Claude Code Auto Mode: Stop Babysitting Your AI
Anthropic's new auto mode lets Claude Code decide which actions are safe to run without asking — no more approving every file write. Here's how it works and who gets it.
In this article

Anthropic launched <strong>Auto Mode</strong> for Claude Code — a permissions mode that lets Claude decide which actions are safe to take on its own, without pausing to ask you every time. It's now available for Team, Enterprise, and API plan users.
The Problem It Solves
If you've spent any time with Claude Code on a large task, you know the friction: every file write, every bash command, every tool call triggers an approval prompt. It's intentional — Anthropic built Claude Code to be conservative by default — but it makes autonomous, long-running tasks impossible without sitting there clicking approve every 30 seconds.
The existing workaround is --dangerously-skip-permissions, which hands complete control to the model with zero safety checks. As the flag name suggests, that's a gamble. Mass-deleting files, exfiltrating data, running malicious code — all theoretically possible if something goes sideways.
Auto mode is the middle path Anthropic has been building toward: Claude runs long tasks autonomously, but a classifier reviews every action before it executes.
How Auto Mode Works
Before each tool call runs, a built-in classifier evaluates the action. If it looks safe, it proceeds automatically — no prompt, no interruption. If the classifier flags it as potentially destructive, it's blocked and Claude is redirected to find a different approach. If Claude repeatedly hits blocks and can't make progress, it eventually escalates to a human permission prompt.
This means you can kick off a complex multi-step task and walk away. Claude will handle the routine actions autonomously and surface only the genuinely ambiguous or risky ones.
What the Classifier Blocks
Anthropic has published the classifier's default block list in their docs. It targets three categories of risk:
- Destructive actions — mass file deletion, overwriting critical system files
- Sensitive data exfiltration — sending data to unexpected external endpoints
- Malicious code execution — running commands that look like privilege escalation or injection attacks
- Prompt injection — detecting when malicious instructions are hidden in content Claude is processing
Anthropic is upfront about the limits: the classifier may still allow some risky actions if user intent is ambiguous, and it may occasionally block benign ones. It's not a guarantee — it's a meaningful reduction in risk over bare --dangerously-skip-permissions.
Auto Mode vs. --dangerously-skip-permissions
The honest comparison:
- --dangerously-skip-permissions: Zero friction, zero safety net. Claude runs everything unchecked. Fast, but you're accepting full risk. Only appropriate in air-gapped sandboxes.
- Auto mode: Near-zero friction, with a classifier catching the most dangerous actions. Some latency overhead per tool call. Recommended for isolated (but not fully air-gapped) environments.
- Default mode: Maximum safety, maximum interruption. Right for production environments or when you need full oversight of every action.
Anthropic still recommends using auto mode in isolated environments — sandboxes, containers, VMs — rather than directly on a production machine or codebase. The classifier reduces risk, but doesn't eliminate it.
How to Enable It
From the CLI, run claude --enable-auto-mode to enable it, then cycle to it with Shift+Tab to switch between permission modes mid-session.
In the VS Code extension or Claude Desktop app: Settings → Claude Code → toggle Auto Mode on, then select it from the permission mode dropdown in a session.
For Enterprise admins: auto mode is now available to all Claude Code users on Team, Enterprise, and API plans. To disable it org-wide, set "disableAutoMode": "disable" in your managed settings. Auto mode is disabled by default on the Claude desktop app until you toggle it on.
Availability
- ✅ Team plan — available now
- ✅ Enterprise plan — available now
- ✅ API users — available now
- ✅ Models supported: Claude Sonnet 4.6 and Opus 4.6 and later
The Bottom Line
Auto mode is the right choice if you want to run Claude Code autonomously but still have guardrails in place. For long, multi-step tasks, it cuts the interruption overhead by 80-90% while maintaining meaningful safety checks.
Get the Claude playbook in your inbox.
One weekly email for Claude and Claude Code users. Real workflows, no hype. Subscribe and we send you The Claude Power-User Cheatsheet.
— ¶ —

Luke Thompson
Luke Thompson is the founder of The Operations Guide, LLC and editor of The Claude Insider. Based in Jonesborough, Tennessee, he has spent years building AI-augmented business systems and automation workflows for operators and teams. He began working with large language models in production well before the current wave of consumer AI tools, integrating them into client workflows, content pipelines, and operational infrastructure. At The Claude Insider, he writes about Claude with the specificity of someone who uses it daily as a professional tool — not as a reviewer or commentator, but as a builder. His coverage focuses on what actually works: prompt patterns, API integration strategies, agentic workflows, and the real-world tradeoffs that practitioners face. He is not affiliated with Anthropic, PBC.
Articles are researched and drafted with AI assistance, reviewed and edited by Luke Thompson.
Know where AI can pay off in your company.
Take the free two-minute AI Readiness Assessment. See your score, the two gaps holding you back, and the next move worth making.


