> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/assist/concepts/permissions-and-privacy.md).

# Permissions & Privacy

{% hint style="warning" %}
Assist is new in the IDA 9.5 beta, and its documentation is subject to change. Treat it as a work in progress rather than a finished reference.
{% endhint %}

Assist can read your database, run code, and (when allowed) modify the database, run Python, use a shell, or write files. Because an AI agent is deciding what to do, the permission model is designed so that nothing consequential happens without a decision you can see and make. You can edit this under **Settings → Permissions**.

## The permission model

Each capability can be set to:

* **On**: the agent may use it freely.
* **Off**: it is removed from the advertised tool list and blocked from executing.
* **Ask when needed**: the agent may request it mid-turn, and you approve or deny it with a permission card.

### Permission cards

When the agent requests a capability that requires approval (a shell command, Python, the debugger, or a file write), Assist shows a **permission card** for you to approve or deny.

### Defaults

Out of the box, reading files is enabled. Capabilities that require approval are seeded to **Ask when needed**.

{% hint style="info" %}
**Capability ceilings and external clients.** A capability set to **Off** applies to MCP clients and mesh peers as well, and they cannot use the interactive escalation path. A capability set to **Ask** is therefore effectively unavailable to an external agent; it will receive a refusal rather than a prompt. Choose **On** or **Off** for capabilities you want automation to use.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/assist/concepts/permissions-and-privacy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
