Configure DSH plugin permission presets and approval prompts
DeepSeek Harness permissions come from two parts: a permission preset decides what can be written, and an approval policy decides whether to ask. The defaults are workspace-write (with ask) and danger-full-access (with never); the fields are presets and defaultPreset. This covers both presets, both approval policies, and custom definitions.
DeepSeek Harness permission presets: workspace-write and danger-full-access
DeepSeek Harness ships two permission presets: workspace-write confines writes to the workspace and pairs with ask, while danger-full-access opens machine-wide writes with approval set to never (source). Two presets, compared:
- The default,
workspace-write— in effect without extra configuration. Expected: writes inside the workspace succeed; out-of-bounds actions are intercepted and go to approval. - The open preset,
danger-full-access— used when an agent must operate machine-wide. Expected: writes are no longer confined to the workspace and no prompt appears. - Select the default with
defaultPreset— explicitly setdefaultPresetto choose the startup preset. Expected: leaving it unset falls back to the built-inworkspace-write. - Verify behavior after switching — run an out-of-bounds write. Expected: if it is still blocked, the preset did not take effect or was written to the wrong profile.
DeepSeek Harness approval policy: ask, never and four outcomes
DeepSeek Harness's ApprovalPolicy is ask or never and defaults to ask; under ask sensitive actions prompt and can resolve as allowed-once, rejected, cancelled or unavailable (source). Read them like this:
ask(default) — asks the user before authorizing an action. Expected: the usual mode for interactive use.never— proceeds per the preset without asking. Expected: common for unattended or automated runs, but it removes the human gate.allowed-once— the grant applies to this one action only. Expected: it does not become a permanent allowance.rejected/cancelled— the user declined, or the action was cancelled. Expected: the agent should stop or reroute, not retry the same step.unavailable— no approval channel is available. Expected: frequent in headless runs; switch toneveror the flow waits forever.
DeepSeek Harness custom permissions: presets, defaultPreset and the reserved name
Define custom permissions with Config.presets and pick a default with Config.defaultPreset; custom is a reserved name and cannot be used as an ordinary preset (source). The fields:
presets— a map keyed by preset name, each describing a scope plus approval policy.defaultPreset— names the preset used at startup. Expected: the name must match a key inpresets.- Avoid the reserved name
custom— do not name a custom presetcustom. Expected: using it collides with the reserved semantics. - Package a team standard — fold common combinations into one preset that applies after plugins are installed. Expected: new members need not memorize every parameter.
- Write it to the right profile — permissions apply per profile just like plugins. Expected: the wrong profile looks like "switching had no effect".
The more a permission tier opens up, the higher the cost of a third-party plugin overstepping. Before installing DSH plugins, check the plugin source and its permission needs on DSH Plugin Hub.

DeepSeek Harness permission cautions and limits
nevercuts both ways: it removes the prompt and also the last human confirmation, so use it only in trusted workspaces.unavailableis a missing channel, not a bug: headless scenarios should decide onneverrather than wait for a prompt.customis reserved: name custom presets something else to avoid a semantic clash.- Read presets and approval as a pair: changing only the scope or only the policy can produce surprising behavior.
- Permissions only bound actions: they do not decide whether a model works or a plugin installs — see configuring model providers and how DeepSeek Harness merges plugin config.
Sources: Permission presets (official docs), Approval (official docs)
FAQ
DeepSeek Harness defaults to the workspace-write preset, which confines writes to the workspace and pairs with ask approval — a safe default. Switch to danger-full-access only when an agent must write across the machine, as that preset pairs with never.
workspace-write allows writes only inside the workspace and routes out-of-bounds actions through approval, while danger-full-access opens filesystem writes across the machine with approval set to never. The first is safe, the second convenient but risky.
The ApprovalPolicy in DeepSeek Harness is ask or never and defaults to ask. Under ask, sensitive actions prompt and can resolve as allowed-once, rejected, cancelled or unavailable; never executes without asking.
unavailable means no approval channel is available, common in unattended headless runs or when nothing is wired to the trigger. Such scenarios should use the never policy, otherwise the flow waits for approval that never comes.
DeepSeek Harness defines custom presets with Config.presets and selects the default with Config.defaultPreset, while custom is a reserved name you cannot reuse as an ordinary preset. Custom presets are useful for packaging a scope plus policy as a team standard.
Related Terms
- permission preset
- A permission preset is the unit in DeepSeek Harness that packages a write scope with an approval policy; presets are defined through Config.presets and selected through Config.defaultPreset, and workspace-write plus danger-full-access ship by default.— DeepSeek Harness official docs - Permission presets
- workspace-write
- workspace-write is the default permission preset of DeepSeek Harness, confining writes to the workspace and pairing with ask approval so out-of-bounds actions need user confirmation.— DeepSeek Harness official docs - Permission presets
- defaultPreset
- defaultPreset is the field in DeepSeek Harness permission configuration that names the preset in effect by default; when unset, the built-in workspace-write is used.— DeepSeek Harness official docs - Permission presets
- ApprovalPolicy
- ApprovalPolicy is the approval type in DeepSeek Harness, taking the value ask or never and defaulting to ask; ask prompts for sensitive actions and never proceeds without asking.— DeepSeek Harness official docs - Approval
Sources
- DeepSeek Harness official docs - Permission presets· deepseek-ai
- DeepSeek Harness official docs - Approval· deepseek-ai