Ask a room of engineers what chmod 754 means and you'll get a confident half of the room and a guessing other half. The octal scheme is elegant if you compute the bits and a footgun if you don't. CliAI just lets you describe the intent.
1. Executable for me only
$ clai make this script executable for me only→ chmod 700 ./deploy.sh
700 = rwx for owner, nothing for group, nothing for others. You'd remember if you used it weekly. Most don't.
2. Group write access
$ clai give the deploy group write access to /srv/app→ chgrp -R deploy /srv/app && chmod -R g+w /srv/app[Safety: CAUTION] — recursive permission change.
Notice the badge: any -R modification gets CAUTION because if the path is wrong, the blast radius is large. The safety classification post walks through why.
3. Recursive ownership change
$ clai chown all files in /srv/app to user app and group app→ chown -R app:app /srv/app[Safety: CAUTION]
The -R is implicit in all files in; CliAI extracts that and adds it. The user:group syntax is the version that works on both Linux and macOS.
4. Setuid bit on a single binary
$ clai add the setuid bit to /usr/local/bin/myutil→ chmod u+s /usr/local/bin/myutil
u+s is more readable than the octal equivalent 4755. This is also where octal math goes wrong most often — adding setuid to an existing 755 file means computing 4755, but if it was already 750, the right answer is 4750. Symbolic flags don't make you do the math.
5. "Same permissions as a neighbor file"
$ clai give ./new.sh the same permissions as ./run.sh→ chmod --reference=./run.sh ./new.sh
--reference= is a flag almost nobody knows about. It exists. CliAI knows.
See also
- Safety classification — why recursive permission changes are CAUTION by default.
- Batch rename files — same shape of problem (act on many files), different verb.