# Let Claude Code Work on a Whole Repo Safely

> Branch, plan, deny the destructive commands, review in small chunks. Auto mode now starts on by default, so don't assume Claude will stop and ask.

- Canonical: https://guides-ai.pages.dev/guides/claude-code-whole-codebase-safely/
- Plate 04.01 · Topic: Workflows (https://guides-ai.pages.dev/topics/workflow/)
- Published: 10 Jun 2026 · Updated: 06 Sept 2026 · 4 min read
- Source site: guides-ai — https://guides-ai.pages.dev/

Letting an agent loose on a whole repo is fine, with guardrails. Start with the one that has
changed: **on Pro, Max and Team plans, interactive terminal sessions now start in auto mode**,
where a classifier approves actions instead of you. Do not assume it will stop and ask.

## 1. Check the mode first

The status bar tells you: `⏵⏵ auto mode on` versus `⏸ manual mode on`. Press `Shift+Tab` to
move to Manual if you want a prompt before each action. Full detail in
[permissions and allowlists](/guides/claude-code-permissions/).

## 2. Work on a branch

```bash
git checkout -b ai/feature-x
```

What it does: gives you a throwaway. If the session goes sideways you delete the branch instead
of unpicking commits on `main`.

## 3. Plan before multi-file changes

Press `Shift+Tab` into [plan mode](/guides/claude-code-plan-mode/), or prefix a single prompt
with `/plan`. Claude reads and proposes; edits stay blocked until you approve. Correcting a
plan costs nothing; correcting a bad refactor costs an afternoon.

## 4. Deny what you never want run

```json
{
  "permissions": {
    "deny": ["Bash(rm *)", "Bash(git push *)", "Read(./.env)", "Read(./.env.*)"]
  }
}
```

What it does: refuses destructive commands and secret reads regardless of the mode, because deny
rules are enforced by Claude Code rather than requested of the model. They also match inside
subshells, so `echo "$(rm -rf tmp)"` is caught too.

## 5. Review in chunks, and run the tests

Ask for small focused commits rather than one giant change, read diffs before approving, and
run tests after each chunk. Give it the map too — a good
[CLAUDE.md](/guides/create-claude-md-project-memory/) with your commands, conventions and
"don't touch" folders keeps it out of the wrong files.

For genuinely parallel work, isolate it properly with
[git worktrees](/guides/claude-code-parallel-sessions-worktrees/) rather than two agents in one
checkout.

## If it goes wrong

```text
/rewind
```

What it does: opens the rewind menu to restore code and conversation to an earlier checkpoint.
Double-tapping `Esc` on an empty prompt opens the same thing. Press `Esc` once to stop Claude
mid-action the moment it heads somewhere you didn't intend.

The pattern: **check the mode → branch → plan → small reviewed steps → tests.** Sensible
[permissions](/glossary/#permissions) are what let you move fast without a bad day.

Source: [Choose a permission mode](https://code.claude.com/docs/en/permission-modes).
