A dialog appears in the chat. You skim it. You click a button. Done.
For most of them, that’s fine — you don’t read every yield sign you drive past either. But you do need to know what each part of the dialog means, because one of the buttons is louder than it looks.
This whole behavior is a mode Claude Desktop calls Ask permissions — the one the docs recommend for new users. It’s on by default, and it’s the safe place to live while you build judgment. (Next lesson we’ll look at the other modes; for now, stay in this one.)
What the modal shows you
When Claude wants to act, the Ask permissions modal lays out three things:
- What — the exact change Claude wants to make, or the exact command it wants to run. For a file edit you’ll see the diff (you learned to read those in Lesson 4.2); for a command you’ll see the command itself.
- Where — which file, which folder. “Delete a file in a scratch folder” is a completely different action than “delete a file in your Documents.” The location is part of the action.
- A label — a plain one-line summary, like “Claude wants to edit
report.md” or “Claude wants to run a command.”
Read it in that order: what it is, where it’s pointed. The second one catches more mistakes than the first. Claude is usually right about the kind of action; the folder is what slips.
Your three choices aren’t equal
The modal gives you, roughly:
- Approve once — allow this exact thing, this one time.
- Always allow — never ask again about actions like this one.
- Decline — say no, and tell Claude what to do differently.
The middle one is the loud one, and people misread it constantly. It’s not “yes for the next ten minutes.” It’s not “yes for this chat.” It’s a persistent setting — the same kind your phone uses when an app asks for camera access. You’re not approving the action. You’re handing that kind of action a permanent door key.
“Always allow” is a one-way door. Use it for the things you’d do yourself without thinking, never for the things you’d want to read twice.
A good test
Before clicking Always allow, ask: if I were doing this myself, would I do it without a second look? Listing files, reading a document — sure. Anything that deletes, sends, pushes, or reaches out to the network — no. You can always loosen later. You can’t easily take back a key you’ve handed out.
Try it
Below is the same approve/decline decision Claude Desktop puts in front of you, four times. For each one, decide whether you’d approve or decline — then see the verdict and how far that action could have reached.
What’s next
You can read the modal now. But “should I approve this?” still depends on something we haven’t named: how far the action can actually reach. That’s the next word — blast radius.