Developers control how much autonomy Claude Code has, from approving every action to letting built-in classifiers distinguish safe actions from risky ones automatically. The default is cautious: Claude Code asks before making changes to your files or running commands.

Anthropic’s approach to agent safety, including how we design for trust, access boundaries, and human control, is documented in our research.

Read our research on agent safety