Approval settings control when Embedder asks before an action. They are separate from agent modes, which control the actions available to the session.
Choose an approval mode
Use the control beside the chat input:
- Always ask (
/always-confirm): ask before ordinary actions, including reads.
- Manually approve (
/manual-confirm): allow ordinary reads and approved commands; ask before other actions. This is the default.
- Skip all approvals (
/auto-confirm): skip ordinary confirmation prompts.
Skip all approvals lets actions proceed without routine confirmation. It does not override Plan mode, protected files, or actions that require explicit consent. Enable it only for work whose scope you understand.
Respond to a request
Review the action and affected files or hardware:
- Allow once permits this action.
- Allow always permits matching actions for the rest of the session, when offered.
- Reject cancels the request and other pending confirmations in the session.
In VS Code, use Y, A, or N when the confirmation is focused. A session grant does not automatically become a rule for future sessions.
Manage persistent rules
In VS Code, choose Manually approve, then run /approvals to open What runs without asking:
- On the Commands tab, add a command prefix under Your rules, or remove an existing entry with its × button. Expand a built-in command group to turn individual command approvals on or off.
- On the Paths tab, add any required SDK or toolchain directory under Allowed outside the project. Allowing a directory does not also approve commands that use it.
- Enter a command under Would this ask? to check the resulting rules without executing it.
Use this panel to change personal rules. Do not use ~/.embedder/approvals.json to manage existing personal rules. In the terminal UI, /approvals shows an overview; editing and command testing are available in VS Code.
The tester checks the selected approval mode and persistent command/path rules. It does not account for earlier Allow always grants. Changing a persistent rule does not revoke those session grants; choose Always ask for further confirmations, or start a new conversation to work without the old session grants.
Use narrow command prefixes. west build does not include west flash, while west includes both. Each entry must be one command prefix without shell operators or substitutions.
Review project requests
A repository’s .embedder/approvals.json can restrict automatic approvals, but it cannot grant itself new permissions. For example:
autoApprove requests permission for matching commands to run without asking in Manual mode.
allowOutsideProject requests permission to use specific external directories, such as an SDK installation. The command itself must still be allowed.
neverAutoApprove removes matching commands from automatic command approval, including commands otherwise allowed. Approval modes and existing session grants still apply.
useBuiltinSafeCommands: false disables built-in command approvals for this project. Setting it to true does not override a personal setting that disables them.
In VS Code, open /approvals and use Add to mine to accept a project command or path request into your personal rules.
If the project file is invalid, inspect the Files tab and correct it before relying on its rules.
Keep the task specific
An approved executable does not identify which board to flash or which files to change. State the target and intended result in your request, particularly when several devices or projects are open.
Use .embedderignore to protect selected files from direct agent edits. Last modified on September 18, 2026