Newly documented features
- Added Run Modes page (
/docs/agent/security/run-modes) covering Auto-review (default), Allowlist, and Run Everything modes for controlling shell, MCP, and Fetch tool approvals, sandboxing, and classifier behavior.
Agent & Security
- Updated Agent Security, Terminal, and related pages to position Auto-review as the default mode and clarify that allowlists + classifier are best-effort guardrails, not hard security boundaries.
- Removed references to the deprecated “Allowlist (with Sandbox)” mode from security, enterprise, permissions, and MCP documentation.
Enterprise
- Revised Enterprise deployment patterns and LLM safety docs to reflect the new Run Modes options and updated permissions.json behavior for Auto-review.
MCP & Tools
- Updated MCP and Terminal documentation to align tool approval flows with the new Run Modes classifier and allowlist handling.
Reference
- Updated permissions.json and sandbox reference pages to document
autoRuninstructions, mode-specific effects, and environment variable references.