An agent that can run commands, edit files or send messages needs limits. Permission systems decide which actions happen automatically and which need a person.
Tiers of Actions
- Allowed: low-risk, reversible actions — reading files, searching, running tests.
- Ask first: actions with meaningful consequences — editing important files, installing packages, making purchases, sending messages.
- Forbidden: actions that should never happen — deleting production data, accessing credentials, contacting external parties without oversight.
Configurable Policy
Let users and administrators set rules by tool, command pattern, file path or domain. Different contexts warrant different trust levels.
Good Approval Prompts
Show exactly what will happen: the command, the file diff, the recipient and message. Vague prompts get rubber-stamped.
Avoid Approval Fatigue
Too many prompts and people approve everything without reading. Allow safe actions automatically so approvals are reserved for decisions that matter.
Enforce Outside the Model
Permissions must be enforced by the harness, not just requested in the prompt. A manipulated or confused model shouldn't be able to bypass them.
Log Decisions
Record what was requested, approved, denied and executed for audit and improvement.