← Mathematical compendium

Published equation contexts

decision(c)={deny,c∈Dask,c∉D and c∈Aallow,c∉D∪A and c∈Wask (default),otherwise\text{decision}(c) = \begin{cases} \text{deny}, & c \in D \\ \text{ask}, & c \notin D \text{ and } c \in A \\ \text{allow}, & c \notin D \cup A \text{ and } c \in W \\ \text{ask (default)}, & \text{otherwise} \end{cases}

Why this formula appears here

The precedence is simple enough to state directly. For a tool call c checked against the deny set D , the ask set A , and the allow set W : decision(c)={deny,c∈Dask,c∉D and c∈Aallow,c∉D∪A and c∈Wask (default),otherwise\text{decision}(c) = \begin{cases} \text{deny}, & c \in D \\ \text{ask}, & c \notin D \text{ and } c \in A \\ \text{allow}, & c \notin D \cup A \text{ and } c \in W \\ \text{ask (default)}, & \text{otherwise} \end{cases}. An unmatched command does not fail open into silent execution. It falls through to a prompt — what the documentation calls fail-closed matching [ 2 ] .

Read the full article-specific guide →

Read the representative guide

How to interpret it

Read it with the definitions, units, and assumptions supplied by the article.

Research cited beside this formula

Published contexts (1)

A symbol can carry a different meaning in another article. Each occurrence keeps its own guide and term definitions.

decision(c)={deny,c∈Dask,c∉D and c∈Aallow,c∉D∪A and c∈Wask (default),otherwise\text{decision}(c) = \begin{cases} \text{deny}, & c \in D \\ \text{ask}, & c \notin D \text{ and } c \in A \\ \text{allow}, & c \notin D \cup A \text{ and } c \in W \\ \text{ask (default)}, & \text{otherwise} \end{cases}

Equation 5 · AI Agents & Systems

What Claude Code's Permission Model Actually Allows, in Plain Terms

This equation states an equality: the expressions on both sides have the same value under the article’s assumptions.

The precedence is simple enough to state directly. For a tool call c checked against the deny set D , the ask set A , and the allow set W : decision(c)={deny,c∈Dask,c∉D and c∈Aallow,c∉D∪A and c∈Wask (default),otherwise\text{decision}(c) = \begin{cases} \text{deny}, & c \in D \\ \text{ask}, & c \notin D \text{ and } c \in A \\ \text{allow}, & c \notin D \cup A \text{ and } c \in W \\ \text{ask (default)}, & \text{otherwise} \end{cases}. An unmatched command does not fail open into silent execution. It falls through to a prompt — what the documentation calls fail-closed matching [ 2 ] .

Meanings in this article

  • AA: the ask set.
  • WW: the allow set.
Equation guide → · Article →