Execution modes
Each project has an execution mode. The default is automatic; you can change it in project settings. A change takes effect on the next run. Runs already in progress keep the old mode.
automatic (default) | protected | |
|---|---|---|
| CLI settings and tools | Uses your CLI's own settings and tools, plus Howse's tools | Limited to Howse's rules and tools. Your CLI settings and hooks aren't carried over. |
| Permissions | Codex runs with full access and no approval prompts, and Claude Code skips permission checks. Other CLIs also run without approval prompts. | Agents can write only to the project and linked folders, and Howse's metadata is protected. |
| Keep in mind | Doesn't guarantee that agents stay inside the project or leave .howse files alone | Won't start if Howse can't confirm the required protections |
In both modes:
- Running in automatic mode doesn't give an agent permission to commit, push, or send anything off your machine unless you asked for it.
- You approve and answer only in the app window. An agent can't approve anything on your behalf.
- These modes are distinctions inside Howse, not a security barrier against other code running under the same operating system user.
protectedis available only on macOS for now, and only with Codex CLI and Claude Code CLI. On Windows, or with other CLIs, aprotectedproject won't start runs. Useautomaticinstead.