Permission belongs to an operation, a revision, and a lifetime
A tool can be enabled without its domain action being authorized. A human can approve a local edit without approving publication. A new session can reuse an extension closure without inheriting the same kind of persisted permission as another example.
The Extension part makes these distinctions concrete. Continuity explains why they remain important when the active conversation moves, and Tan explains why Main’s protections cannot simply be presumed to follow another runtime. The Permissions part adds the operator’s resolution path: which declaration, effective policy key, mode, and UI capability govern this particular call?
The title’s operation/revision/lifetime discipline is a design principle, not a claim that the generic tool-approval dialog implements every domain revision check. Its binary answer admits one call; the domain must still validate its own object and authority.
Compare the examples without flattening their policies
| Example | State and authority lifetime | Consequence |
|---|---|---|
| Seed Desk reservations | Reservations and agentEnabled are persisted in branch snapshots. Revision combines session identity and the latest relevant state-entry ID. | Ancestor grants can be inherited. A headless reopen can retain an existing grant; both human grant and revoke commands require UI in this supplied stage. |
| Review Desk | Draft state is reconstructed from branch entries. The one-action grant is in memory, tied to session identity and numeric revision. | A successful mutation consumes the grant. Navigation, revocation, and shutdown invalidate authority and retire pending dialogs. |
| Field Notes | Selection is local to the factory binding and is not persisted in the journal. | /new and session switching can keep the selection; a fresh binding starts without it. |
| Memory and skills | Retained evidence and procedural guidance have their own storage and discovery scope. | Retrieved prose does not grant a tool permission or establish that a procedure was executed. |
Even the persisted-data validation policies differ. Seed Desk refuses malformed matching snapshots rather than skipping them. Review Desk’s small fixture skips entries that fail its state predicate. Preserve that distinction when studying recovery; the examples do not define one universal corruption policy.
Resolve host approval without inventing a domain grant
Approval Desk: modes and policies establishes a precise order. Tool deny and effective user deny are checked before automatic mode admission. Explicit tool allow or prompt can outrank a non-deny user policy. An override-only prompt is not an unbypassable policy in yolo. Consequently, neither “the user record always wins” nor “yolo disables every gate” is an accurate summary.
Dispatch Desk adds policy identity. A valid device policy replaces the invoking write fallback; it is not an intersection with every policy in the record. The outer transport borrows a tier, while an applicable inner wrapper can still deny. xdevApproved suppresses a particular unchanged-input duplicate prompt, not every nested check. A supported input replacement can require reclassification, and the source predicate is not a universal content-revision guard.
The generic one-call boundary offers Approve and Deny only. Dismissal is not approval, and an approval does not persist an allow-for-session setting. Two questions at outer and inner device gates can still precede only one execution. None of those answers creates Seed Desk’s branch grant or Review Desk’s revision-bound one-action authority.
Authority and concurrency are separate checks
Seed Desk re-reads its revision after awaiting human confirmation. Review Desk uses generation invalidation to prevent an old dialog answer from reviving authority. Both respond to the same asynchronous hazard: the context that made a decision meaningful may have changed while the UI was waiting.
A current revision does not supply permission, and permission does not make an old revision current. On a stale refusal, inspect again and reconsider the action; do not merely substitute a newer token into an unchanged request.
These revisions are domain-specific. Seed Desk’s token, Review Desk’s counter, a workbook page revision, and a provider-facing session ID are not interchangeable concurrency controls. The generic wrapper’s supported pre-approval input replacement and Review Desk’s pending-dialog generation invalidation also remain different mechanisms.
UI, launch, and child construction are distinct boundaries
When the host can ask separates terminal presence from an installed UI adapter. RPC can provide select requests through its transport. ACP form support is capability-dependent, and a non-no-op adapter can still return an unavailable value for a particular operation. Print/no-UI execution fails closed when this generic gate requires a prompt. None of those statements proves physical keyboard behavior or every native component.
Configuration and launch precedence explains why a displayed always-ask setting can coexist with wrapper yolo: the execute-time autoApprove boolean can outrank the configured mode. This does not remove an effective explicit deny or acknowledge pending provider safety checks.
Subagents and inherited policies traces both Task construction and TanCommandController.start() to createSubagentSettings(). The helper defaults child mode to yolo while retaining per-tool policy values, and explicit helper overrides are applied afterward. Initial construction, later live runtime inputs, and conversation ancestry are not one inheritance contract. No universal live synchronization or safeguard clone is established.
Reload is not a universal revocation boundary
The source’s AgentSession.reload() reopens the current session through switchSession(). It does not establish that every extension factory is imported and rebound. Review Desk uses the switch path to invalidate its authority. Field Notes deliberately retains its factory-local selection.
Therefore neither “reload clears everything” nor “reload preserves everything” is a sound rule. State the intended lifetime, implement its transitions, and test those transitions through the actual host. Restarting the explicit launch is the source workbook’s reliable procedure for testing extension code edits, not a claim that every hot-reload route is equivalent.
Give the agent an interface, not implied authority
A model-required capability needs a supported tool, not a suggestion to invoke a human slash command. Humans and tools should share mandatory domain rules when both can reach the same action. A human command path is not cryptographic proof of a human keystroke: SDK and RPC hosts can deliberately dispatch command text.
Host approval controls execution under the host’s policy. Domain grants control the example’s operation. Pending provider safety acknowledgement is another gate. Operating-system and broker policy control a different boundary. The supplied isProjectTrusted() compatibility method and trusted-file selection do not sandbox arbitrary extension JavaScript or its imports.
This matters especially for unattended tangents and permission-denied file fallbacks. Verify the actual subagent settings and installed safeguards rather than assuming Main’s experience follows it. A fallback adapter must refuse the wrong session or destination and rely on a real broker; returning success before the exact write has completed is not permission-aware behavior. That is a host-design contract, not a request to use a privileged broker for this workbook. Approval is not a sandbox preserves the distinction between application admission, a denied primitive, and a verified effect.
Source trail: Seed Desk reservations, Review Desk, Discovery, installation and reload, and File fallbacks. Supplied examples include examples/seed-desk/03-reservations/desk.ts — reconstruct, changeReservation; examples/review-desk/index.ts — stateFor, invalidateAuthority; and examples/package-lab/multi/index.ts — the factory-local selected variable. New permissions anchors include packages/coding-agent/src/tools/approval.ts — resolveApproval; extensibility/extensions/wrapper.ts — ExtensionToolWrapper.execute; modes/rpc/rpc-mode.ts — runRpcMode; and task/executor.ts — createSubagentSettings, with the latter abbreviated paths relative to packages/coding-agent/src/. Their recorded checks remain scoped in Permissions evidence.
Related chapters:
- Prepare a reversible lab
- Seed Desk: reservations on the active branch
- Review Desk: edit and decide locally
- Package Lab: one file to an embedded host
- Discovery, installation and reload
- Tools, interception and native delegation
- Permission-denied file fallbacks
- Decision Desk refusals and failures
- 2. Start from Main
- Four places knowledge can live
- Approval Desk: modes and policies
- Dispatch Desk: device and path gates
- Boundary Desk: one call at a time
- Boundary Desk: when the host can ask
- Configuration and launch precedence
- Subagents and inherited policies
- Approval is not a sandbox
- Recovery without widening permission
Connections and next steps · Unified editorial chapter; connects the recorded source material without rerunning it.