Enter plan mode
/mode to choose between normal, plan, orchestrate, auto, and yolo modes. Normal is the startup default. If multiple explicit startup modes are present, the safer mode wins: plan, then orchestrate, then normal, then auto, then yolo.
What can run
Plan mode allows file reading, search, file metadata, paged tool-result reading, web fetch and search, skill loading, memory search, and clarification questions. Interactive plan mode also allowsshell, but every command asks for approval, even when shell is always allowed in normal mode; headless --plan and subagent workers keep it denied. It denies processes, Python, Bun, general writes and edits, subagents, and every MCP tool.
Why an allowlist: New skills and MCP servers can add tools the host has never seen. In plan mode, unknown tools are denied rather than assumed harmless.
One writable destination
Markdown plans directly insidedocs/plan/ are the only writes plan mode permits. The recommended name is docs/plan/YYYY-MM-DD-feature-name.md.
--auto-approve because nobody is present to approve them; the plan-directory fence still applies.
Approve and implement
After a successful interactive turn writes or revises a plan, the TUI asks whether to approve it and start implementing, once queued prompts have finished. This is a separate yes/no decision from approving the file write.yswitches to normal mode and starts an implementation turn referencing the saved plans. Normal tool approvals still apply.nkeeps plan mode on. The prompt is not repeated until a plan is written or revised.
/mode normal; the host reports plans successfully written during the episode. Headless runs do not perform this interactive approval-to-implementation handoff.