from the task's own policy, and the answer, allow or deny and why,\nlands on the work item's timeline. You do not have to watch a session to know\nwhat it was let do. The policy comes from ",[299,300,301],"code",{},"allowed_tools",", ",[299,304,305],{},"deny_tools"," and\n",[299,308,309],{},"grants",", which you set at any layer down from the repository to the task. See\n",[280,312,44],{"href":313},"\u002Fconcepts\u002Fcaps-and-budgets#how-a-policy-resolves"," for how those\nlayers combine.",[284,316,318],{"id":317},"why-it-works-differently-per-harness","Why it works differently per harness",[276,320,321],{},"The gate has to meet each CLI where that CLI offers a hook. The harnesses\ndiffer, so Kraft uses the strongest mechanism each one has.",[276,323,324,328,329,331,332,335,336,338,339,342],{},[325,326,327],"strong",{},"Claude Code"," settles most tool calls itself with its own classifier, such as\na read-only shell command or a routine edit. What it will not settle, it hands\nto a permission prompt tool. Kraft points that at its own tool, so the CLI\ncalls into Kraft instead of prompting a human who is not there. Whether the\ngate is reachable, and how much reaches it, follows from the permission mode.\nWith no ",[299,330,301],{},", Claude runs in ",[299,333,334],{},"auto",", and the gate sees only what the\nclassifier declines to settle. With an ",[299,337,301],{}," list, Claude switches to\n",[299,340,341],{},"manual",", and every call the built-in allowlist does not cover reaches the\ngate. That is what makes the gate worth configuring.",[276,344,345,348],{},[325,346,347],{},"Cursor and Codex"," have no prompt tool, but each runs a hook before every\ntool call. Kraft installs a hook that asks the same gate. Kraft scopes the\nhook to the launch: Cursor's is written into the worktree and kept out of your\ncommits, and Codex's is passed per launch and trusted by hash, never by\nbypassing Codex's hook trust, since that would trust every hook a repository\nships.",[276,350,351,354,355,358],{},[325,352,353],{},"Gemini"," runs with ",[299,356,357],{},"--approval-mode yolo",", so its calls never reach the gate.",[276,360,361,364,365,367,368,370,371,374],{},[325,362,363],{},"OpenCode and Amp"," offer no reliable per-call hook. Kraft writes the task's\n",[299,366,305],{}," and ",[299,369,301],{}," into the CLI's own permission configuration\nfor that one launch, and the CLI enforces them itself. The trade-off is that\nthese calls never reach the gate, so they leave no ",[299,372,373],{},"permission_decision"," on\nthe timeline.",[284,376,378],{"id":377},"why-a-deny-is-final-but-an-allow-may-not-be","Why a deny is final but an allow may not be",[276,380,381,382,385,386,389],{},"Kraft can only decide; the CLI still runs the call. A deny is a deny on every\nharness. An allow is the gate's decision, and on Cursor it does not override\nthe CLI's own ",[299,383,384],{},"--auto-review"," classifier, so a call the gate allows can still\nbe refused. This is why ",[280,387,309],{"href":388},"\u002Freference\u002Fpermissions#grants"," are described\nas the gate's decision and not a guarantee that a command will run.",[284,391,393],{"id":392},"why-grants-are-names-not-command-patterns","Why grants are names, not command patterns",[276,395,396,397,400,401,404,405,408],{},"A grant such as ",[299,398,399],{},"git-push"," is a named operation, not a pattern like\n",[299,402,403],{},"git push *",". A pattern also matches ",[299,406,407],{},"git push x; rm -rf y",". Kraft's grant\nmatcher accepts only a call that is exactly one plain git invocation of the\ngranted subcommand, and refuses anything that could run something else. That\nis also why grants are not written into OpenCode's or Amp's rules, where only a\npattern is available.",[284,410,412],{"id":411},"why-an-escalation-gets-git-grants-by-default","Why an escalation gets git grants by default",[276,414,415,416,302,419,367,422,424],{},"An escalation turn holds ",[299,417,418],{},"git-commit",[299,420,421],{},"git-rebase",[299,423,399],{}," unless you\nnarrow it, because an escalation that rebased the branch has to push it. A\ngate's reviewer gets no such default.",[284,426,428],{"id":427},"related","Related",[430,431,432,438],"ul",{},[433,434,435,437],"li",{},[280,436,202],{"href":203}," covers what the gate does per\nharness and how to configure it.",[433,439,440,442],{},[280,441,206],{"href":213},"\nshows how each harness runs unattended.",{"title":444,"searchDepth":445,"depth":445,"links":446},"",2,[447,448,449,450,451,452,453],{"id":286,"depth":445,"text":287},{"id":293,"depth":445,"text":294},{"id":317,"depth":445,"text":318},{"id":377,"depth":445,"text":378},{"id":392,"depth":445,"text":393},{"id":411,"depth":445,"text":412},{"id":427,"depth":445,"text":428},"Why Kraft answers a worker's permission prompts itself, and how each harness lets it.","md",null,{},true,{"title":48,"description":454},"npLU8z-i8ydnXfnXukhOnzTP7iMKO0CechT9-tqvWLA",[462,464],{"title":44,"path":45,"stem":46,"description":463,"children":-1},"How Kraft bounds time, tokens, and dollars, and how a policy resolves from policy.yaml down to a single task.",{"title":10,"path":53,"stem":57,"description":465,"children":-1},"Task-focused how-tos for driving, extending, and reaching Kraft.",1790824539857]