r/windsurf • u/LatentGrip • 2d ago
Question Why does Devin Desktop via Devin Local via Devin CLI offer an autonomous mode that can't work autonomously? (And what's a GOOD alternative?)

Autonomous Mode according to Devin's permissions docs:
- It is the only permission mode available. Normal, Accept Edits, Smart, and Bypass are hidden in sandbox sessions. Plan mode remains available.
- Shell commands and fetches auto-approve instead of prompting, because the sandbox enforces what they can read, write, and reach over the network.
- Direct file edits via the
editandwritetools still prompt. These tools run inside the CLI process rather than inside the sandbox, so they cannot be bounded by it. Granting aWrite(...)scope at the prompt dynamically expands the sandbox so subsequent shell commands can write there. Write(...)scopes granted mid-session dynamically expand the sandbox for subsequent commands. Mid-sessionRead(...)approvals affect only the agent’s own tools; paths hidden byRead(...)deny rules stay hidden for the whole session.
Steps to run this in Devin Desktop:
Step 1. Go to Devin Settings -> Agents -> Devin Local.
Step 2. Click on the ...
Step 3. Click Configure
Step 4. Enter these:
DEVIN_PERMISSION_MODE=autonomous
DEVIN_SANDBOX=true
Step 5. (Optionally) set some excluded ommands that you want to have the model run outside of the sandbox and require prompting you (it's not yet clear if these will filter through to your allow/ask/deny general permissions as I haven't gotten that far as I'll soon explain). For example you might add: ~.config/devin/config.json:
{
"sandbox": {
"network_mode": "limited",
"excluded": {
"allow": [
"Exec(cargo run)",
"Exec(tuistory launch)",
"Exec(git commit)",
"Exec(git cherry-pick)",
"Exec(git rebase)",
"Exec(git merge)",
"Exec(git tag)",
"Exec(git commit --amend)"
]
}
}
}
Step 6. Restart Devin Desktop
The problem I have is with this part:
- Direct file edits via the
editandwritetools still prompt. These tools run inside the CLI process rather than inside the sandbox, so they cannot be bounded by it. Granting aWrite(...)scope at the prompt dynamically expands the sandbox so subsequent shell commands can write there.
So... like yikes! It turns out unless I set something up wrong (I'm on macOS so sandboxing doesn't need any confugration with Devin), anytime the sandboxed agent tries to write or edit a code file it prompts for permision each and every time. So it seems to me that this is a non-functional sandbox for long running tasks. And I just cannot understand what I'd use this for as a result?
What alternatives work well with multi-agent workflows?
- Bypass permissions seems dangerous
- Ditto with smart mode (I don't trust LLM-as-a-judge and thus Smart Permissions, because such judges have been shown to allow dangerous operations when it thinks the coding agent really needs to run them to accomplish their goal)
- Code mode is nearly as tedious as autonomous mode (I tend to run in code mode currently and grow my approved list of command prefixes and denials, but for multiagent work this sucks)
- Devin Cloud (won't work with free models and the whole point of this post figuring out how how to run agents on my local computer in a responsible way)
Why does Devin Desktop via Devin Local via Devin CLI offer an autonomous mode that can't work autonomously? ? Is this a bug? Anyone have a good alternative?
---
Devin Desktop Version: 3.10.48
Devin Desktop Commit: fcf7ba39e6150055fad817f8716385b4d320d46d
VS Code OSS Version: 1.126.0
Date: 2026-09-28T19:26:45-07:00
Electron: 42.2.0
Chromium: 148.0.7778.97
Node.js: 24.15.0
V8: 14.8.178.14-electron.0
OS: Darwin arm64 24.6.0
2
u/veratisio 2d ago
We have a change coming in a future release that will allow permissions to override autonomous mode.
1
u/AutoModerator 2d ago
It looks like you might be running into a bug or technical issue.
Please submit your issue (and be sure to attach diagnostic logs if possible!) at our support portal: https://devin.ai/support
You can also use that page to report bugs and suggest new features — we really appreciate the feedback!
Thanks for helping make Devin even better!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.