Collaborator permissions
Control what an approved guest can read, change, and execute.
Approval gives a device access to one shared project. The host can adjust the collaborator's capabilities in that project's sharing settings.
| Capability | What it permits |
|---|---|
| View threads | Read the project's shared conversation history. |
| Create threads | Start a thread in the shared project. |
| Message and steer agents | Submit messages and steer eligible shared runs. |
| Read project files | Read files within the shared directory. |
| Edit project files | Modify project files, when Agent shell is On. |
| Use terminal | Use project terminals, when Agent shell is On. |
| View project previews | Access previews exposed by the shared project. |
| Stop runs | Interrupt eligible runs. |
| Rename, archive, and delete threads | Manage eligible project threads. |
| Manage invitations and collaborators | Manage sharing within the granted authority. |
Messaging and provider inference also require permission to view the thread. A guest cannot use an inference request to receive history they are not allowed to read.
Agent shell
Off denies command execution through the shared agent policy. Ask requires explicit host approval for command or extension execution. On allows execution subject to the remaining permissions.
For this alpha, Off and Ask also disable file editing and terminals, including in older saved grants. Editing configuration, plugins, or source watched by a dev server can execute code, so write access is not treated as harmless when shell access is restricted. An individually approved Ask command still executes with the host's operating-system privileges.
Trust the people who can execute code
Worktree enforces project-scoped API access, but it is not an operating-system sandbox. Shell commands, plugins, and other executable project code run with the host user's privileges and may reach files, environment variables, or credentials outside the project. Use On only with trusted collaborators.
Changes to permissions apply to subsequent authorization checks. They cannot retrieve data someone has already read or undo work already admitted.