Claude Code 'ask again next time' for reads outside the project
Auto mode now offers a one-time yes for a read outside your working directories. Where Sume results land, and how to keep media inside the project.

Claude Code 2.1.284 added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories. It lets you allow that one read and still be asked about later ones. If an agent keeps tripping that prompt while handling Sume output, save the result inside the project instead of approving reads elsewhere.
The answer is from the Claude Code changelog entry dated September 28, 2026, read 2026-10-01. The Sume side is from the docs.
What does the new answer do?
Before this change the choices on that prompt were to allow or deny. The changelog adds a third: allow this one read, and do not remember it. It applies to auto mode's prompt for a read outside the working directories, not to every permission dialog.
Why would a Sume workflow read outside the project?
Sume results are hosted files. The asset library docs say Sume mirrors generated outputs into Sume-owned media URLs before exposing them in public results, and assets_download_url is a read tool in tools and gates. An agent that downloads a result to a temp folder and then opens it triggers an outside-the-project read.
| Step | Location | Prompt in auto mode? |
|---|---|---|
Generate, then jobs_result | Sume, as a hosted file | No local read |
| Download into the repo's media folder | Inside the working directory | Not outside-the-project |
| Download to a temp folder, then open it | Outside the working directory | Yes, the new three-way prompt |
How do I keep the files inside the project?
Tell the agent where to put output: a folder under the repo, such as an assets/ directory, before it downloads anything. Ask it to refer to results by their Sume public ids and media.sume.com URLs in notes and reports; the docs advise against pasting signed URLs, OAuth tokens or API keys into chat logs.
Should I choose the one-time answer or allow it for good?
Choose the one-time answer when the path is unusual, such as a file somebody else dropped in a shared folder. For a stable output folder, move the folder into the project rather than widening what auto mode may read. Reading a result back through jobs_result needs no local file at all.
Sources
Related posts
More in Integrations
- Claude Code fork subagents keep plan mode: paid Sume tools
Since 2.1.285 a fork subagent runs under its parent's permission mode and cannot exit plan mode. Two more gates still guard paid Sume MCP tools.
- Claude Code headless MCP: a failed first connect is now retried
Since 2.1.283, headless Claude Code retries a remote MCP server whose first connect fails transiently. What to check in a CI run that calls Sume.
- MCP tool call ran twice in Claude Code: can Sume bill it twice?
Claude Code 2.1.287 fixed an MCP connector call that could run twice when the server changed protocol version. How Sume's idempotency_key and jobs_list help.
- Claude Code /mcp shows no Authenticate for a server: check the URL
Since 2.1.283, /mcp no longer offers Authenticate for a server with no valid URL. Re-add Sume as an http server at https://mcp.sume.com/mcp and sign in.
Written by Sume