Anthropic is introducing 'auto mode' for Claude Code, a new permissions mode that acts as a middle ground between the default conservative approval-based system and the risky --dangerously-skip-permissions flag. A classifier reviews each tool call before execution, automatically allowing safe actions and blocking potentially destructive ones (like mass file deletion or data exfiltration). If Claude repeatedly hits blocks, it escalates to a human prompt. Available now as a research preview for Team plan users, with Enterprise and API rollout coming soon. It works with Claude Sonnet 4.6 and Opus 4.6, and can be enabled via `claude --enable-auto-mode`.
Sort: