Overview

Loop gives you fine-grained control over what the agent is allowed to do. Configure per-tool approval policies, file edit review behavior, and project-level trust gates.

Tool Permissions

Each built-in tool has a configurable permission policy:

Default Permissions

By default, read runs freely while write, edit, and bash require your approval.

Setting Permissions

In ~/.loop/agent/settings.json:

Session-Scoped Approval

When prompted to approve a tool call, you can choose to accept all for the remainder of the session. This lets you start with safety checks and then streamline once you trust the agent’s approach.

File Edit Review

Control how file edits are reviewed:

Slash Command

Settings

External Diff Review

Loop can open file diffs in an external editor for review:
Supported editors: When enabled, file edits open a side-by-side diff in your editor, and you approve or reject from there.

Project Trust

Loop supports project-level configuration via .loop/settings.json in your project root. For security, these overrides are only loaded when the project is trusted.

Trust Gate

When Loop encounters a .loop/settings.json in an untrusted project, it prompts you:

Managing Trust

Trust state is stored in ~/.loop/agent/trust.json.

Default Trust Policy

Project-Level Overrides

When a project is trusted, .loop/settings.json overlays the global settings:
This lets teams share consistent agent settings per-project.
Only trust projects from sources you control. Malicious project settings could configure permissive tool policies.