Skip to content

Permissions

Each member is its own Claude Code session and asks for its own permissions. A message from your orchestrator never counts as your consent there. To grant something to every member, tell your orchestrator (“allow the members to run npm test”), which runs cadrei allow:

Terminal window
cadrei allow add 'Bash(git push origin HEAD:main)' # an exact command
cadrei allow add --once 'Bash(npm publish)' # for one task; removed afterwards
cadrei allow add --auto "Merging a reviewed branch into main in my projects is expected"
cadrei allow list # numbered, with kind, once and wildcard marks
cadrei allow remove 'Bash(npm publish)' # by its exact text, or its list number
cadrei allow remove --once # every one-time grant
  • A rule is a Claude Code permission rule: a tool name with an optional specifier, such as Bash(npm test), Read(./docs/**) or mcp__github__create_issue.
  • --auto adds a sentence (one line, at most 300 characters, plain ASCII letters) to the auto-mode classifier’s allow list, after "$defaults", so the built-in rules stay. Describe the work that’s expected; a sentence about permissions, settings or grants, or one claiming your approval, is refused.
  • Refused: blanket rules (*, a bare Bash, Edit, Write, Read, WebFetch, NotebookEdit or PowerShell, a specifier that’s only a wildcard), whole MCP servers, wildcards in the program name, shells, interpreters and wrappers with a wildcard, programs that run whatever follows a subcommand (docker run, npm exec, go run and the like) with a wildcard, chained or backgrounded commands, commands built with shell syntax, WebFetch for every domain, Edit and Read paths that climb with .., startup files and files that run code outside a session (shell and git config, ~/.ssh, launch agents, ~/.local/bin and the like), and anything that reaches cadrei’s own files: the grants file, cadrei allow, cadrei.conf, ~/.cadrei/config. For Edit and Read rules, paths are read the way Claude Code reads them, so glob classes, escapes and braces can’t hide a refused file. Bash rules are checked word by word: cadrei reads the paths, variables such as $CADREI_HOME and .. climbs in them, but it can’t see where a link on disk leads, so a shell rule is a weaker guard than an Edit rule. The full tables are in internal/runtime/claude/allow.
  • Warned: other wildcards, git with a wildcard (it can run other programs), make, npm run, pip install and ./script with a wildcard (they run code from files a member can change), and Read rules that reach secrets such as ~/.ssh or ~/.aws. Accepted wildcards are marked in list.
  • Every change is committed in your crew (git log -- .claude/ is the record) and travels with it. One-time grants are listed in .claude/member-settings.once with the time they were added. When some are left over, your orchestrator offers to remove them.
  • Members can’t add or remove grants.
  • A running member keeps the grants it started with. cadrei allow lists the members to restart; a restart picks up the same chat.

Every member starts with the grants in .claude/member-settings.json, a Claude Code settings file. Members never get the file itself: before each start, cadrei validates it and writes a read-only copy to .claude/build/. The file may hold only permissions.allow and deny and autoMode.allow and soft_deny, with no duplicate keys, "$defaults" in every autoMode list, and the fixed entries. A file that breaks these rules gives members a copy with no grants, and a warning.

Every copy also gets fixed entries that keep members off cadrei’s own files: Edit denies for ~/.cadrei/config, ~/.cadrei/framework, and each crew’s .claude (which holds local/ and build/), cadrei.conf, members, playbook.md, protocol.md, projects.yaml, .git, CLAUDE.md, CLAUDE.local.md and .mcp.json; Read and Edit denies for ~/.cadrei-archive; denies for cadrei allow, cadrei new (and its old name cadrei init) and cadrei use; and a soft_deny line telling the auto-mode classifier that only you change these, through your orchestrator. Team folders stay writable.

A fingerprint in ~/.cadrei/config/member-settings.sha256 flags a file changed outside cadrei allow. A change that arrives as a commit cadrei allow made (for example pulled from another machine) is accepted. If the fingerprint is gone, cadrei checks the file against its last commit instead. To undo a hand edit, run git -C ~/.cadrei/<name> checkout -- .claude/member-settings.json.