The agent asked for confirmation for the twentieth time to run npm run test, and you started hitting Enter without reading. That is exactly when a wrong rm slips through. The fix is not to turn off every confirmation. It is to tell Verboo Code, rule by rule, what it can do on its own, what it has to ask about, and what it can never do. You do that with /permissions, and this guide shows the commands, the rule syntax, and where each rule is saved.
What does /permissions do in Verboo Code?
It opens a panel to create, view, and delete permission rules for the agent's tools. Each rule says whether a tool (or one specific command of it) is allowed without asking, always asked about, or always refused.
The command also answers to the alias /allowed-tools. The panel has five tabs:
| Tab | What it does |
|---|---|
| Recently denied | Lists commands recently denied by the auto mode classifier, with the option to approve or retry |
| Allow | Verboo Code won't ask before using these tools |
| Ask | Verboo Code always asks for confirmation before using these tools |
| Deny | Verboo Code always refuses to use these tools |
| Workspace | Extra directories, outside the project, the agent can access |
How do you write a permission rule?
A rule is the tool name, optionally followed by a specifier in parentheses. Without parentheses, the rule covers the whole tool.
| Rule | What it matches |
|---|---|
WebFetch | Any use of the WebFetch tool |
Bash | Any terminal command |
Bash(npm run test:*) | Any command starting with npm run test |
Bash(git status) | Exactly the command git status |
Read(**/.env) | Reading any .env file, in any folder |
WebFetch(domain:docs.python.org) | WebFetch requests to that domain |
The trailing :* is what turns a Bash rule into a prefix; the panel describes it as "Any Bash command starting with". Without it, the rule matches only the exact command. In file rules, such as Read and Edit, the specifier follows .gitignore patterns, so ** crosses folders.
If the command has parentheses, escape them with a backslash: Bash(python -c "print\(1\)").
How do you allow a command so the agent stops asking?
Open the panel, go to the Allow tab, choose Add a new rule… and type the rule:
/permissions
# Allow tab → Add a new rule… →
Bash(npm run test:*)
After you type the rule, Verboo Code asks where to save it. There are three destinations:
| Option in the panel | File | When to use |
|---|---|---|
| Project settings (local) | .verboo/settings.local.json | Just you, just this project |
| Project settings | .verboo/settings.json | The whole team, checked into git |
| User settings | ~/.verboo/settings.json | You, in every project |
The rule can also go straight into the file, without opening the panel. The format is:
{
"permissions": {
"allow": [
"Bash(npm run test:*)",
"Bash(npm run lint:*)",
"Bash(git status)",
"Bash(git diff:*)"
],
"ask": [
"Bash(git push:*)"
],
"deny": [
"Read(**/.env)",
"Bash(rm -rf:*)"
]
}
}
A short allow list for the commands you always approve (tests, lint, git reads) already removes most confirmations without giving up anything dangerous.
How do you block a file or command for good?
Put the rule in the Deny tab. Deny is an automatic refusal: the agent gets the rejection and never gets to ask you.
/permissions
# Deny tab → Add a new rule… →
Read(**/.env)
A Read rule covers the file reading tool. If you want a second layer at the operating system level, combine the rules with Verboo Code's sandbox, which isolates terminal commands.
A rule that comes from company-managed configuration (managed settings) shows up in the panel with a notice that it cannot be modified. In that case, only the administrator can change it.
Why doesn't my allow rule work?
Almost always because a deny or ask rule matches the same command. Verboo Code evaluates in this order: deny first, then ask, and only then allow. An allow never beats a deny.
Three things to check:
- Rules from every file are counted. A deny in
~/.verboo/settings.jsonblocks even if the project's.verboo/settings.jsonallows it. - Deny holds even with
--dangerously-skip-permissions. In the code, the deny check runs before the permission mode check, so not even the mode that skips confirmations overrides it. - A prefix without
:*is an exact command.Bash(npm run test)does not allownpm run test -- --watch.
The panel shows which file each rule comes from when you select it in the list, which settles most cases in seconds.
Can you pass permissions on the command line?
Yes, useful for a one-off session or for CI. The flags take a comma or space separated list:
verboo --allowedTools "Bash(git:*) Edit" --disallowedTools "Bash(git push:*)"
To change the overall behavior, not just individual rules, use --permission-mode. The available modes are default, plan, acceptEdits, bypassPermissions and dontAsk. The same value can be set in settings:
{
"permissions": {
"defaultMode": "acceptEdits"
}
}
How do you allow access to a folder outside the project?
In the Workspace tab of /permissions, add the directory. Verboo Code asks whether it applies only to the session or should be saved to the project's local settings. In the file, the key is additionalDirectories:
{
"permissions": {
"additionalDirectories": ["../shared-lib"]
}
}
With the right rules, the agent runs tests and lint back to back without calling you, and each extra attempt doesn't cost more: Verboo Code runs with unlimited tokens.



