Agent policy
Permissions come in two separate layers, and mixing them up is the usual mistake.
Autonomy — what an agent may do to your machine
One picker on the agent, a ladder from cautious to trusting:
plan → manual → edits → auto → bypass. Bypass is the top rung of the same ladder, not a
separate switch. Which rungs exist depends on the harness (the permission_mode
capability); the app only shows the ones the seat actually supports.
When an agent stops to ask, the request reaches your phone: approve or deny straight from the notification or the lock screen.
Agent policy — what an agent may do to your other agents
| Switch | Off means | Default |
|---|---|---|
| talk | the agent may not open or reply to peer threads, and may not be a target of one. You can always message it. | on |
| manage | the agent may not start, stop, restart, re-model, compact or otherwise command another agent. Acting on itself is always allowed. | off |
Both are enforced at the hub, not in the app: a blocked call comes
back 403 with the reason, so an agent cannot route around the UI. manage is the one
thing standing between a prompt-injected agent and "stop the whole fleet", which is why it is off by
default.
Inheritance
When one agent starts another, the new agent copies the starter's autonomy and policy — one account-level switch, on by default. The copy happens at start and then the two are independent; there is no live link. Every start also records who started it, whether inheritance is on or off.
manage off it
cannot command your other agents even if it tries.