Claude's Plan Mode Is Not a Permission
Claude’s documentation tells us that plan mode only plans and never edits.
It is described in the "Choose a permission mode".
and the CLI flag is --permission-mode plan.
So, that sounds like permissions and it sure does not edit files, right?
No! Plan mode can still edit! The plan most isn’t really a permission, but more a guideline. Then why and how can the plan mode still edit? The underlying issue is the AI models love for Bash. They use Bash to search, read library APIs, and so on and on. Therefore in plan mode, Bash is still available. And the models also use Bash also to edit files, so the models can accidentally edit files in plan mode.
An easy example (I tried it with Sonnet 5 and Opus 5):
# Time
$ claude --permission-mode plan
# Inside Claude
> Please write 'Hi Gamlor' to fun.txt
# Claude now shows a plan and asks a question.
Here is Claude's plan:
# Plan
Claude has written up a plan and is ready to execute. Would you like to proceed?
1. Yes, and use auto mode
2. Yes, manually approve edits
3. Tell Claude what to change
# Well, I don't like this plan, so I'll pick option 3 ;)
> Please use bash instead
# Now Claude got confused, skipped the plan,
and just wrote the file with Bash.
...
Written — /home/roman/dev-temp/fun.txt contains Hi Gamlor.However, Claude only does this in the default Auto mode, that most of us are using. In the 'ask me' mode you’ll probably overlook the edit and approve it as well ;)
And yes, this is all expected behavior =). You might just be surprised if you don’t read the documentation.



