BOTBUS / BLOG

How to auto-approve Claude Code and Codex safely while you're away

Agents stuck on approvals, but --dangerously-skip-permissions feels risky? The middle settings in Claude Code and Codex, plus per-project auto-approve.

The short answer

When you step away from your computer, agent approvals tend to collapse into two options: wait until you're back to approve each one, so the task sits idle for hours, or launch with --dangerously-skip-permissions or --yolo and hope nothing goes wrong. There is a lot of room in between. Claude Code and Codex both ship settings like "edit files freely but ask before risky commands" or "do anything inside the sandbox, ask to leave it". If you manage agents from your phone, BotBus adds a per-project auto-approve switch that only covers turns started from the phone, approves commands and file edits, and still sends questions to you. Which level fits depends on how much the project matters and how easily a mistake can be undone.

This post covers what goes wrong at each extreme, lines up the built-in middle settings next to the BotBus approach, and is honest about what none of them protect against. Claude Code and Codex details were checked against their official docs on 2026-10-07.

Why both extremes hurt

Approving every action is slow, but speed isn't the real problem. An agent can stop to ask dozens of times in an afternoon, and people quickly go from reading each request to tapping "allow" on reflex. That's approval fatigue, and it gets worse on a phone: a long shell command means horizontal scrolling, and deciding whether an rm or a git push is fine while walking down the street is not a careful review. You end up with the worst of both: the risky things aren't really checked, and the harmless ones still block for hours.

Skipping all permissions does exactly what it says. Claude Code's docs describe bypassPermissions (the mode behind --dangerously-skip-permissions) as meant for isolated containers and VMs only, and recommend running it as a non-root user on Linux and macOS. Codex labels --dangerously-bypass-approvals-and-sandbox (alias --yolo) as elevated risk. Both are reasonable in a throwaway CI container. On your everyday machine, with SSH keys, cloud credentials and personal files sitting next to the repo, it's a different bet.

So the useful question is: which actions can go through without asking, which ones must always ask, and how do you undo the ones that went wrong?

The middle settings Claude Code and Codex already have

These live on your computer and work whether or not you ever use a phone.

Claude Code (checked 2026-10-07) has several permission modes. You cycle through them with Shift+Tab or pick one with --permission-mode:

On top of any mode you can write allow, deny and ask rules in settings. Per the docs, deny rules apply in every mode, including bypassPermissions, and ask rules always prompt. That's the direct way to pin git push or directory deletion to "always ask" or "never".

Codex (checked 2026-10-07) separates "what the agent can touch" from "when it asks". The sandbox mode is read-only, workspace-write or danger-full-access. The approval policy is on-request, never, or a granular policy that tunes prompting per category. Network access is off by default, and for version-controlled folders the recommended preset is Auto: workspace write plus on-request approvals when something needs to leave the sandbox. There's also an optional auto-review, where a reviewer agent checks eligible approval requests first, looking for data exfiltration, credential probing, persistent security weakening and destructive actions.

These settings are precise, they're enforced inside the agent, and they apply everywhere. What they don't make easy is per-project trust. They're mostly machine-wide or user-wide defaults, so "let my side project run freely while I'm out, but keep asking on the work repo" means maintaining separate config for each project.

What BotBus auto-approve covers, and what it doesn't

BotBus is an app that runs on your computer (in the menu bar on Mac, in the background on Linux and Windows). It syncs tasks from local agents such as Codex and Claude Code to an iPhone, Apple Watch or Android phone, where you can read the conversation, approve or deny, follow up, stop a task or start a new one. It doesn't change Claude Code's or Codex's own permission settings: whether an action pauses for approval is still decided by the agent's config. BotBus handles the approvals that actually come up.

Auto-approve is a per-project switch on top of that, and it's deliberately narrow:

Approvals granted this way don't send a push and don't leave a pending card, so the task keeps going until it finishes, fails or asks a question. The setting is stored on the computer and survives a restart.

Turning it on and off

Open a conversation inside a project on your phone (or start a new one in a project) and tap the model button on the right above the input field. The bottom of that panel has an Approvals section. Choose auto-approve and a note appears: for this project only, commands and file edits in conversations started from the phone go through, and questions still come to you. It takes effect with your next message, and the button shows a small shield while it's on.

To turn it off, go back to the same panel and switch to approving each request, which also applies from your next message. There's currently no toggle in the Mac menu bar, so you turn it off from the phone.

Making it safer in practice

Turning on auto-approve means saying "yes" in advance, so it's worth making mistakes cheap first:

  1. Only enable it where you can roll back. In a git repo, a bad edit is a git restore or a revert away. Projects without version control, or ones that touch production data, release artifacts or cloud resources, are a poor fit.
  2. Pair it with worktrees. When starting a new conversation from the phone you can choose to run it in a worktree. The agent works on its own git worktree and branch, leaves your uncommitted work alone, and you can merge the session back from the phone once it looks right.
  3. Keep a few deny or ask rules in the agent. BotBus only answers approvals the agent actually raises, and the agent's own rules apply first. Put git push or directory deletion in Claude Code's deny list, keep Codex's network off or stay on workspace-write, and auto-approve can't get past those lines.
  4. Glance at the changes afterwards. The phone shows the session's uncommitted changes, which is enough to tell whether the agent went the right way. Big diffs that need a line-by-line review still belong on the computer.
  5. Know you can stop it. If the agent heads the wrong way, stop the task from your phone and follow up with a correction.

If you'd rather keep approving each request and just want it to be easier on a small screen, see approving Claude Code from your phone. The approval card shows the command or the files involved, and denying is always fine when you're unsure. In turns started from the phone, an approval nobody answers is treated as denied after 30 minutes by default. It never turns into an approval.

Limits

FAQ

How is this different from --dangerously-skip-permissions?

--dangerously-skip-permissions skips permission checks for the whole Claude Code session, including what you do at the computer. BotBus auto-approve only grants approvals in one project, only in turns started from the phone, and still sends you questions. The agent's own deny rules and sandbox settings stay in place, and you don't change how Claude Code is launched.

Will Claude Code stop asking me at my desk once it's on?

No. Turns you run at the computer are unaffected and follow Claude Code's own permission mode. Only new tasks and follow-ups from the phone are auto-approved.

Can I auto-approve file edits but not shell commands?

Not with the BotBus switch, which covers every approval in the turn. For finer control, set it in the agent: Claude Code's acceptEdits mode with ask and deny rules, or a granular approval policy in Codex.

Can other phones see that a project has auto-approve on?

Yes. The setting is stored on the computer, so every phone paired with it can see and change it in the same panel. The iPhone and Android apps have the same panel.

How do I get started?

Install BotBus on your computer and scan the pairing QR code with your phone. Downloads are on the home page: Mac (macOS 26 or later), Linux and Windows for the computer, iPhone and Apple Watch on the App Store (iOS 26 / watchOS 26 or later), and an Android app as a direct download.

← All posts