Execution Policy
Control how Hanzo Dev executes commands with execution policy rules.
Execution Policy
Hanzo Dev uses execution policies to control what commands the agent can run and when approval is required.
Sandbox Modes
| Mode | Description |
|---|---|
off | No sandboxing (commands run directly) |
workspace-read | Read-only access to workspace |
workspace-write | Read/write access to workspace (default for full-auto) |
network-off | Disable network access |
Approval Policies
| Policy | Description |
|---|---|
always | Always ask for approval before executing |
on-failure | Ask only when a command fails (default for full-auto) |
on-request | Ask when the model explicitly requests approval |
never | Never ask for approval |
Usage
# Set sandbox mode
dev --sandbox workspace-write "your prompt"
# Set approval policy
dev --ask-for-approval on-failure "your prompt"
# Full auto (sandboxed + auto-approve)
dev --full-auto "your prompt"