# Make always_allow_tool_actions override always_confirm and default_mode \(\#47012\) · gitcafe/zed

[View on GitCafe](https://git.cafe/gitcafe/zed/commit/258d9223e41bb096b254b4baa3c134919ff2e197)

Repository: [gitcafe/zed](https://git.cafe/gitcafe/zed)

Visibility: public

Requested revision: 258d9223e41bb096b254b4baa3c134919ff2e197

Requested commit: 258d9223e41bb096b254b4baa3c134919ff2e197

Commit: 258d9223e41bb096b254b4baa3c134919ff2e197

Tree: 83f460e72836b17846c744faca3d4cbf260dcf3b

Author: Richard Feldman

Committer: GitHub

## Message

```
Make always_allow_tool_actions override always_confirm and default_mode (#47012)

Previously, `always_confirm` patterns would force confirmation even when
`always_allow_tool_actions` was set to true. This was counterintuitive
since the global setting should provide a way to skip all confirmations.

The new precedence order is:
1. **`always_deny`** - still blocks for security
2. **`always_allow_tool_actions`** - when true, allows all non-denied
actions
3. **`always_confirm`** - prompts if `always_allow_tool_actions` is
false
4. **`always_allow`** - allows without prompting
5. **`default_mode`** - fallback behavior

This means setting `always_allow_tool_actions=true` will now skip
confirmation prompts from `always_confirm` patterns and override
`default_mode: Deny` settings, while still respecting `always_deny`
patterns for security.

(No release notes because granular tool permissions are still
feature-flagged.)

Release Notes:

- N/A
```

## Parents

- [c0bfba85c5a948a8af7c2f6bef221e4a0700488f](https://git.cafe/gitcafe/zed/commit/c0bfba85c5a948a8af7c2f6bef221e4a0700488f?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zed/tree/258d9223e41bb096b254b4baa3c134919ff2e197?format=markdown)
