Menu
Best PracticesLesson 11 of 12

Models, Approvals and the Browser

6 min readCursor for Designers

Three settings shape how the agent works for you: which model does the thinking, what it may run without asking, and how it checks its work in the browser.

Picking a model

The model name sits under the prompt box. Click it to switch, or press Cmd+/ to cycle through models. Set your default in Cursor Settings → Models.

Free plan
Cursor picks from its own models, such as Composer 2.5 and Grok. Clicking the model name shows Upgrade to unlock more models.
Paid plans
The full list, including Claude, GPT and Gemini models. Auto picks a model for each request.
Teams
Auto can be set to favour cost, balance or intelligence.
On the free plan the model is fixed
Which one to use

Start with the default. Cursor recommends Composer 2.5 for Design Mode and quick visual edits. Switch to a stronger model only when a task keeps going wrong, such as a tricky layout or a bug the agent cannot pin down.

What the agent may do without asking

The agent edits files in your project freely. Running commands, opening pages and using connected tools such as Figma are different: by default it stops and asks.

The agent asking before it opens a page to check its work
Run
Allow this one action.
Always Run
Allow it now and from now on. Use it for actions you will see again and trust, like opening your local app.
Skip
Refuse. The agent carries on without it or tries another way.

Run Mode: setting the default

Open Cursor Settings (the gear at the bottom of the sidebar), choose Agents and scroll to Execution and Approvals. Run Mode decides how much runs without a prompt.

Run Mode in Cursor Settings
Allowlist
Only commands on your allowlist run on their own. Everything else asks you.
Allowlist (with Sandbox)
The same, but many other commands also run on their own inside a sandbox, a fenced-off space where they cannot touch the rest of your computer.
Auto-Review (with Sandbox)
Cursor checks each action itself and only asks you when something looks risky. Fewest interruptions with a safety net.
Run Everything (Unsandboxed)
Nothing asks. Avoid this one on your main computer.

For prototyping, either sandboxed option is a good balance. If prompts get in your way, add the commands you trust to the Command Allowlist on the same page, or click Always Run when the prompt appears.

The browser checks the agent's work

  • When you ask the agent to run your app, it opens it in a browser tab inside Cursor (lesson 7).
  • The agent can use that browser itself: open pages, click, type, take screenshots and read errors. That is how it checks its own work, as in the Figma build in lesson 8.
  • Type @Browser in a message to share what is on screen with the agent.

Privacy

In Cursor Settings → General, Privacy Mode stops your code from being used to train models. It is on by default for teams. Turn it on if you work on client or unreleased projects.

Pro Tip

Read approval prompts before clicking Run. They show exactly what the agent wants to do, such as the address it will open or the command it will run. That habit matters more than any setting.

You are in control

  • You can see and switch the model, and know what the free plan includes
  • You know what Run, Always Run and Skip do
  • You can choose a Run Mode that suits how you work
  • You know how the agent uses the browser to check its work

Last lesson: best practices and working with your team.