Configure DSH plugin permission presets and approval prompts

Configuration & UsagePublished 2026-10-02Author: DeepSeek Plugin Market
DeepSeek HarnessDSH pluginpermission presetsapprovalworkspace-write
DeepSeek Harness permissions combine presets and approval policy: workspace-write and danger-full-access bound writes, while approval is ask or never.

DeepSeek Harness permissions come from two parts: a permission preset decides what can be written, and an approval policy decides whether to ask. The defaults are workspace-write (with ask) and danger-full-access (with never); the fields are presets and defaultPreset. This covers both presets, both approval policies, and custom definitions.

DeepSeek Harness permission presets: workspace-write and danger-full-access

DeepSeek Harness ships two permission presets: workspace-write confines writes to the workspace and pairs with ask, while danger-full-access opens machine-wide writes with approval set to never (source). Two presets, compared:

  1. The default, workspace-write — in effect without extra configuration. Expected: writes inside the workspace succeed; out-of-bounds actions are intercepted and go to approval.
  2. The open preset, danger-full-access — used when an agent must operate machine-wide. Expected: writes are no longer confined to the workspace and no prompt appears.
  3. Select the default with defaultPreset — explicitly set defaultPreset to choose the startup preset. Expected: leaving it unset falls back to the built-in workspace-write.
  4. Verify behavior after switching — run an out-of-bounds write. Expected: if it is still blocked, the preset did not take effect or was written to the wrong profile.

DeepSeek Harness approval policy: ask, never and four outcomes

DeepSeek Harness's ApprovalPolicy is ask or never and defaults to ask; under ask sensitive actions prompt and can resolve as allowed-once, rejected, cancelled or unavailable (source). Read them like this:

  1. ask (default) — asks the user before authorizing an action. Expected: the usual mode for interactive use.
  2. never — proceeds per the preset without asking. Expected: common for unattended or automated runs, but it removes the human gate.
  3. allowed-once — the grant applies to this one action only. Expected: it does not become a permanent allowance.
  4. rejected / cancelled — the user declined, or the action was cancelled. Expected: the agent should stop or reroute, not retry the same step.
  5. unavailable — no approval channel is available. Expected: frequent in headless runs; switch to never or the flow waits forever.

DeepSeek Harness custom permissions: presets, defaultPreset and the reserved name

Define custom permissions with Config.presets and pick a default with Config.defaultPreset; custom is a reserved name and cannot be used as an ordinary preset (source). The fields:

  1. presets — a map keyed by preset name, each describing a scope plus approval policy.
  2. defaultPreset — names the preset used at startup. Expected: the name must match a key in presets.
  3. Avoid the reserved name custom — do not name a custom preset custom. Expected: using it collides with the reserved semantics.
  4. Package a team standard — fold common combinations into one preset that applies after plugins are installed. Expected: new members need not memorize every parameter.
  5. Write it to the right profile — permissions apply per profile just like plugins. Expected: the wrong profile looks like "switching had no effect".

The more a permission tier opens up, the higher the cost of a third-party plugin overstepping. Before installing DSH plugins, check the plugin source and its permission needs on DSH Plugin Hub.

Settings

DeepSeek Harness permission cautions and limits

  1. never cuts both ways: it removes the prompt and also the last human confirmation, so use it only in trusted workspaces.
  2. unavailable is a missing channel, not a bug: headless scenarios should decide on never rather than wait for a prompt.
  3. custom is reserved: name custom presets something else to avoid a semantic clash.
  4. Read presets and approval as a pair: changing only the scope or only the policy can produce surprising behavior.
  5. Permissions only bound actions: they do not decide whether a model works or a plugin installs — see configuring model providers and how DeepSeek Harness merges plugin config.

Sources: Permission presets (official docs), Approval (official docs)

FAQ

Which permission preset does DeepSeek Harness use by default, and what can it write?

DeepSeek Harness defaults to the workspace-write preset, which confines writes to the workspace and pairs with ask approval — a safe default. Switch to danger-full-access only when an agent must write across the machine, as that preset pairs with never.

What is the difference between workspace-write and danger-full-access in DeepSeek Harness?

workspace-write allows writes only inside the workspace and routes out-of-bounds actions through approval, while danger-full-access opens filesystem writes across the machine with approval set to never. The first is safe, the second convenient but risky.

How do I set ask versus never approval in DeepSeek Harness, and what outcomes exist?

The ApprovalPolicy in DeepSeek Harness is ask or never and defaults to ask. Under ask, sensitive actions prompt and can resolve as allowed-once, rejected, cancelled or unavailable; never executes without asking.

Why does DeepSeek Harness approval return unavailable?

unavailable means no approval channel is available, common in unattended headless runs or when nothing is wired to the trigger. Such scenarios should use the never policy, otherwise the flow waits for approval that never comes.

How do I define a custom permission preset in DeepSeek Harness, and what is the reserved name custom?

DeepSeek Harness defines custom presets with Config.presets and selects the default with Config.defaultPreset, while custom is a reserved name you cannot reuse as an ordinary preset. Custom presets are useful for packaging a scope plus policy as a team standard.

Related Terms

permission preset
A permission preset is the unit in DeepSeek Harness that packages a write scope with an approval policy; presets are defined through Config.presets and selected through Config.defaultPreset, and workspace-write plus danger-full-access ship by default.— DeepSeek Harness official docs - Permission presets
workspace-write
workspace-write is the default permission preset of DeepSeek Harness, confining writes to the workspace and pairing with ask approval so out-of-bounds actions need user confirmation.— DeepSeek Harness official docs - Permission presets
defaultPreset
defaultPreset is the field in DeepSeek Harness permission configuration that names the preset in effect by default; when unset, the built-in workspace-write is used.— DeepSeek Harness official docs - Permission presets
ApprovalPolicy
ApprovalPolicy is the approval type in DeepSeek Harness, taking the value ask or never and defaulting to ask; ask prompts for sensitive actions and never proceeds without asking.— DeepSeek Harness official docs - Approval

Sources