The short answer
When you step away from your computer, agent approvals tend to collapse into two options: wait until you're back to approve each one, so the task sits idle for hours, or launch with --dangerously-skip-permissions or --yolo and hope nothing goes wrong. There is a lot of room in between. Claude Code and Codex both ship settings like "edit files freely but ask before risky commands" or "do anything inside the sandbox, ask to leave it". If you manage agents from your phone, BotBus adds a per-project auto-approve switch that only covers turns started from the phone, approves commands and file edits, and still sends questions to you. Which level fits depends on how much the project matters and how easily a mistake can be undone.
This post covers what goes wrong at each extreme, lines up the built-in middle settings next to the BotBus approach, and is honest about what none of them protect against. Claude Code and Codex details were checked against their official docs on 2026-10-07.
Why both extremes hurt
Approving every action is slow, but speed isn't the real problem. An agent can stop to ask dozens of times in an afternoon, and people quickly go from reading each request to tapping "allow" on reflex. That's approval fatigue, and it gets worse on a phone: a long shell command means horizontal scrolling, and deciding whether an rm or a git push is fine while walking down the street is not a careful review. You end up with the worst of both: the risky things aren't really checked, and the harmless ones still block for hours.
Skipping all permissions does exactly what it says. Claude Code's docs describe bypassPermissions (the mode behind --dangerously-skip-permissions) as meant for isolated containers and VMs only, and recommend running it as a non-root user on Linux and macOS. Codex labels --dangerously-bypass-approvals-and-sandbox (alias --yolo) as elevated risk. Both are reasonable in a throwaway CI container. On your everyday machine, with SSH keys, cloud credentials and personal files sitting next to the repo, it's a different bet.
So the useful question is: which actions can go through without asking, which ones must always ask, and how do you undo the ones that went wrong?
The middle settings Claude Code and Codex already have
These live on your computer and work whether or not you ever use a phone.
Claude Code (checked 2026-10-07) has several permission modes. You cycle through them with Shift+Tab or pick one with --permission-mode:
- Manual (config value
default): asks before almost everything except reads. acceptEdits: file edits and common filesystem commands likemkdirandmvgo through; everything else asks. Good when you'll review the diff anyway but want to see commands first.plan: Claude researches and writes a plan, and doesn't edit code until you approve it.auto: a separate classifier model reviews each action and blocks things that go beyond your request, target unfamiliar infrastructure, or look driven by hostile content Claude read. The docs say recent versions start interactive terminal sessions in this mode, and list which models and providers support it.dontAsk: only pre-approved tools run, everything else is denied. Built for CI.bypassPermissions: everything runs. As above, the docs reserve it for isolated environments.
On top of any mode you can write allow, deny and ask rules in settings. Per the docs, deny rules apply in every mode, including bypassPermissions, and ask rules always prompt. That's the direct way to pin git push or directory deletion to "always ask" or "never".
Codex (checked 2026-10-07) separates "what the agent can touch" from "when it asks". The sandbox mode is read-only, workspace-write or danger-full-access. The approval policy is on-request, never, or a granular policy that tunes prompting per category. Network access is off by default, and for version-controlled folders the recommended preset is Auto: workspace write plus on-request approvals when something needs to leave the sandbox. There's also an optional auto-review, where a reviewer agent checks eligible approval requests first, looking for data exfiltration, credential probing, persistent security weakening and destructive actions.
These settings are precise, they're enforced inside the agent, and they apply everywhere. What they don't make easy is per-project trust. They're mostly machine-wide or user-wide defaults, so "let my side project run freely while I'm out, but keep asking on the work repo" means maintaining separate config for each project.
What BotBus auto-approve covers, and what it doesn't
BotBus is an app that runs on your computer (in the menu bar on Mac, in the background on Linux and Windows). It syncs tasks from local agents such as Codex and Claude Code to an iPhone, Apple Watch or Android phone, where you can read the conversation, approve or deny, follow up, stop a task or start a new one. It doesn't change Claude Code's or Codex's own permission settings: whether an action pauses for approval is still decided by the agent's config. BotBus handles the approvals that actually come up.
Auto-approve is a per-project switch on top of that, and it's deliberately narrow:
- One project. It's keyed to the project path on that computer, and git worktree sessions opened from the project count as the same project. Other projects, and same-named paths on other computers, are unaffected. Sessions outside any project can't use it.
- Only turns started from your phone. New tasks you start on the phone, and follow-up turns you send from it (including a follow-up into a session that began on the computer), get their approvals granted automatically. Turns you run at the computer still ask at the computer. When BotBus shares the Codex desktop app, only approvals inside the phone's turn are granted.
- Approvals only, never questions. Requests to run a command, edit files or get a permission are granted as "allow this once". Questions that need a decision from you, like Claude Code's
AskUserQuestionor Codex'srequestUserInput, still go to your phone. - Codex and Claude Code only. Other agents don't show the switch. On a given computer, the setting applies to every supported agent there.
Approvals granted this way don't send a push and don't leave a pending card, so the task keeps going until it finishes, fails or asks a question. The setting is stored on the computer and survives a restart.
Turning it on and off
Open a conversation inside a project on your phone (or start a new one in a project) and tap the model button on the right above the input field. The bottom of that panel has an Approvals section. Choose auto-approve and a note appears: for this project only, commands and file edits in conversations started from the phone go through, and questions still come to you. It takes effect with your next message, and the button shows a small shield while it's on.
To turn it off, go back to the same panel and switch to approving each request, which also applies from your next message. There's currently no toggle in the Mac menu bar, so you turn it off from the phone.
Making it safer in practice
Turning on auto-approve means saying "yes" in advance, so it's worth making mistakes cheap first:
- Only enable it where you can roll back. In a git repo, a bad edit is a
git restoreor a revert away. Projects without version control, or ones that touch production data, release artifacts or cloud resources, are a poor fit. - Pair it with worktrees. When starting a new conversation from the phone you can choose to run it in a worktree. The agent works on its own git worktree and branch, leaves your uncommitted work alone, and you can merge the session back from the phone once it looks right.
- Keep a few deny or ask rules in the agent. BotBus only answers approvals the agent actually raises, and the agent's own rules apply first. Put
git pushor directory deletion in Claude Code's deny list, keep Codex's network off or stay onworkspace-write, and auto-approve can't get past those lines. - Glance at the changes afterwards. The phone shows the session's uncommitted changes, which is enough to tell whether the agent went the right way. Big diffs that need a line-by-line review still belong on the computer.
- Know you can stop it. If the agent heads the wrong way, stop the task from your phone and follow up with a correction.
If you'd rather keep approving each request and just want it to be easier on a small screen, see approving Claude Code from your phone. The approval card shows the command or the files involved, and denying is always fine when you're unsure. In turns started from the phone, an approval nobody answers is treated as denied after 30 minutes by default. It never turns into an approval.
Limits
- It's not a sandbox. Auto-approve doesn't limit what the agent can reach. It only decides whether raised approvals wait for you. For isolation, use Codex's sandbox, Claude Code's Bash sandbox, or a container or VM.
- It doesn't judge. Unlike Claude Code's auto mode or Codex's auto-review, BotBus doesn't run a model over each action. On means every approval in that project's phone turns goes through. If you want a reviewer, use the agent's own; if you want "I trust this project", use auto-approve. They stack.
- Phone turns only. A turn running in a session you started at the computer follows the computer's settings.
- Codex and Claude Code only. Hermes, Pi, OpenCode, OpenClaw, DeepSeek Harness and other agents don't have the switch, and some of them have no approval channel to begin with.
- The computer has to be on and online. Tasks run on your computer; while it sleeps or is offline, anything you do on the phone waits for it.
- Encryption. Approval contents, your answers and this setting are inside end-to-end encrypted content the relay can't read. The relay does see device IDs, online status, update times and data sizes. Details are in the security overview.
FAQ
How is this different from --dangerously-skip-permissions?
--dangerously-skip-permissions skips permission checks for the whole Claude Code session, including what you do at the computer. BotBus auto-approve only grants approvals in one project, only in turns started from the phone, and still sends you questions. The agent's own deny rules and sandbox settings stay in place, and you don't change how Claude Code is launched.
Will Claude Code stop asking me at my desk once it's on?
No. Turns you run at the computer are unaffected and follow Claude Code's own permission mode. Only new tasks and follow-ups from the phone are auto-approved.
Can I auto-approve file edits but not shell commands?
Not with the BotBus switch, which covers every approval in the turn. For finer control, set it in the agent: Claude Code's acceptEdits mode with ask and deny rules, or a granular approval policy in Codex.
Can other phones see that a project has auto-approve on?
Yes. The setting is stored on the computer, so every phone paired with it can see and change it in the same panel. The iPhone and Android apps have the same panel.
How do I get started?
Install BotBus on your computer and scan the pairing QR code with your phone. Downloads are on the home page: Mac (macOS 26 or later), Linux and Windows for the computer, iPhone and Apple Watch on the App Store (iOS 26 / watchOS 26 or later), and an Android app as a direct download.