Equation 5 · What Claude Code's Permission Model Actually Allows, in Plain Terms
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol c
c is an argument of the function-like quantity on the left; its role is set by that function’s stated inputs.
Symbol D
D is an input to the expression that computes the quantity on the left.
=
The expressions on both sides represent the same quantity under the stated assumptions.
See an illustrated explanation →How to interpret it
Read it with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
The precedence is simple enough to state directly. For a tool call c checked against the deny set D , the ask set A , and the allow set W : . An unmatched command does not fail open into silent execution. It falls through to a prompt — what the documentation calls fail-closed matching [ 2 ] .
Sources cited in the surrounding passage
These citations give research context. Read each source to check which claims it supports.
Return to What Claude Code's Permission Model Actually Allows, in Plain Terms