Skip to main content
executionPolicy is a host-owned gate for validated tool calls. It can allow, request approval, or deny execution. A per-tool approval exemption cannot override it.

Plan mode

RunOpts.runMode is "execute" or "plan". In plan mode, a classified read may run, a write/execute/external effect is denied, and an unknown effect requires review. Supply an approval handler if your policy can return ask; see approval. The host classifies the complete execution, including result transformers. Model arguments and remote annotations do not establish permission. A policy returning an invalid decision fails closed, and reviewed arguments cannot be mutated into a different call before execution. Delegated policy is combined with the Agent’s policy; it cannot relax it. Core Agent, controlled drivers, and supported local voice tools share this boundary. Arbitrary application callbacks and provider-executed remote tools remain outside local interception.