Files
cline/docs/features/auto-approve.mdx
T
David AndersonandJuan Pablo Flores d850fbc0ad Documentation Update - Toggle to Enable Notifications Moved to Auto Approve Menu (#8445)
* Changed the "Notes" column for "Enable notifications" from "Helpful for terminal work" to "Accessible directly in the Auto Approve menu" to make it clear that users don't need to navigate to General Settings anymore.

Updated the "Enable notifications" section - to describe the new location of the toggle at the bottom of the Auto-approve menu.

A link to a short video showing the toggle was added.

* updated as per issue 7810 and noted in previous commit.

* edit - remove extra link to video in /auto-approve.mdx

---------

Co-authored-by: Juan Pablo Flores <juan@cline.bot>
2026-01-16 10:35:53 -08:00

108 lines
5.1 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Auto Approve"
sidebarTitle: "Auto Approve"
description: "Let Cline take specific actions without asking for approval every time."
---
Auto Approve lets you decide which actions Cline can take without prompting you each time. It keeps you out of approval popups during routine work, while still letting you keep tight control over high-risk actions.
If you find yourself repeatedly clicking approve for the same safe operations, Auto Approve is the setting that fixes that. The goal is fewer interruptions without losing the ability to review changes when it matters.
<Frame>
<video
style={{ width: "100%" }}
src="https://storage.googleapis.com/cline_public_images/autoapprove.mp4"
autoPlay
controls
playsInline
/>
</Frame>
## How it works
Auto Approve is evaluated per tool call. When Cline is about to read a file, edit a file, run a command, or use the browser, Cline checks your Auto Approve settings for that category.
A few details matter in practice:
- **Workspace vs outside your workspace**: “Read all files” and “Edit all files” only extend the base toggle. If the base toggle is off, the “all files” option does nothing.
- **Terminal commands**: Cline treats terminal commands as either safe or requiring approval. “Execute safe commands” covers the first category. “Execute all commands” extends this to commands flagged as requiring approval.
- **Notifications**: If enabled, Cline sends OS-level notifications when approval is required, and when an auto-approved terminal command has been running for 30 seconds and may need attention.
<Note>
[YOLO mode](/features/yolo-mode) bypasses these granular approvals.
</Note>
## Permissions
These labels match what you see in the Auto Approve menu.
| Setting | What it allows | Notes |
|--------|-----------------|------|
| Read project files | Read files, list files, search in your workspace | Good default for most tasks |
| Read all files | Read files outside your workspace | Requires “Read project files” |
| Edit project files | Create and edit files in your workspace | Consider using checkpoints |
| Edit all files | Edit files outside your workspace | Requires “Edit project files” |
| Execute safe commands | Run terminal commands marked safe | Can still run long |
| Execute all commands | Run commands marked as requiring approval | Requires “Execute safe commands” |
| Use the browser | Allows use of the browser tool for web fetching and searching | Proxy issues can apply |
| Use MCP servers | Use MCP tools and access MCP resources | Some servers also have per-tool auto-approve |
| Enable notifications | Notifies you about long-running auto-approved commands | Accessible directly in the Auto Approve menu |
<Warning>
“Read all files” and “Edit all files” only matter if their base toggle is enabled. They extend access outside your workspace.
</Warning>
<Card title="Networking & proxies" icon="globe" href="/troubleshooting/networking-and-proxies">
If browser-based tools fail in corporate networks, this page covers the common fixes.
</Card>
## Safe vs approval-required command examples
Cline does not use a fixed allowlist of safe or unsafe commands. The model marks each command with a `requires_approval` flag based on the command and its arguments, and Auto Approve uses that flag.
These are examples, not guarantees.
### Commonly treated as safe
| Example | Why it is usually safe |
|--------|-------------------------|
| `npm run build` | Build output, no direct file deletions |
| `npm test` | Runs tests |
| `git status` | Read-only |
| `ls -la` | Read-only |
| `cat package.json` | Read-only |
### Commonly requires approval
| Example | Why it often needs approval |
|--------|------------------------------|
| `npm install <pkg>` | Modifies dependencies and lockfiles |
| `rm -rf <path>` | Deletes files |
| `mv <a> <b>` | Moves files (can overwrite) |
| `sed -i ...` | In-place file edits |
| `curl https://...` | Downloads and executes remote code |
<Note>
Whether a command is treated as safe depends on the exact command, flags, and the current task. When in doubt, keep command auto-approval off and approve commands manually.
</Note>
## Enable notifications
Auto-approved actions can run for a while, especially long terminal commands. If you enable notifications, Cline can notify you when an auto-approved command has been running for a while and may need attention.
The **Enable notifications** toggle is located at the bottom of the Auto Approve menu, below a separator line. This puts the notification setting right where you manage your auto-approval permissions, making it easy to discover and adjust.
## Recommendations
A good default setup is:
- Enable **Read project files**
- Leave **Edit project files**, **Execute safe commands**, **Use the browser**, and **Use MCP servers** off until you have a specific reason to enable them
If you enable edits, use [Checkpoints](/features/checkpoints) so you can roll back quickly.
If you’re working in a sensitive environment (production credentials, personal files, corporate devices), keep external file access and command execution locked down and approve actions manually as you go.