v1.4.0next
Agent harnesses

Unattended runs

The permission mode each harness runs in when no one can answer a prompt.

A worker has nobody to answer a permission prompt, so Kraft runs each CLI in its classifier mode where it has one, and otherwise in its most autonomous unattended mode. What Kraft itself needs from a worker, its result file and its commits, is granted explicitly and never left to a classifier.

HarnessModeClassifier?Notes
claude--permission-mode auto, plus Kraft's MCP permission tool for what the classifier won't settleyes
codexapprove-for-me (-c keys), plus explicit results and .git writable roots, and Kraft's PreToolUse hook, trusted per launch, when the task's policy has something to enforceyesthe hook's deny blocks
cursor--auto-review, plus a per-launch config with commit attribution off, and Kraft's preToolUse hook when the task's policy has something to enforceyesthe hook's deny blocks; its allow doesn't outrank the classifier
opencode--auto, plus the task's tool policy as per-launch config rules (--standalone) when it has anynone in the CLIno permission gate: the rules are enforced by OpenCode, and nothing is logged
ampapproves by default, plus the task's tool policy as a per-launch settings file when it has anynono permission gate: the rules are enforced by Amp, and nothing is logged
gemini--approval-mode yolono

Claude sends the asks its classifier won't settle to Kraft, and Cursor's and Codex's hooks ask Kraft before every call when policy has something to enforce. OpenCode and Amp never ask Kraft: their tool lists are written into their own config at launch. Gemini's calls are not routed to Kraft. See The permission gate for how those asks reach Kraft and how Kraft decides them.

Copyright © 2026