Chat modes
Appenda owns the permission ladder in the agent composer. This is not Cursor's ask / agent / edit modes.
Ask is the default for new chats. Risky table tools pause for an approval card.
Modes
| Mode | Meaning |
|---|---|
read_only | Table reads only |
ask | Default for new chats. Risky tools pause for an approval card |
allow_session | After you confirm, allow risky tools for this chat session |
full_access | Widest session allowance for Appenda tools. Native adapter shell/terminal stays off |
Switch modes from the Ask dropdown on the left side of the composer.
Role ceilings
Settings → Permissions sets which modes each role may pick:
| Role | Typical ceiling |
|---|---|
| Viewer | Read only |
| Editor | Allow session |
| Admin / Creator | Full access |
Members cannot pick a mode above their role ceiling. Only workspace admins (and roles with manage team) change ceilings in Permissions, not from the chat itself.
Escalation confirm
Choosing Allow session or Full access opens an in-app confirm dialog before the wider posture applies. Read only and Ask switch immediately.
How chat modes work with approvals
Chat modes and approvals solve different layers:
| Layer | Where it lives | What it controls |
|---|---|---|
| Chat mode | Composer dropdown | Session posture for this chat tab |
| Permissions | Settings → Permissions | Per-role tool classes (Deny / Require approval / Allow) |
| Runtime cards | In the chat | A single tool call that still needs your answer |
Think of chat mode as the default posture for the tab. Permissions are the workspace ceiling no mode can bypass.
When you still see an approval card
| Situation | Why |
|---|---|
| Mode is Ask or Read only | Most mutating appenda.* tools pause until you choose Allow once, Allow for session, Always allow, or Deny |
| Mode is Allow session or Full access | A tool class is still Require approval for your role (for example enrichment on Editor) |
| Paid or destructive paths | Integrations, enrichment runs, and destructive deletes can prompt even in Full access |
| Adapter filesystem / terminal | Denied by default for all roles; not unlocked by Full access |
Allow for session on a card remembers that tool for the current chat tab. Always allow saves a durable grant when your role may grant approvals. Full access auto-approves most Appenda gateway tools, but it does not override paid integration preview steps or workspace Deny rules.
How the two layers combine
- Your role picks which modes appear in the dropdown.
- You pick a mode for this chat (with confirm when escalating).
- Each tool call is checked against Permissions and the active mode.
- If anything is still ambiguous, Appenda pauses the turn and shows a card.
Full access and Appenda tools
Full access auto-approves appenda.* gateway tools for the session. It does
not unlock Claude bypassPermissions or native Bash/filesystem inside the
adapter.