Every chat has an access level, set from the Access picker in the composer, that decides how much an agent may do before it stops to ask you.
The three levels
- Ask for approval: asks before it edits files, runs commands or uses the internet.
- Approve for me: only asks about actions that look risky; its own reviewer approves the rest.
- Full access: never asks, and runs outside the sandbox. It can change any file and use the internet on its own.
Turning on Full Access asks you to confirm, once, in words: the agent will change files, run commands and use the internet without asking, and anything it reads, like a web page or a file, can try to steer it. A scheduled task carries its own access level too, set when you create it.
The sandbox
Below Full Access, macOS itself limits what an agent’s commands can touch, whatever the agent was told by something it read:
- A command can change files in the chat’s folder, but not the places where a change would outlast the chat: what starts when you log in, your shell’s settings, each agent’s own settings, and Outmake’s.
- It can’t read where your keys, sign-ins and website cookies are kept, or your other chats.
- It reaches package registries and code hosts, like npm and GitHub, by itself. Any other website asks you first.
Claude chats run under these rules, and any folder you gave Claude Code yourself in its own settings stays open to it. OpenCode chats run under them too, with one difference: a website off the list is refused rather than asked about, and Outmake tells you when it happens. ChatGPT runs commands in its own sandbox, which keeps changes to the chat’s folder and has no internet. Gemini chats aren’t sandboxed yet.
OpenCode has no reviewer of its own, so at Approve for Me, Outmake is its reviewer: a command in the sandbox and a change to a file in the chat’s folder go ahead, and anything else asks you.
ChatGPT uses its own sandbox, which lets it change files in the chat’s folder without asking, even at Ask for Approval. So below Full Access, a ChatGPT chat whose folder is your home folder works in an empty folder of its own instead, and asks before writing anywhere else. To have ChatGPT work on a project, start the chat in that project’s folder.
When Outmake starts one of your apps and a chat below Full Access works on it, its server runs in a sandbox too, since that chat could have written its code: it can reach the internet and write in the app’s folder, but it can’t read your keys or passwords or change anything that runs later. Where every chat on it is at Full Access, it runs as you started it.
A few things need more than the sandbox allows, like starting a new Git repository in a Claude chat, changing Git’s settings, or making a Git worktree or submodule. Use Full Access for those.
The always-ask list
Whatever the access level, six kinds of action stop an agent first. Under Full Access, Claude and OpenCode still stop for them; ChatGPT and Gemini may not.
- Sending messages or email
- Spending money
- Deleting things for good (moving something to the Trash is fine)
- Publishing or deploying
- Reading passwords and keys
- Running downloaded or hidden code
This is a net, not a sandbox: it's built from real patterns in commands and tool calls, not a hard wall around the agent, so treat it as a strong habit rather than a guarantee that nothing on this list can ever slip through reworded. If an agent does something you didn't want, Outmake can put back files it changed; it can't undo what a command did outside your files.