## Subagents and inherited policies

The preceding Tan part established that a conversation fork is not a cloned runtime\.&#32;Permission construction supplies a concrete reason\.

Nia expects an unattended child to reproduce Main’s interactive approval mode\.&#32;The initial helper does something more specific\:&#32;it snapshots settings\,&#32;applies child defaults\,&#32;and permits explicit helper overrides afterward\.

### Read the helper in its actual callers

`createSubagentSettings()`&#32;in&#32;`packages/coding-agent/src/task/executor.ts`&#32;reads every key in&#32;`SETTINGS_SCHEMA`&#32;from the base settings\.&#32;It creates an in\-memory settings instance with that snapshot\,&#32;then applies these defaults before spreading any explicit overrides\:

- `tools.approvalMode: "yolo"`\;
- `advisor.enabled: false`\.

It also passes the base storage handle to the isolated settings instance\.&#32;“In\-memory settings overrides” therefore does not mean every shared runtime resource or storage service has been duplicated or removed\.

`runSubprocess()`&#32;uses this helper for Task construction\.&#32;**`TanCommandController.start()`&#32;uses the same helper\.**&#32;Its call is&#32;`createSubagentSettings(this.ctx.settings)`\,&#32;with no explicit approval\-mode override at that call site\.

The initial Tan SDK construction sets&#32;`hasUI: false`&#32;and disables extension discovery\.&#32;It passes enabled\-tool names and other captured context through specific options\;&#32;it does not pass Main’s live extension instances as a cloned safeguard set\.&#32;Supplied MCP proxies and custom\-tool discovery are separate mechanisms\.

### Predict a child from a small configuration

Use this fictional base configuration on paper\:

~~~json
{
  "tools.approvalMode": "always-ask",
  "tools.approval": { "bash": "deny" }
}
~~~

**Prediction\:**&#32;after the helper’s ordinary defaults\,&#32;must the child prompt for every exec\-tier call\?&#32;Does bash become allowed\?

**Source\-backed worked answer\:**&#32;the child settings mode defaults to yolo\,&#32;so tier\-only exec prompting is not inherited unchanged\.&#32;The per\-tool policy record remains relevant\:&#32;an effective bash deny still resolves to denial\.&#32;A user prompt policy can likewise leave a child needing a UI it does not have\,&#32;subject to the resolver’s tool\-policy precedence\.

This example is a source\-derived calculation\,&#32;not an executed child scenario\.&#32;None of the 46 private cases launches Task or Tan\.

### Separate three meanings of inheritance

| Layer | What is established | What not to infer |
| --- | ---: | --- |
| Initial helper defaults | Snapshot values are used\,&#32;then yolo and advisor\-off defaults are applied\. | The parent’s interactive mode was copied unchanged\. |
| Explicit helper overrides | The final&#32;`overrides`&#32;spread can replace the helper’s default mode\. | Ordinary Tan launch supplies such an override\,&#32;or a new Tan flag exists\. |
| Live runtime inputs | The wrapper samples its execute\-time settings and autoApprove\;&#32;specific shared callbacks\/resources can remain live\. | Every later parent setting or safeguard automatically mirrors into every child\. |

The helper’s optional inherited service\-tier argument is another example of an explicit input\.&#32;It concerns provider service tiers\,&#32;not the read\/write\/exec approval tiers\.&#32;Likewise\,&#32;the SDK can carry a live extension\-root provider for certain child construction paths\.&#32;Neither establishes a universal live approval\-policy inheritance mechanism\.

If another host later applies runtime inheritance\,&#32;that is a separate transition to inspect\.&#32;An initial helper result is not proof that a child remains permanently at that value\,&#32;and a conversation relationship is not proof of a later synchronization\.&#32;The complete&#32;`packages/coding-agent/src/session/agent-session.ts`&#32;implementation and host\-specific live inheritance adapters are outside this selected permissions pack\;&#32;no blanket statement about those transitions is warranted\.

### Parent approval is not an OS delegation

The helper’s source explains the unattended design in terms of the parent Task approval boundary\.&#32;That does not make the child a sandbox or erase its per\-tool policies\.&#32;It also does not make a human&#32;`/tan`&#32;command identical to a model\-issued Task call\:&#32;they are different entry surfaces\.

A “do not edit” assignment remains behavioral guidance\.&#32;The child’s actual tool surface\,&#32;policy record\,&#32;domain rules\,&#32;and host authority determine what it can do\.&#32;Focusing a headlessly created Tan later is not evidence that it was reconstructed with every interactive facility\.

For the original launch and lifecycle qualifications\,&#32;retain&#32;[Start from Main](<https://present-sketch-tp94.here.now/chapters/tan-2-start-from-main>)&#32;and&#32;[Interrupt\,&#32;cancel\,&#32;or kill](<https://present-sketch-tp94.here.now/chapters/tan-8-interrupt-cancel-or-kill>)\.&#32;Their historical observations are not rerun by this chapter\.

**Paper checkpoint\:**&#32;locate the Tan helper call\,&#32;then the helper’s merge order\.&#32;Explain how an explicit helper override could differ from the ordinary Tan call without inventing a CLI or slash\-command option\.&#32;**Worked answer\:**&#32;the helper API accepts overrides after its defaults\;&#32;the supplied Tan call does not provide them\.

**Failure boundary\:**&#32;neither a conversation fork\,&#32;a settings snapshot\,&#32;nor shared storage proves identical live permissions\,&#32;loaded safeguards\,&#32;remote authority\,&#32;or cross\-process enforcement\.

**Source anchors\:**&#32;`packages/coding-agent/src/task/executor.ts`&#32;—&#32;`createSubagentSettings`\,&#32;`runSubprocess`\,&#32;`createMCPProxyTools`\;&#32;`packages/coding-agent/src/modes/controllers/tan-command-controller.ts`&#32;—&#32;`TanCommandController.start`\;&#32;`packages/coding-agent/src/sdk.ts`&#32;—&#32;`CreateAgentSessionOptions`\,&#32;`createAgentSessionScoped`\;&#32;`packages/coding-agent/src/extensibility/extensions/wrapper.ts`&#32;— execute\-time approval inputs\.
