Back to the episode map

Research Note

Project Permissions and Agent Authority Record

Antigravity projects can span multiple folders and carry project-level settings and permissions. Documentation distinguishes local work from isolated worktree mode.

Aug 4, 20261 min readBy Dalton Anderson

Project Permissions and Agent Authority Record

Antigravity projects can span multiple folders and carry project-level settings and permissions. Documentation distinguishes local work from isolated worktree mode.

The permissions engine uses Deny, Ask, and Allow lists. Google documents Deny as the highest-precedence rule, followed by Ask and Allow. Unconfigured web browsing, terminal commands, MCP actions, external file access, and other sensitive operations may prompt under documented defaults.

Workspace files are treated differently from non-workspace assets. MCP servers and hooks extend the execution surface. A permission granted to a tool does not prove that the connected system, data, script, or output is safe.

As of July 28, the documentation calls terminal sandboxing a preview on macOS and Linux and says Windows support is coming later. Do not describe all platforms as equally sandboxed.

The durable authority map should name assets, actions, external systems, denials, approval points, isolation, duration, evidence, revocation, and the person authorized to release a consequential result.

Sources

Follow the evidence.

  1. Antigravity changelogantigravity.google
  2. Antigravity 2.0 product pageantigravity.google
  3. Spotify episode recordpodcasters.spotify.com
  4. Antigravity MCP documentationantigravity.google
  5. Antigravity subagents documentationantigravity.google
  6. csrc.nist.gov: finalcsrc.nist.gov
  7. Antigravity permissions documentationantigravity.google
  8. Antigravity 2.0 overviewantigravity.google
  9. Antigravity 2.0 feature deep diveantigravity.google
  10. Antigravity hooks documentationantigravity.google
  11. Google people-first content guidancedevelopers.google.com
  12. Antigravity projects documentationantigravity.google
  13. Google Developers Blog: transitioning Gemini CLI to Antigravity CLIdevelopers.googleblog.com
Project Permissions and Agent Authority Record