The GenAI Field Guide · Trending
Agent tools are replacing the click-yes-on-every-command prompt with written deny, ask and allow rules, often with a second model deciding the cases in between.
Across September 2026 the major agent products converged on the same control: a policy, set by a person or an administrator, that sorts every agent action into blocked, needs approval, or allowed, with a reviewer model approving routine boundary crossings so humans see only the risky ones. GitHub made enterprise-managed deny, ask and allow rules generally available for Copilot agents on 9 September; OpenAI's dots and Codex and Anthropic's Claude Code ship the same shape. Anyone who runs coding or background agents, or has to sign off on letting staff use them, should know which part of this is a hard rule and which part is a model's judgement.
This is a trend, not one launch. The old approval model asked the person at the keyboard to confirm each shell command, file edit or network call. In practice people either clicked yes without reading or switched on a bypass mode, which is the failure the new designs are built around. The replacement has two layers: deterministic rules that block or force a prompt for named actions, and a reviewer model that decides everything the rules leave open, so a human is interrupted only for what is genuinely risky.
GitHub is the clearest example of the rule layer. Its 9 September 2026 changelog made enterprise-managed permissions generally available on Copilot Business and Copilot Enterprise: administrators decide which agent operations are blocked, need human approval, or proceed without a prompt, across shell commands, file reads and edits, and network domains. GitHub says these managed restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals, and teams inside an enterprise can get their own policies. On 22 and 25 September GitHub added the reviewer layer and an isolation layer in public preview: assisted approvals in JetBrains, which approve low-risk tool calls and prompt for riskier ones, and local sandboxing in the Copilot app, which limits an agent's access to files, networks and credentials.
The same split appears elsewhere. OpenAI's Codex has an approval policy plus an auto-review mode that sends eligible approval requests to a separate reviewer agent, which administrators can enforce through managed configuration. OpenAI's dots, launched at DevDay on 29 September, start with built-in rules and let users add Custom Rules to allow, block or require approval for specific actions, with an auto-review step and some actions, such as password changes, that always need the user, as reported by The Next Web. Anthropic's Claude Code has allow, ask and deny permission rules evaluated before an auto mode classifier, and its docs say auto mode is now the built-in starting mode for interactive terminal and VS Code sessions from version 2.1.283.
The rule layer is pattern matching with a fixed precedence. In GitHub's managed settings, a permissions object holds deny, ask and allow lists of selectors: Shell(...) for commands with prefix matching, Read(...) and Edit(...) or Write(...) for file paths with globs, and Domain(...) for network origins. Deny beats ask, which beats allow. A deny from any managed source blocks the operation for everyone, an ask rule cannot be satisfied by bypass mode, an auto-approval setting, a hook or a saved grant, and once any source declares an allow list, anything unmatched needs approval. Claude Code's ask and deny rules work the same way and are checked before its classifier runs, so neither the classifier nor the user's chat can override a managed deny.
The reviewer layer is a second model with a narrower job. In Codex, auto-review runs only when an action would cross the sandbox boundary: an escalated shell command, a blocked network request, an edit outside the writable roots, or an MCP or app call marked for approval. The reviewer, itself a Codex agent, sees a compact transcript and the exact request but not the main agent's hidden reasoning. A denial comes back with a rationale and an instruction not to route around it; three consecutive denials, or ten within a rolling window of 50 reviews, abort the turn. Claude Code's classifier is two-stage, a fast yes or no filter tuned to block followed by chain-of-thought reasoning only on flagged actions, and it reads only user messages and tool calls, with tool outputs stripped so text the agent read cannot argue for approval. Three blocks in a row or 20 in a session pause auto mode and return to prompting.
Vendors publish different evidence for the reviewer. OpenAI's alignment team reported on 30 April 2026 that Codex sessions in auto-review stop for human approval roughly 200 times less often than in manual mode, with 99.1 percent of escalated actions approved, and recall of 90.3 percent on an overeagerness set and 99.3 percent on a prompt injection set. Anthropic's 25 March 2026 engineering post reports a 0.4 percent false positive rate on 10,000 real actions and a 17 percent false negative rate on 52 real overeager actions, which it calls the honest number. These are different datasets and different definitions, so the figures cannot be compared with each other, and both vendors say the reviewer is not a security guarantee.
Where the classifier takes prose policy, the policy is itself natural language. Claude Code's autoMode settings hold environment, allow, soft_deny and hard_deny lists written as sentences, such as which source-control orgs and buckets are trusted; Codex accepts a custom policy text that its docs say should start as a copy of the full default policy. Both read these only from user or managed scope, and Claude Code ignores autoMode in a repository's own settings files so a checked-in file cannot grant itself permissions.
You can adopt the pattern today in whichever agent your team already runs. GitHub's managed permissions need Copilot Business or Enterprise and an enterprise administrator; Codex and Claude Code accept managed configuration from an administrator and personal configuration from each developer. Start with the deterministic rules, then decide where a reviewer model is acceptable.