Markdownkeyboard_arrow_down
content_copyCopy Markdown
open_in_newView Markdown
Permissions
Secure your local workstation, restrict absolute file paths, configure custom allow/deny/ask policies, and manage interactive approvals. You can also manage these rules interactively using the Permissions Command.
Fine-grained permissions
To secure your workstation while enabling autonomous workflows,
Antigravity CLI integrates a robust Fine-Grained Permissions Engine.
Every sensitive operation the agent performs is represented as a
permission resource formatted as action(target).
Permissions are evaluated across three distinct access lists configured inside your global settings:
~/.gemini/antigravity-cli/settings.json
deny: The action is blocked immediately.ask: The agent pauses and prompts for your explicit approval before proceeding.allow: The action is auto-approved without prompting.
Supported actions & matching rules
Fine-grained permissions follow a standard schema pattern:
action(target)
The supported actions, target format specifications, and matching algorithms are:
[TABLE]
Global wildcard syntax
Across all supported action types, passing the global wildcard * (such
as read_file(*), command(*), mcp(*)) matches all targets within
that entire action namespace.
Implicit permission rules
- Write implies Read: Allowing
write_fileon a path automatically grantsread_fileon that path. - Deny Read implies Deny Write: Denying
read_fileon a path immediately blockswrite_fileon that path.
Cross-platform path normalization
Antigravity ensures your permission rules work flawlessly whether you
are developing on macOS, Linux, or Windows. On macOS and Linux, paths
use standard forward slashes (/). On Windows, Antigravity
automatically normalizes paths prior to rule evaluation by stripping
drive letters (e.g., C:) and converting all backslashes (\) to
forward slashes (/).
Default system behaviors & guardrails
When an action is not explicitly listed in your allow, deny, or
ask lists, the system falls back to secure system defaults:
- Workspaces are Auto-Allowed: In standard operation, reading and writing files inside your active project directory is automatically allowed.
- Web Browsing Defaults to Ask: Actions for
read_urlandexecute_urldefault to Ask. Before the agent navigates to or actuates on any web page, it will pause and prompt for your approval unless an allow rule is configured. - Unconfigured Actions Default to Ask: All other unconfigured
actions (
command,mcp,execute_url, non-workspace files) default to Ask.
Interactive permission prompts
When the agent encounters an operation requiring approval (Ask mode), an interactive prompt card appears in your TUI.
Before confirming Allow for file, URL, or MCP permissions, you can
directly edit the target string in the prompt card to expand the granted
scope (e.g., broadening a single file request like /project/file.txt
to the parent directory /project). The CLI validates that your edited
target safely covers the operation and applies the expanded grant for
the remainder of the turn, preventing repeated prompts for related
operations. (Note: Scope editing is not supported for terminal
commands).
Configuration examples
Add these rules to your ~/.gemini/antigravity-cli/settings.json file:
{
"permissions": {
"allow": [
"command(git)",
"command(npm run (build|lint|test))",
"unsandboxed(git push)",
"read_file(/var/log/app)",
"write_file(src/)",
"read_url(google.com)",
"mcp(linter/*)"
],
"deny": [
"command(rm -rf)",
"command(curl .*)",
"command(sudo)",
"write_file(.git/)",
"write_file(/home/user/.ssh)"
],
"ask": ["command(*)", "execute_url(aws.amazon.com)", "mcp(sql/execute_mutation)"]
}
}See also
- Permissions Command: Manage rules interactively in the TUI.
- Sandbox Customization: Enforce OS-level container isolation boundaries.
- Plugins & Skills: Create your own custom skills slash commands.
- Settings, Rendering & Keybindings: Customize keyboard hotkeys and buffers.
Last updated Oct 08, 2026