Approvals and Autonomous mode
Decide what the agent can do on its own, and answer it from wherever you are.
Agents ask before doing things that might matter: running a command, editing a file, or starting on a plan. Sesh puts the question in front of you wherever you are, and waits.
Answer a request
The question appears in a panel above the message box, such as “Allow Claude Code to run this command?”, with what it wants to run underneath. Click it to jump to that step in the chat.
| Button | What it does |
|---|---|
| Allow | Lets it go ahead this once. Press Return. |
| Always Allow | Tells the agent not to ask again for this kind of action. How long that lasts depends on the agent. |
| Don’t Allow | Says no this time. The agent carries on without it. |
| Never Allow | Tells the agent not to try this kind of action again. |
When several requests are waiting, the panel says “1 of 3” and shows them in order.
Answer without opening the session
- Needs You at the top of the sidebar lists every session that’s waiting on you.
- The menu bar shows the same list, with Allow and Don’t Allow right there.
- Notifications have Allow and Don’t Allow buttons. On iPhone and iPad, Allow asks you to unlock first.
Answer on one device and the request disappears from the others.
Approve a plan
In plan mode, the agent writes a plan before touching anything and asks you to approve it.
- Read the plan card in the chat, or click Read Full Plan.
- Click Approve to let it start, or Keep Planning to send it back.
How much it asks
Each agent has its own modes, in the Mode chip under the message box. Change it any time; Sesh remembers it for the session. A new session starts in a mode that asks only about risky actions:
| Agent | Starts in |
|---|---|
| Claude Code | Auto: routine actions go ahead, risky ones ask |
| Codex | Agent |
| Gemini CLI | Auto Edit |
Autonomous mode
Turn on Autonomous in New Session and the agent doesn’t ask at all. Use it for long tasks you want finished while you’re away.
Sesh fences it in where the machine allows:
- The agent can only write to its own session folder, the project’s git data, temporary folders and its own caches.
- It can’t read your credentials folders, like
~/.ssh. - Everything it starts is fenced in the same way.
On a Mac this works out of the box. On Linux it needs bubblewrap installed:
sudo apt install bubblewrap
Heads up. Without a sandbox, Autonomous sessions run unfenced. The session says so when it starts, and New Session warns you. Some Linux setups, and Docker with its default settings, block sandboxing.
Autonomous sessions show Autonomous where the Mode chip would be. You can’t switch a running session in or out of it; start a new one.
Good to know
- Cursor has no mode that skips approvals, so in Autonomous sessions Sesh answers its requests for you, one at a time.
- Choosing Sessions open in: Terminal in Settings › General shows Claude Code’s own screen instead of the chat. You answer it there, and Sesh doesn’t send approval notifications.