Permissions
~2 min read
Concept & How It Works
- Key points are in the visual diagram above.
Learn these elsewhere (not covered in depth here)
- →Least Privilege — Phase 20
Why Does It Exist?
A coding agent without permissions is a remote shell as the model.
Real-World Analogy
OS permissions: the model is never root by default.
Visual Workflows
What is Permissions?
Example
Scenario
OS permissions: the model is never root by default.
Solution
In Claude Agent SDK, apply Permissions to this scenario: OS permissions: the model is never root by default. Identify the inputs, run the technique, validate the output, and note one thing you would monitor in production.
Practice Task
Do this before moving to the next module — reading alone is not enough.
Open the Code Walkthrough below and run it locally. Change one parameter related to Permissions (e.g. model, temperature, top_k, or tool name), observe the difference in output, and write 2–3 sentences explaining what changed.
Code Walkthrough
Highlighted lines show where Permissions happens in the code.
1# Permissions — minimal example2from openai import OpenAI3
4client = OpenAI() # create API client5
6# Ask the model to explain this topic7response = client.chat.completions.create( # core API call for Permissions8 model="gpt-4o-mini",9 messages=[10 {"role": "system", "content": "You explain permissions clearly."},11 {"role": "user", "content": f"What is permissions?"},12 ],13 temperature=0,14)15print(response.choices[0].message.content) # show output for debuggingCommands to Remember
Commands to Remember
npm install @anthropic-ai/claude-agent-sdk # Claude Agent SDKpip install claude-agent-sdk # Python Claude Agent SDK
Common Mistakes
- Skipping evaluation for Permissions before production
- No logging or tracing around claude permissions steps
- Ignoring cost and latency implications
Cheat Sheet
Quick recap — the most important points from this module.
Cheat Sheet
quick ref- •Every tool call is gated. Read vs write vs irreversible. HITL for the last class
