Skip to main content
Kova has five things that are commonly called a “mode”. They are unrelated, and collapsing them is the most common misunderstanding about the app. This page separates them completely.

1. Session mode (whether it may write)

  • agent: the full toolset
  • plan: structurally read-only; writes the plan with plan_write, and implements only after plan_exit approval (the model can call plan_enter itself)
  • ask: a read-only subset (no bash); when code changes are needed it proposes a tier switch through the ask_needs_work exit tool
  • goal: full toolset plus cross-turn autonomy — see Goal mode

2. Approval level (whether it must ask)

Interpreter and destructive commands (node / bash / npx / pnpm dlx / sudo / rm / cp / find) get no “remember” button: everything after the first word is the code to execute or an arbitrary path, so one click would mean a permanent free pass. The card says outright that the approval is for this one time. The fine print — the three buttons, the prefix rules and their guards, and the writable-root list — lives in the Agent engine.
Shift+Tab cycles through the four approval levels. The two dimensions are separate: session mode decides whether it may write, the approval level decides whether it must ask.

3. Work mode (who it is for)

Orthogonal to session mode: that one switches permissions and shape, this one switches audience. The design tier has a gate — if the ui-design plugin is missing or disabled it walks you through installing it first.

4. The automation policy tier (for unattended runs)

Same name as the approval level, and the two now decide the same way:
  • “Auto in workspace” (approval level) decides by path: it tells whether the target file is inside the workspace or the writable-root list, and asks when it cannot tell;
  • “Writable workspace” (automation tier) also decides by path: write / edit pass only inside the workspace or the machine-local writable-root list, and anything beyond that is rejected on the spot; bash, MCP and the config tools are rejected too. The only difference is that nobody can be asked, so “would ask” becomes “denies”.
The two even look identical (the automation editor deliberately reuses the ModePicker’s capsule shape), so judging by name will be wrong almost every time. The automation default was also tightened from workspace-write to read-only — the safe default when unattended.
Historically this tier decided by tool category, ignoring paths (write / edit always passed), so the boundary its name promised did not exist: an unattended run could write outside the workspace. If you really want “write anywhere”, choose full instead of an in-between tier that does not mean what it says.

5. Things that are not modes at all

6. Where each one is stored

Next

How this permission model adjudicates when nobody is watching.