Skip to main content
Product Updates

Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14

Anthropic announced today (August 8) that starting August 14, it will change Claude Code's default permission mode to Auto Mode for Pro, Max, and Team subscribers.

Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14

Anthropic announced today (August 8) that starting August 14, it will change Claude Code's default permission mode to Auto Mode for Pro, Max, and Team subscribers.

According to a blog post cited by ITHome, Auto Mode means that Claude Code uses an independent AI classifier to evaluate every tool call and Shell command in real time, allowing safe operations while automatically blocking destructive, irreversible, or unauthorized actions.

Regarding coverage, Claude Enterprise, Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry will remain optional for now. Anthropic plans to roll out the change on the platforms mentioned above within the next 1 month, making Auto Mode the default option and eliminating the corresponding overhead.

During testing, Anthropic invited 1,053 paid testers to participate. It found that the traditional manual approval mode identified only 13.6% of dangerous commands, while Auto Mode was able to identify 89% of dangerous commands.

Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14

In prompt injection evaluations, Trajectory Labs used 72 scenarios with 10 tests per scenario, for a total of 720 attack attempts, covering Claude Code v2.1.205 and Codex v0.144.5.

Claude Fable 5, Opus 5, and Sonnet 5 blocked all attacks in Auto Mode, with 0 successful attempts. GPT-5.6 Sol had a success rate of 5.83% in Codex's Auto-review mode and 19.03% in Full Access mode.

Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14

Anthropic also noted that the bypassPermissions mode without additional safeguards had an average attack success rate of 0.09%, while the new Auto-review version released by OpenAI last week may change the results.

Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14
Claude Code Default Permissions for Pro, Max, and Team Users to Switch to Auto Mode Starting August 14