Permissions
Each member is its own Claude Code session and asks for its own permissions. A message from your orchestrator never counts as your consent there. To grant something to every member, tell your orchestrator (“allow the members to run npm test”), which runs cadrei allow:
cadrei allow add 'Bash(git push origin HEAD:main)' # an exact commandcadrei allow add --once 'Bash(npm publish)' # for one task; removed afterwardscadrei allow add --auto "Merging a reviewed branch into main in my projects is expected"cadrei allow list # numbered, with kind, once and wildcard markscadrei allow remove 'Bash(npm publish)' # by its exact text, or its list numbercadrei allow remove --once # every one-time grant- A rule is a Claude Code permission rule: a tool name with an optional specifier, such as
Bash(npm test),Read(./docs/**)ormcp__github__create_issue. --autoadds a sentence (one line, at most 300 characters, plain ASCII letters) to the auto-mode classifier’s allow list, after"$defaults", so the built-in rules stay. Describe the work that’s expected; a sentence about permissions, settings or grants, or one claiming your approval, is refused.- Refused: blanket rules (
*, a bareBash,Edit,Write,Read,WebFetch,NotebookEditorPowerShell, a specifier that’s only a wildcard), whole MCP servers, wildcards in the program name, shells, interpreters and wrappers with a wildcard, programs that run whatever follows a subcommand (docker run,npm exec,go runand the like) with a wildcard, chained or backgrounded commands, commands built with shell syntax,WebFetchfor every domain,EditandReadpaths that climb with.., startup files and files that run code outside a session (shell and git config,~/.ssh, launch agents,~/.local/binand the like), and anything that reaches cadrei’s own files: the grants file,cadrei allow,cadrei.conf,~/.cadrei/config. ForEditandReadrules, paths are read the way Claude Code reads them, so glob classes, escapes and braces can’t hide a refused file.Bashrules are checked word by word: cadrei reads the paths, variables such as$CADREI_HOMEand..climbs in them, but it can’t see where a link on disk leads, so a shell rule is a weaker guard than anEditrule. The full tables are ininternal/runtime/claude/allow. - Warned: other wildcards,
gitwith a wildcard (it can run other programs),make,npm run,pip installand./scriptwith a wildcard (they run code from files a member can change), andReadrules that reach secrets such as~/.sshor~/.aws. Accepted wildcards are marked inlist. - Every change is committed in your crew (
git log -- .claude/is the record) and travels with it. One-time grants are listed in.claude/member-settings.oncewith the time they were added. When some are left over, your orchestrator offers to remove them. - Members can’t add or remove grants.
- A running member keeps the grants it started with.
cadrei allowlists the members to restart; a restart picks up the same chat.
The grants file
Section titled “The grants file”Every member starts with the grants in .claude/member-settings.json, a Claude Code settings file. Members never get the file itself: before each start, cadrei validates it and writes a read-only copy to .claude/build/. The file may hold only permissions.allow and deny and autoMode.allow and soft_deny, with no duplicate keys, "$defaults" in every autoMode list, and the fixed entries. A file that breaks these rules gives members a copy with no grants, and a warning.
Every copy also gets fixed entries that keep members off cadrei’s own files: Edit denies for ~/.cadrei/config, ~/.cadrei/framework, and each crew’s .claude (which holds local/ and build/), cadrei.conf, members, playbook.md, protocol.md, projects.yaml, .git, CLAUDE.md, CLAUDE.local.md and .mcp.json; Read and Edit denies for ~/.cadrei-archive; denies for cadrei allow, cadrei new (and its old name cadrei init) and cadrei use; and a soft_deny line telling the auto-mode classifier that only you change these, through your orchestrator. Team folders stay writable.
A fingerprint in ~/.cadrei/config/member-settings.sha256 flags a file changed outside cadrei allow. A change that arrives as a commit cadrei allow made (for example pulled from another machine) is accepted. If the fingerprint is gone, cadrei checks the file against its last commit instead. To undo a hand edit, run git -C ~/.cadrei/<name> checkout -- .claude/member-settings.json.