Made for the way you work

Hooks, permissions, and trust

Make important boundaries explicit. Guidance tells an agent what you want; controls decide what actions can run.

In practice

A useful place to start

Require a check before a tool writes to a protected area, or ask for approval before a sensitive command. Read the request in the chat before making the decision.

Checks around actions

Hooks let you connect checks and workflow actions to supported agent events. They can add context or participate in decisions about whether a tool may proceed.

Clear human decisions

Question and permission cards keep choices visible in the chat. Secret requests use masked inputs, so sensitive values need not become ordinary conversation text.

Trust the workspace first

Restricted Mode limits active capabilities in untrusted workspaces. Enable tools and configuration deliberately, and inspect the sources of rules, hooks, and connected servers.

Get started

Review workspace trust when opening a project. Configure hooks and permissions for the boundaries you need, then test both allowed and blocked cases.

Good to know

Hooks can run programs and deserve review. Autopilot can answer permission cards when enabled, so leave it off when those decisions must be made by you.

Your next step starts here.

Get Pumpkin All features