Read the five autonomy levels
By now, you’ve connected tools and assembled a team. There’s one question left, the one that decides whether you can sleep easy: what can the agent do without you?
A runtime/POLITICA.md responds with five levels, from N0 to N4. The file's first line sums up the idea: the greater the impact of the action, the more the human is involved.
🆕 New here? Three words from this module
- Autonomy — how much the agent acts on its own without waiting for your “go ahead.”
- Level (N0 to N4) — the degree of autonomy. N0 is just conversation. N4 means acting without even notifying you.
- "Prepare and ask" — the kit’s default: the agent gets everything ready and asks before doing anything with an impact.
| Level | The agent… |
|---|---|
| N0 | conversation only |
| N1 | prepares; the human executes |
| N2 | runs after asking, each time |
| N3 | run it automatically and notify me |
| N4 | run it automatically, without notifying me |
What to look for in the table: it’s the exact copy of the “Autonomy levels” section from the POLITICA.md. The difference between N1 and N2 is who presses the button: in N1, you do; in N2, the agent does, with your approval.
How to read the diagram: each step gives the agent more freedom. The amber step (N2) is where the kit puts everything with an impact. The blue steps are for actions that, if they go wrong, you can undo without trouble.
conversation only
you run
asks each time
acts and notifies, or doesn't even notify
Use the cap for each type of action
The levels alone don’t mean anything. They make sense when you connect each action type to a maximum level. It's the second table in the POLITICA.md, the one for cap.
The last two columns show how each cap becomes a configuration: in Claude Code and Codex. You’ll see both in topics 4 and 5.
🆕 New here? What is a "ceiling"
Limit is the highest level an action can have. Nothing goes above it—not the agent, not an impulsive click. You can be stricter below it: the ceiling is a maximum, not a requirement.
| Action | Limit | In Claude Code | In Codex |
|---|---|---|---|
| Read a file, page, or spreadsheet | N4 | allowed | -s read-only |
| Create/modify project file | N3 | acceptEdits | -s workspace-write |
| Command that changes the system | N2 | asks for confirmation | without auto-approval |
| Send (email, message, post, push) | N2 | asks for confirmation | without auto-approval |
| Spend money or credits | N1 | blocked | do not execute |
| Delete data / production | N1 + backup | blocked (rm -rf) | do not execute |
What to look for in the table: The ceiling drops as the possible damage increases. Reading doesn't break anything (N4). Spending and deleting can't be undone (N1): the agent prepares it, and you do it.
Clara and the schedule
Read the spreadsheet for finding an available time is "read spreadsheet": N4. The agent responds without asking.
Change the calendar affects real patients. The calendar is not a project draft file: it is clinic data in use. Clara treats it as a command that changes the system: N2, the agent asks each time.
Sônia and the client’s money
Adding up the sales CSV is reading: N4. Creating the report in a new file is changing a project file: N3.
Paying for a guide, issuing a boleto, or spending credits counts as “spending money”: N1. The agent gets everything ready, and Sônia pays.
Open claude in the kit folder and paste:
Leia runtime/POLITICA.md e responda em uma linha qual é o teto de 'Enviar'.
Result confirmed in CHANGELOG 0.2.0 (same question, in a background session):
respondeu "N2" lendo a POLITICA
N2. Replace 'Send' with 'Spend money or credits' and the answer has to be N1.N4 cap
N3 cap
N2 cap
N1 cap
Understand why "always allow" has a limit
When Claude Code asks for permission, it offers "yes," "no," and an option to stop asking. By the tenth question in a row, the temptation is to click the third option. In one of the mod videos, there was even a helper that approved permissions on its own.
A POLITICA.md close that door with a sentence: a "always allow" permission never exceeds the action limit. You can allow reading forever. You can't allow payments forever.
✓ "Always allow" makes sense
- ✓ Read Clara’s calendar (N4 ceiling)
- ✓ Read Sônia’s sales CSV (N4 ceiling)
- ✓ Create a report in the project folder (N3 ceiling)
- ✓ Run the
doctor.mjs, which only observes and reports
✗ “Always allow” exceeds the limit
- ✗ Send a message to a patient (N2 limit: asks each time)
- ✗ Do
pushin the repository (N2 limit) - ✗ Pay Sônia’s client’s bill (N1 cap)
- ✗ Delete a folder with
rm -rf(N1 + backup)
Fatigue
Lots of questions in a row, all harmless. You stop reading and start approving automatically.
Broad authorization
One click on "don't ask again" applies to all similar cases, including dangerous ones.
The cap holds
Even when enabled, anything above the limit remains blocked or keeps asking. That’s what topic 4 shows in action.
⚠️ Be careful with the mode that allows everything
Claude Code has a permission mode that doesn't ask anything. It's intended for tests in a disposable folder. If you use it, the only thing that still protects you is what's written as a block in .claude/settings.json. That's why N1 restrictions stay in the file, not in your memory.
💡 Phrase to remember
"Always allow" is a shortcut for what’s safe to repeat. For anything with an impact, the question itself is the control: if it goes away, the control goes with it.
only up to the cap
the actual risk
doesn’t depend on a click
it’s the control
See the block in Claude Code
In Claude Code, the policy becomes the file .claude/settings.json, which is included in the kit. Claude Code reads this file automatically when it opens in the folder.
The part that matters here is the list deny: commands the agent doesn't run; ask whoever requests them. These are the basic blocks that the POLITICA.md mentions "delete" and the forced push.
🆕 New here? Three terms from settings.json
- settings.json — the Claude Code configuration file for this folder. Plain text that you can open and read.
- deny — "deny." List of commands Claude Code refuses without asking. The
:*at the end means "with anything after it." - hook — a small program that Claude Code runs before or after each action. The kit uses hooks for the guard (module 4.3).
{
"permissions": {
"deny": [
"Bash(rm -rf:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)"
]
},
"enabledMcpjsonServers": [
"ponte-modelo"
],
"hooks": { ... }
}
hooks turn on the guard (collision and radius) before and after each edit and each command. It is summarized here with ... and is the subject of module 4.3.How to read the diagram: both requests go through the same amber box. Anything not on the list follows the blue arrow. Anything on the list stops at the red arrow, without asking and without depending on you watching.
Result confirmed in CHANGELOG 0.1.0
The test used Claude Code without a screen, in the permission mode that allows everything, asking it to do two things: create an empty file and delete it with rm -rf.
touch run; rm -rf denied by the .claude/settings.json.
💡 Adjust for your use case
Step 3 of the LEIA-ME.md says: read the POLITICA.md and adjust the .claude/settings.json if needed. If Clara has a command that overwrites the schedule, it’s a good candidate to add to the list deny or stay at N2.
already comes with the kit
4 denied commands
the guard, in 4.3
CHANGELOG 0.1.0
Apply the policy in Codex
Codex doesn't read the .claude/settings.json. In it, the policy comes through the sandbox, selected with the option -s for each call. The quota table already tells you which one to use.
The bridge runtime/pontes/codex-exec.sh, which you used in module 2.1, only accepts two values. Any other value is rejected before Codex is called.
🆕 New here? What is a sandbox
Sandbox ("sandbox") is a fence around the program. In the read-only Codex only reads. In workspace-write it also writes, but only inside the specified folder. There is also a mode with no restrictions at all, and that's the one the bridge rejects.
| Sandbox in the bridge | POLITICA line | Limit |
|---|---|---|
read-only (default) | Read a file, page, or spreadsheet | N4 |
workspace-write | Create/modify project file | N3 |
| any other | rejected: sandbox recusado pela POLITICA | — |
What to look for in the table: sending, spending, and deleting have no sandbox in the bridge. For those rows, POLITICA says "no auto-approval" or "do not execute": Codex prepares it, and the action is up to you.
In the terminal, from inside the kit folder:
runtime/pontes/codex-exec.sh "x" . danger-full-access
Result confirmed in CHANGELOG 0.1.0:
sandbox recusado pela POLITICA, saída 2
case "$sandbox" in read-only|workspace-write) ;; *) echo "sandbox recusado pela POLITICA: $sandbox" >&2; exit 2 ;; esac
💡 Why the refusal stays in the bridge
If Claude asks Codex using the wrong shortcut, the bridge blocks it first. The rule is in one place, in four lines you can read. Anyone who wants to change it has to edit the file, and that shows up in Git.
read, N4
modify, N3
rejected, exit code 2
the rule in one place
Follow the three integration rules
Beyond the levels and the cap, the POLITICA.md has a short section called Integration. These are three rules about how the tools connect to one another.
They protect what no deny takes: your account, password, and system stability.
Only official tools through the subscription (Claude Code, Codex CLI).
No borrowed API key or parallel client. Each agent signs in with its own login.
Never pass a tool's credentials to another tool.
When Claude calls Codex through the bridge, Codex uses its own login. Claude doesn't hand over a password, token, or cookie to anyone.
Reverse engineering is a lab: make a note in LIMITES.md and don't use it in production.
It’s the course’s thesis turned into a rule. Module 4.2 shows the LIMITES.md and 4.4 covers the lab.
🆕 New here? Credential
Credential is anything that proves who you are to a system: a password, token, key, or session cookie. Whoever has the credential can act on your behalf.
How to read the diagram: the amber bridge only passes text: the request goes in, the response comes back. Logins each stay in their own box. The red dashed line is the path that rule 2 prohibits.
Quick test (optional): Sônia clicked "always allow" when the agent asked to pay a bill. Which rule applies?
official tool
stays where it is
reverse engineering
where it's recorded
🎓 Module summary
Next module:
4.2 — The agent proposes, you approve