PrivacyFence tells claude.ai truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. claude.ai decides from that whether to ask you before it calls a tool, so it may ask before a write, in front of PrivacyFence's own card. On the Team plan, a tool marked as a write prompts on every call.
Where claude.ai offers to always allow a tool, allowing it only stops claude.ai asking: a gated call still waits for PrivacyFence's approval card at /approvals, whatever claude.ai was told or allowed. There is no mode that advertises writes as read-only.
What we observed: claude.ai asked before creating a calendar event; choosing to always allow the tool stopped it asking, and PrivacyFence's approval card was still shown.