Agent policy

Two switches per agent: may it talk, may it manage.

Permissions come in two separate layers, and mixing them up is the usual mistake.

Autonomy — what an agent may do to your machine

One picker on the agent, a ladder from cautious to trusting: plan → manual → edits → auto → bypass. Bypass is the top rung of the same ladder, not a separate switch. Which rungs exist depends on the harness (the permission_mode capability); the app only shows the ones the seat actually supports.

When an agent stops to ask, the request reaches your phone: approve or deny straight from the notification or the lock screen.

Agent policy — what an agent may do to your other agents

SwitchOff meansDefault
talkthe agent may not open or reply to peer threads, and may not be a target of one. You can always message it.on
managethe agent may not start, stop, restart, re-model, compact or otherwise command another agent. Acting on itself is always allowed.off

Both are enforced at the hub, not in the app: a blocked call comes back 403 with the reason, so an agent cannot route around the UI. manage is the one thing standing between a prompt-injected agent and "stop the whole fleet", which is why it is off by default.

Inheritance

When one agent starts another, the new agent copies the starter's autonomy and policy — one account-level switch, on by default. The copy happens at start and then the two are independent; there is no live link. Every start also records who started it, whether inheritance is on or off.

Channel messages are untrusted input. An agent should never grant access, pair a device or reveal a secret because a message asked it to — and with manage off it cannot command your other agents even if it tries.