Agent harnesses
Unattended runs
The permission mode each harness runs in when no one can answer a prompt.
A worker has nobody to answer a permission prompt, so Kraft runs each CLI in its classifier mode where it has one, and otherwise in its most autonomous unattended mode. What Kraft itself needs from a worker, its result file and its commits, is granted explicitly and never left to a classifier.
| Harness | Mode | Classifier? | Notes |
|---|---|---|---|
| claude | --permission-mode auto, plus Kraft's MCP permission tool for what the classifier won't settle | yes | |
| codex | approve-for-me (-c keys), plus explicit results and .git writable roots, and Kraft's PreToolUse hook, trusted per launch, when the task's policy has something to enforce | yes | the hook's deny blocks |
| cursor | --auto-review, plus a per-launch config with commit attribution off, and Kraft's preToolUse hook when the task's policy has something to enforce | yes | the hook's deny blocks; its allow doesn't outrank the classifier |
| opencode | --auto, plus the task's tool policy as per-launch config rules (--standalone) when it has any | none in the CLI | no permission gate: the rules are enforced by OpenCode, and nothing is logged |
| amp | approves by default, plus the task's tool policy as a per-launch settings file when it has any | no | no permission gate: the rules are enforced by Amp, and nothing is logged |
| gemini | --approval-mode yolo | no |
Claude sends the asks its classifier won't settle to Kraft, and Cursor's and Codex's hooks ask Kraft before every call when policy has something to enforce. OpenCode and Amp never ask Kraft: their tool lists are written into their own config at launch. Gemini's calls are not routed to Kraft. See The permission gate for how those asks reach Kraft and how Kraft decides them.