2.2 Modes and Governance

Info
⏱ Duration: ~45 min · 🎯 Goal: read the Manual/Auto/Skip matrix against each connector’s permission and draft your team’s mode policy.

Automating without governance is a risk. Before leaving tasks running on their own, your team needs clear rules about who approves what. There are three modes, switchable anytime from the selector in the message box, and their behavior depends on each connector’s permission.

Step 1 — Read the matrix

Every connector has a tool permission: Always allow, Needs approval, or Blocked. The chosen mode crosses with that permission like this:

Mode Always allow connector Needs approval connector Blocked connector
Manual (formerly “Ask before acting”) Approved Asks permission Denied
Auto Read-only approved; write/delete → Claude decides Claude decides Denied
Skip (formerly “Act without asking”) Approved Approved Denied

Step 2 — Understand Auto mode

  • Claude reviews each action for safety (data-exfiltration and prompt-injection checks) and automatically blocks anything unsafe; if something is blocked, it finds a safer path or asks you. If it keeps hitting blocks, it reverts to asking per-step.
  • It will NOT auto-approve sensitive actions: granting access to new folders, deleting files in an accessible folder, and creating scheduled tasks, among others.
  • It consumes more usage limit than other modes (extra safety checking).
  • Official recommendation: for work with real consequences —money, messages sent as you, important files— stay close or switch back to Manual.

Step 3 — Understand Skip mode

Warning
Skip (verbatim): “Claude doesn’t pause to ask and nothing checks its actions automatically. Only use this when you completely trust every action, connector, file, app, etc. involved.”
Tip
Deletion protection in ALL modes: Cowork requires explicit permission before permanently deleting files —you must click “Allow”, even in Skip.
Info
Team/Enterprise override: the organization can require per-task approval on write-capable connector tools, so “Always allow” preferences may not apply.

Step 4 — Executive exercise: draft your mode policy

Use politica/plantilla-politica-modos.docx from the zip. With Cowork, draft your division’s mode policy:

Based on politica/plantilla-politica-modos.docx, draft my team's mode policy.
Classify our typical tasks into Manual, Auto, or Skip.
Rule: money, external messages, and important files → Manual.
No task in Skip without a director's approval.
Justify each classification in one sentence.
Save it as politica-de-modos.docx.

Step 5 — Peer review (~15 min)

Swap your politica-de-modos.docx with your neighbor and hunt for a gap: a misclassified task, a missing rule, or a case in Skip without approval. Return one concrete observation and adjust your policy with your neighbor’s in view. A mode policy gets better when another director stress-tests it.

✅ Checkpoint

There is a politica-de-modos.docx with your tasks classified into Manual/Auto/Skip, the “money/messages/important files → Manual” rule applied, and no task in Skip without approval. You can explain why Auto does not auto-approve deletions or scheduled-task creation.

Got it? — 2 questions

1. In Auto mode, what happens with a connector marked “Needs approval”? Claude decides: it reviews the action for safety and acts if it’s safe, or asks you; it never auto-approves it like Skip does.

2. What protection exists in all three modes? Permanent file deletion always requires your explicit “Allow” click, even in Skip.


Workshop Claude Avanzado · Grupo Salinas · v1.0 · 2026