Anthropic disclosed a number this week: 93% of permission prompts on Claude Code get a straight "approve" from users. In other words, most prompts aren't gating anything — they're just draining your attention.
What this is
Agents aren't traditional programs — give them a sentence in natural language and they decide which tools to call, what parameters to pass, and what to chain next, with the whole path dynamic and probabilistic. Slapping IAM (identity and access management — controlling who can enter which systems) onto an agent doesn't fit, because humans bring judgment and a sense of cost to their actions. Agents currently lack that self-restraint and just push to complete the task, even when they've misunderstood it.
Industry consensus: permissions aren't an on/off switch but a risk-tiered ladder. Claude Code's design shows the approach — file reads pass through silently, file edits stay quiet only within the session, shell commands (direct OS-level execution) get permanent authorization scoped to repo and command, and outbound fetches are gated by domain.
Industry view
Tiering alone isn't enough — you need another AI to screen first. Claude Code's auto mode runs two gates: the input layer scans returned content for hidden prompt injections (malicious instructions tucked into tool outputs to derail the original task), and the output layer runs a fast classifier first, escalating suspicious cases to a slower reasoning review. The approval classifier is deliberately kept blind to the agent's internal reasoning, so a compromised agent can't talk its way past the reviewer.
But the counterpoint deserves airtime: Anthropic's own data shows auto mode carries a 17% false-negative rate (the share of dangerous actions that slip through) — roughly 1 in every 6 approvals could go wrong. The industry compromise: auto mode suits CI pipelines (automated tests run before code merges) and overnight batch refactors — medium-to-low-risk, long-running tasks. High-impact actions like production databases, funds, and outbound messages must stay under human sign-off.
Supporting mechanisms also include: giving agents their own identity, minute-long short-lived credentials replacing permanent API keys, permissions scoped to "which action on which resource," routing high-risk approvals to SMS or a separate panel (channels the agent can't spoof), confining execution to sandboxes (isolated virtual spaces), and setting rate limits plus circuit breakers (forced shutdowns on anomalies).
Impact on regular people
For enterprise IT: IAM systems need dedicated modules for agents — separate accounts, short-lived credentials, and audit trails. Okta and WorkOS are already filling in product lines.
For working developers: people using Claude Code and Cursor will feel the difference — low-risk operations stop interrupting, but destructive ones still demand a click.
For consumer markets: end users won't feel much yet, but once AI assistants start ordering food or transferring money on your behalf, settings for "which actions AI can take autonomously" will become standard.