Skip to content

Permissions and Approval in Agent Harnesses

Controlling what agents can do on their own: allow lists, approval prompts, forbidden actions and escalation.

Editorial team 1 min read

An agent that can run commands, edit files or send messages needs limits. Permission systems decide which actions happen automatically and which need a person.

Tiers of Actions

  • Allowed: low-risk, reversible actions — reading files, searching, running tests.
  • Ask first: actions with meaningful consequences — editing important files, installing packages, making purchases, sending messages.
  • Forbidden: actions that should never happen — deleting production data, accessing credentials, contacting external parties without oversight.

Configurable Policy

Let users and administrators set rules by tool, command pattern, file path or domain. Different contexts warrant different trust levels.

Good Approval Prompts

Show exactly what will happen: the command, the file diff, the recipient and message. Vague prompts get rubber-stamped.

Avoid Approval Fatigue

Too many prompts and people approve everything without reading. Allow safe actions automatically so approvals are reserved for decisions that matter.

Enforce Outside the Model

Permissions must be enforced by the harness, not just requested in the prompt. A manipulated or confused model shouldn't be able to bypass them.

Log Decisions

Record what was requested, approved, denied and executed for audit and improvement.

More in Agent harnesses

All Agent harnesses guides →
Agent harnesses Guide · 2 min

What Is an Agent Harness?

The software around a language model that turns it into an agent: the loop, tools, context, permissions and memory.

Agent harnesses 2 min read 27 Sep 2025

Agent harnesses Guide · 1 min

The Agent Loop Explained

The core cycle every agent runs: think, call a tool, observe the result, repeat — and how the loop knows when to stop.

Agent harnesses 1 min read 26 Sep 2025

Agent harnesses Guide · 1 min

Designing Tools for AI Agents

How to write tools agents use well: clear names, precise descriptions, sensible inputs and informative outputs.

Agent harnesses 1 min read 25 Sep 2025

Agent harnesses Guide · 1 min

Context Management in Agent Harnesses

How agents stay effective over long tasks: what to keep in context, what to summarise, and what to store outside.

Agent harnesses 1 min read 24 Sep 2025