grok-build-upstream-mirror/crates/codegen/xai-grok-pager/docs/tutorial/07-plan-and-permissions.md
grokkybara[bot] 69f0ba880a Synced from monorepo
Synced from monorepo

Changes:
- Workspace server: report `/ready` as failed with dwell on hub connect failure
- Refresh OIDC token for the Grok agent in the shell
- ACP terminal output recorder
- Cross-platform provider auth commands in the shell
- Default `/resume` to Grok sessions with a hint for hidden external sessions
- Resume sessions by title with `--resume`
- Limit app-builder archive size
- Data-driven tag labels for slash commands
- Doctor fixes for tmux
- Custom provider gateways and subprocess environment policy in the shell
- `/tutorial` — opt-in onboarding tour of Grok Build
- Soft and required CLI version checks in the shell
- Privacy banner env overrides survive live settings updates
- Add remote flag to override the image-edit model
- Return profile fields from auth info even when the access token is expired
- Add edit control on queued prompt rows
- Keep fail-closed policy when clearing orphans with no team
- Setting to disable the Ctrl+Space/F8 voice shortcut
- Pass `--raw` to pw-record so Linux dictation works on older PipeWire
- Validate git URLs when adding marketplace entries
- Stop shipping stale tool-doc parameter and tool names
- Re-point dashboard attach after `/fork` only when the parent was attached
- Surface Grok Computer media-generation results as file-path chunks
- Clear web background-task tray on kill and keep the task description
- Show privacy upsell banner in agent view until acted on
- Add tools-server client callback surface
- Protect persistent global hook sources

Source-Revision: 95d84f443eddcbed6cbfd6eed22e2eafe6b3939d
2026-07-23 17:12:33 +00:00

1.4 KiB

Plan Mode & Permissions

Grok asks before doing anything risky — and can plan before it codes.

Permissions

When Grok wants to run a risky command or edit a file, it pauses and asks: allow once, always allow that kind of action, or deny.

Reading is always free: file reads, searches, and safe read-only commands (ls, git status, grep, …) never prompt. Chained commands are checked piece by piece — ls && rm -rf tmp still prompts for the rm.

Trust the session? /always-approve (or Ctrl+O) skips the prompts.

Plan mode

For bigger or more ambiguous tasks, use plan mode: Grok explores the codebase read-only, designs an approach, and presents a plan you approve before any code is written.

  • Shift+Tab (prompt focused) cycles the mode: Normal → Plan → Always-approve.
  • /plan enters plan mode directly; /plan <task> plans that task in one step.

When the plan is ready: a approves, c comments on a specific line, s requests changes — Grok iterates until you're happy, then implements.

A good habit: plan mode for "how should we even do this?", normal mode for "just do it".

Long-running commands

A build or test run hogging the turn? Ctrl+B sends it to the background — Grok keeps working and you're notified when it finishes (Ctrl+G shows the tasks pane).

Go deeper: /docs Plan Mode or /docs Permissions and Safety