Skip to main content
ZeroTwo uses permission modes, sandboxing, and approval prompts to control what agents can do on your machine. Use these controls instead of a separate CLI rules language.

Permission modes

In the ZeroTwo desktop app, choose how much access ZeroTwo has by default:
  • Workspace access — read and edit files in the active project or Cowork folder
  • Auto-review — ZeroTwo can automatically review requests for additional access
  • Full access — edit files more broadly and run networked commands with fewer prompts (use carefully)
See Permission modes and Permissions for details.

Sandboxing

Command execution and file tools run inside ZeroTwo’s sandbox model. Escalations that leave the sandbox prompt for approval unless your settings allow them.

Approvals during a run

When ZeroTwo needs something outside the current policy — network, a path outside the workspace, or a sensitive command — it asks before continuing. You can approve once, allow for the session, or deny. Smart / auto-review settings can reduce repeated prompts for similar safe requests. Review suggested escalations carefully.

Project instructions vs permissions

Windows

On Windows, also see Windows sandbox and WSL.