Enterprise policy to allow yolo in CLI sandbox
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 11.2k
- Forks
- 1.9k
- Avg merge
- 14h 16m
- Merged PRs (30d)
- 6
Description
Describe the feature or problem you'd like to solve
There should be a separate policy scope for cli sandboxes for yolo mode and other permission related enterprise policies
Proposed solution
Enterprise policies allow restrictive access for setting like yolo mode, and other folder/tool settings. These are generally used because of trust within an enterprise environment, where broad tool access could cause damage. The point of sandbox mode is to create a 'safe place' for developers to work agentically. Currently, when yolo mode is disabled by enterprise policy, it applies to both standard and sandbox mode. Ideally, enterprise policies should have a separate sandbox hierarchy where any policy which could make sense to configure more permissively would allow a separate setting.
Example prompts or workflows
No response
Additional context
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by tracing the existing enterprise policy handling for yolo mode and the CLI sandbox, then identify which permission-related settings need a separate sandbox scope. Done means sandbox mode can use its own policy hierarchy without changing the restrictions for standard mode.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- shell
- Domain
- authorization, cli, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100