The GenAI Field Guide · Trending

Policy-based agent approvals

Agent tools are replacing the click-yes-on-every-command prompt with written deny, ask and allow rules, often with a second model deciding the cases in between.

Across September 2026 the major agent products converged on the same control: a policy, set by a person or an administrator, that sorts every agent action into blocked, needs approval, or allowed, with a reviewer model approving routine boundary crossings so humans see only the risky ones. GitHub made enterprise-managed deny, ask and allow rules generally available for Copilot agents on 9 September; OpenAI's dots and Codex and Anthropic's Claude Code ship the same shape. Anyone who runs coding or background agents, or has to sign off on letting staff use them, should know which part of this is a hard rule and which part is a model's judgement.

What it is

This is a trend, not one launch. The old approval model asked the person at the keyboard to confirm each shell command, file edit or network call. In practice people either clicked yes without reading or switched on a bypass mode, which is the failure the new designs are built around. The replacement has two layers: deterministic rules that block or force a prompt for named actions, and a reviewer model that decides everything the rules leave open, so a human is interrupted only for what is genuinely risky.

GitHub is the clearest example of the rule layer. Its 9 September 2026 changelog made enterprise-managed permissions generally available on Copilot Business and Copilot Enterprise: administrators decide which agent operations are blocked, need human approval, or proceed without a prompt, across shell commands, file reads and edits, and network domains. GitHub says these managed restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals, and teams inside an enterprise can get their own policies. On 22 and 25 September GitHub added the reviewer layer and an isolation layer in public preview: assisted approvals in JetBrains, which approve low-risk tool calls and prompt for riskier ones, and local sandboxing in the Copilot app, which limits an agent's access to files, networks and credentials.

The same split appears elsewhere. OpenAI's Codex has an approval policy plus an auto-review mode that sends eligible approval requests to a separate reviewer agent, which administrators can enforce through managed configuration. OpenAI's dots, launched at DevDay on 29 September, start with built-in rules and let users add Custom Rules to allow, block or require approval for specific actions, with an auto-review step and some actions, such as password changes, that always need the user, as reported by The Next Web. Anthropic's Claude Code has allow, ask and deny permission rules evaluated before an auto mode classifier, and its docs say auto mode is now the built-in starting mode for interactive terminal and VS Code sessions from version 2.1.283.

How it works

The rule layer is pattern matching with a fixed precedence. In GitHub's managed settings, a permissions object holds deny, ask and allow lists of selectors: Shell(...) for commands with prefix matching, Read(...) and Edit(...) or Write(...) for file paths with globs, and Domain(...) for network origins. Deny beats ask, which beats allow. A deny from any managed source blocks the operation for everyone, an ask rule cannot be satisfied by bypass mode, an auto-approval setting, a hook or a saved grant, and once any source declares an allow list, anything unmatched needs approval. Claude Code's ask and deny rules work the same way and are checked before its classifier runs, so neither the classifier nor the user's chat can override a managed deny.

The reviewer layer is a second model with a narrower job. In Codex, auto-review runs only when an action would cross the sandbox boundary: an escalated shell command, a blocked network request, an edit outside the writable roots, or an MCP or app call marked for approval. The reviewer, itself a Codex agent, sees a compact transcript and the exact request but not the main agent's hidden reasoning. A denial comes back with a rationale and an instruction not to route around it; three consecutive denials, or ten within a rolling window of 50 reviews, abort the turn. Claude Code's classifier is two-stage, a fast yes or no filter tuned to block followed by chain-of-thought reasoning only on flagged actions, and it reads only user messages and tool calls, with tool outputs stripped so text the agent read cannot argue for approval. Three blocks in a row or 20 in a session pause auto mode and return to prompting.

Vendors publish different evidence for the reviewer. OpenAI's alignment team reported on 30 April 2026 that Codex sessions in auto-review stop for human approval roughly 200 times less often than in manual mode, with 99.1 percent of escalated actions approved, and recall of 90.3 percent on an overeagerness set and 99.3 percent on a prompt injection set. Anthropic's 25 March 2026 engineering post reports a 0.4 percent false positive rate on 10,000 real actions and a 17 percent false negative rate on 52 real overeager actions, which it calls the honest number. These are different datasets and different definitions, so the figures cannot be compared with each other, and both vendors say the reviewer is not a security guarantee.

Where the classifier takes prose policy, the policy is itself natural language. Claude Code's autoMode settings hold environment, allow, soft_deny and hard_deny lists written as sentences, such as which source-control orgs and buckets are trusted; Codex accepts a custom policy text that its docs say should start as a copy of the full default policy. Both read these only from user or managed scope, and Claude Code ignores autoMode in a repository's own settings files so a checked-in file cannot grant itself permissions.

How to use it

You can adopt the pattern today in whichever agent your team already runs. GitHub's managed permissions need Copilot Business or Enterprise and an enterprise administrator; Codex and Claude Code accept managed configuration from an administrator and personal configuration from each developer. Start with the deterministic rules, then decide where a reviewer model is acceptable.

  1. List the actions that must never happen without a person, such as pushing to protected branches, deploying, deleting cloud data, reading credential files and calling unknown domains, and the ones that must never happen at all.
  2. Write the never list as deny rules and the needs-a-person list as ask rules in managed settings, so users and repositories cannot weaken them. The GitHub example below is the shape; Claude Code and Codex have equivalents.
  3. Turn off bypass or full-access modes centrally where the product allows it: disableBypassPermissionsMode in GitHub's managed settings, disableAutoMode or bypass controls in Claude Code, allowed_approval_policies and allowed_sandbox_modes in Codex requirements.
  4. Add allow rules only for narrow, routine commands such as running the test suite or reaching your package registry, and prefer tightening the sandbox's writable paths and network list over teaching a reviewer to approve noise.
  5. If you enable a reviewer model, tell it what your environment trusts: Claude Code's autoMode.environment entries or a Codex custom policy built from the default one.
  6. Review the denial logs weekly (Claude Code's Recently denied tab, Codex session transcripts, Copilot OpenTelemetry where enabled) and turn repeated legitimate denials into rules rather than one-off approvals.

Use cases

Sources

  1. Enterprise managed permissions for GitHub Copilot agent operations, GitHub Changelog, 2026-09-09
  2. Enterprise managed settings, GitHub Docs, 2026-09
  3. New features and improvements in Copilot for JetBrains, GitHub Changelog, 2026-09-22
  4. GitHub Copilot weekly releases, September 21, GitHub Changelog, 2026-09-25
  5. Auto-review, OpenAI docs, 2026-10
  6. Agent approvals and security, OpenAI docs, 2026-10
  7. Auto-review of agent actions without synchronous human oversight, OpenAI Alignment, 2026-04-30
  8. Choose a permission mode, Claude Code Docs, 2026-10
  9. Configure auto mode, Claude Code Docs, 2026-10
  10. Claude Code auto mode, Anthropic Engineering, 2026-03-25
  11. OpenAI launches dots, always-on AI agents with their own cloud computers, The Next Web, 2026-09-29