Claude Code 'ask again next time' for reads outside the project

Auto mode now offers a one-time yes for a read outside your working directories. Where Sume results land, and how to keep media inside the project.

4 min readSume
All posts

Claude Code 2.1.284 added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories. It lets you allow that one read and still be asked about later ones. If an agent keeps tripping that prompt while handling Sume output, save the result inside the project instead of approving reads elsewhere.

The answer is from the Claude Code changelog entry dated September 28, 2026, read 2026-10-01. The Sume side is from the docs.

What does the new answer do?

Before this change the choices on that prompt were to allow or deny. The changelog adds a third: allow this one read, and do not remember it. It applies to auto mode's prompt for a read outside the working directories, not to every permission dialog.

Why would a Sume workflow read outside the project?

Sume results are hosted files. The asset library docs say Sume mirrors generated outputs into Sume-owned media URLs before exposing them in public results, and assets_download_url is a read tool in tools and gates. An agent that downloads a result to a temp folder and then opens it triggers an outside-the-project read.

Where a read lands in a Sume workflow, from the docs and changelog, read 2026-10-01.
StepLocationPrompt in auto mode?
Generate, then jobs_resultSume, as a hosted fileNo local read
Download into the repo's media folderInside the working directoryNot outside-the-project
Download to a temp folder, then open itOutside the working directoryYes, the new three-way prompt

How do I keep the files inside the project?

Tell the agent where to put output: a folder under the repo, such as an assets/ directory, before it downloads anything. Ask it to refer to results by their Sume public ids and media.sume.com URLs in notes and reports; the docs advise against pasting signed URLs, OAuth tokens or API keys into chat logs.

Should I choose the one-time answer or allow it for good?

Choose the one-time answer when the path is unusual, such as a file somebody else dropped in a shared folder. For a stable output folder, move the folder into the project rather than widening what auto mode may read. Reading a result back through jobs_result needs no local file at all.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume