Skip to content

Leadership1 publisher3 min readPublished

Anthropic's Chrome permission drop-down leaves agent oversight to whoever is at the keyboard

Anthropic has renamed the three permission modes for Claude in Chrome to Manual, Auto and Skip all approvals. In Skip, by the company's own guide, nothing checks the agent's actions, and the extension remembers the choice.

The Board Room · Leadership desk

Illustration accompanying Anthropic's Chrome permission drop-down leaves agent oversight to whoever is at the keyboard

What happened

  • Anthropic's support guide sets out three permission modes for Claude in Chrome, chosen from a drop-down on the chat input in the extension side panel or in Claude Desktop.
  • Manual, formerly "Ask before acting", stops for approval before each action; Skip all approvals, formerly "Act without asking", acts without approval and runs no automatic check on what Claude does.
  • Auto keeps Claude working while reviewing each action for safety, blocking anything it judges unsafe and pausing to ask the user when it needs to.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision The oversight level for a browser agent is set per session at the keyboard, so an executive who has not matched a mode to a category of work has handed that call to user habit.
  • cost The mode that checks every action is the one that uses the most allowance, so a user whose limit is running down has a cost reason to pick the mode with no check.
  • exposure Under Skip, the always-blocked list is the entire remaining floor, and every connector, file and app the session can reach sits inside the agent's discretion.
  • constraint Manual with a plan holds Claude to a named set of websites, so work that needs breadth costs repeated approvals and gives teams a reason to switch to a looser mode.

The choice persists. Auto is the default mode in the Cowork side panel, and when a user switches to something else, the panel keeps that choice for future sessions [7]. Anthropic's guide documents the modes as a user-facing control on the chat input [1]. It does not describe an organisation-level setting that pins one mode in place [16].

That leaves a written policy as the instrument, and a policy has to match a mode to a kind of work. Anthropic's guide supplies the categories itself: for work with real consequences, naming money, messages sent as you and important files, it tells users to stay close and review what Claude does, or to switch back to Manually approve [14].

The usage pricing runs the other way. Auto reviews each action before it happens, including checks for data exfiltration and prompt injection [3][6], and Anthropic says that extra checking makes Auto consume more of a user's usage limit than the other modes [8]. Skip removes the pauses and the automatic review together [4]. So the mode that runs without interruption and costs the least allowance is the one with no review in it [18]. A user who runs short mid-task has an obvious way to keep going.

Anthropic's guide does not present Auto's check as a substitute for the user. "We tested Claude's safety check extensively before releasing it, including working with outside security experts who tried to sneak dangerous actions past it," Anthropic wrote of Auto [12], and then: "Of course, no defense is perfect and no mode replaces your judgment" [13].

Some actions stay blocked in every mode, including making purchases, creating accounts, bypassing bot authorizations, executing trades, permanently deleting files, and actions that suggest a prompt injection risk [9]. Under Skip, that list is all that remains. Anthropic's guide tells users to choose Skip only when they completely trust every action, connector, file and app involved in the task [5].

Auto has one property a policy can rely on. When it blocks an action it looks for a safer route or stops and asks, and if it keeps hitting blocks it reverts to asking permission at every step [15]. Manual keeps a human check on every action, Auto keeps a model check, and Skip runs without either [17].

Manual comes in two forms. In the classic side panel, Claude proposes a plan naming the websites it will visit and the approach it will take, and will not deviate from it without asking [10]. In the Cowork panel there is no plan, and each action comes to the user as Allow all for this website, Allow this time only, or Deny [11].

This quarter the decision is a paragraph in an acceptable-use note saying which mode goes with which work. The consequence arrives later, when something in a session goes wrong and the answer to which mode was running comes from the person who set it.

What to watch

  • Whether Anthropic publishes an administrator control that pins a permission mode for managed Chrome or Claude Desktop deployments.
  • Whether the usage cost of Auto changes, since that gap is what pushes a user who is short on allowance toward Skip.
  • Whether Anthropic documents a per-session record of which mode was in force, without which a written mode policy cannot be checked after the fact.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories