OpenRig
← All of OpenRig 0.6.6

ChangedOpenRig 0.6.6

Claude Code agents in your teams can run OpenRig commands, read the project and run its tests without a permission prompt, but still ask before starting, stopping or installing teams. It's an allow list, not a sandbox, and applies only where you haven't set permissions yourself.

Claude Code agents in your teams need fewer permission prompts. OpenRig passes an allow list and an ask list at launch, so rig commands, reads inside the project and common test commands such as npm test, pytest, go test and cargo test run without a prompt, while lifecycle commands such as rig up, rig down, rig bundle install, rig seat stop and rig daemon stop still ask.

Applies outside the kernel at an agent's next launch, resume, fork or handover, only when no member or rig `permission_policy` and no saved permission choice is set; `permission_policy: none` keeps the old behaviour. These are command allowances, not containment: a project's test command runs project code. Your own ask and deny rules still apply, and no settings file is written. Asking before lifecycle commands works in Claude Code team agents only; Codex team agents don't ask yet. In a Claude Code team agent, `rig down --help` also asks; `rig help down` prints the same help without a prompt. `rig setup`'s permission question still describes the behaviour before these defaults; its text is corrected in the next release.

Pull request
#893