Claude Managed Agents Permissions: always_allow vs always_ask Defaults
Coffee Summary
- FACT: Permission policies govern server-executed tools only (agent toolset + MCP). Custom tools are app-side and not covered.
- FACT: Policies are
always_allow,always_ask, and (as of 10 Sep 2026)auto— server evaluates each call to run, deny, or pause for approval. - FACT: Defaults: agent toolset →
always_allow; MCP toolsets →always_ask(new MCP tools do not auto-run). - FACT: Running sessions keep create-time toolset config; agent updates apply to later sessions only.
- OPINION (AIImpish): Override bash and high-impact MCP for production — do not ship on silent demo defaults.
What happened
Managed Agents docs define permission policies for when pre-built agent tools and MCP tools may execute. Platform release notes for 10 Sep 2026 add auto and document that agent.tool_use / agent.mcp_tool_use events carry evaluated_permission plus an evaluation object. Requests need the managed-agents-2026-04-01 beta header (SDK sets it).
Why it matters
The split between agent toolset default allow and MCP default ask is the difference between a coding agent that can bash freely and an MCP connector that cannot invent side effects without a checkpoint. Mis-set policies are a production incident class: MCP exfil, destructive bash, or alert fatigue from asking on every read.
What changed
Policy types (FACT)
| Policy | Behavior |
|---|---|
always_allow |
Tool runs with no confirmation |
always_ask |
Session pauses until user.tool_confirmation allow/deny |
auto |
Server allows, denies, or asks per call (tool + input + context) |
Disabling a tool removes it; a policy only gates when an enabled tool may run.
Defaults and overrides (FACT)
Set tools[].default_config.permission_policy on create/update. Omit default_config on agent_toolset_20260401 → enabled with always_allow. MCP entries (type: "mcp_toolset", mcp_server_name matching mcp_servers[].name) stay always_ask until you opt into always_allow or auto. Per-tool overrides use configs (e.g., allow the toolset but force bash to always_ask).
auto and confirmations (FACT)
Under auto, a call may run; deny with tool error Permission to use {tool_name} has been denied. (session continues — client cannot override); or pause like always_ask when indeterminate. Docs warn: user.message counts as your intent and can widen allows; tool results, fetched pages, and MCP responses do not. Relayed end-user text in user.message is also treated as your intent. auto is not a human checkpoint for irreversible actions.
On ask: tool-use event → session.status_idle with requires_action → send user.tool_confirmation → session resumes. Confirming a non-ask event returns 400.
Who should care
Platform engineers wiring Managed Agents; security teams defining bash/MCP allowlists; app developers implementing the confirmation loop (or ant beta:sessions connect); anyone attaching third-party MCP servers whose tool lists change.
Limitations
Policies do not cover custom tools. Default always_allow on the agent toolset is demo-friendly and risky for unattended prod. auto denials are final for that call. Intent-via-user.message means prompt injection from end users can widen allows if you forward raw text. Fixing an agent does not retrofit in-flight sessions.
What to do next — production security checklist
1. Inventory agent tools vs each MCP tool list; disable unused tools. 2. Keep MCP at always_ask until trusted; only then consider always_allow or auto. 3. Override bash (and destructive tools) to always_ask even if the toolset default is allow. 4. Use auto for mixed-risk MCP volume; keep human always_ask on irreversible tools. 5. Implement confirmation handling (events or ant beta:sessions connect / --web). 6. Log evaluated_permission + evaluation; tolerate unknown reason_code values. 7. Do not forward untrusted end-user prose into user.message without always_ask on powerful tools. 8. After tightening policies, create a new session to verify. 9. Gate custom tools in your app — Managed Agents policies will not.
AIImpish Take
Remember the default split: agent tools allow, MCP tools ask. The Sep 10 auto policy is a useful middle path, but still machine judgment. Production posture: disable first, ask on bash and write MCP, use auto where volume drowns operators, and treat user.message as a privileged intent channel. Ship the checklist before you ship the agent.
AIImpish