Worktree

Collaborator permissions

Control what an approved guest can read, change, and execute.

Approval gives a device access to one shared project. The host can adjust the collaborator's capabilities in that project's sharing settings.

CapabilityWhat it permits
View threadsRead the project's shared conversation history.
Create threadsStart a thread in the shared project.
Message and steer agentsSubmit messages and steer eligible shared runs.
Read project filesRead files within the shared directory.
Edit project filesModify project files, when Agent shell is On.
Use terminalUse project terminals, when Agent shell is On.
View project previewsAccess previews exposed by the shared project.
Stop runsInterrupt eligible runs.
Rename, archive, and delete threadsManage eligible project threads.
Manage invitations and collaboratorsManage sharing within the granted authority.

Messaging and provider inference also require permission to view the thread. A guest cannot use an inference request to receive history they are not allowed to read.

Agent shell

Off denies command execution through the shared agent policy. Ask requires explicit host approval for command or extension execution. On allows execution subject to the remaining permissions.

For this alpha, Off and Ask also disable file editing and terminals, including in older saved grants. Editing configuration, plugins, or source watched by a dev server can execute code, so write access is not treated as harmless when shell access is restricted. An individually approved Ask command still executes with the host's operating-system privileges.

Trust the people who can execute code

Worktree enforces project-scoped API access, but it is not an operating-system sandbox. Shell commands, plugins, and other executable project code run with the host user's privileges and may reach files, environment variables, or credentials outside the project. Use On only with trusted collaborators.

Changes to permissions apply to subsequent authorization checks. They cannot retrieve data someone has already read or undo work already admitted.

On this page