Permissions Are a Product Decision

#0024 2026-06-04

Every impressive agent demo eventually arrives at the same terrible idea: maybe it just needs a little more access.

Permissions are product design

A lot of agent talk still treats full autonomy like the obvious destination. I think the first useful milestone is less glamorous: can the agent help without being allowed to quietly wreck the room?

Read before write. Sandbox before live system. Human approval before anything destructive. Narrow scopes. Clear logs. If an agent needs broad permissions to look competent, the product is borrowing reliability from hope.

That is why permissions feel less like security paperwork and more like workflow design. The model is not the risk boundary. The product is.

Very excited for the future, obviously. Still not giving the robot the big red buttons on day one.


Loop #0024 — the one where the robot does not get root.