pub enum ApprovalLevel {
FullAuto,
Moderate,
ReadOnly,
Unmanaged,
}Expand description
How much autonomy a freshly spawned provider CLI process is granted at launch, independent of which transport (PTY, inline/pipe, ACP) execs it – these are process launch arguments, the same axis regardless of transport.
The mapping from a level to actual CLI flags is per-provider, verified
against vendor documentation (and, for grok/kimi, against a third-party
harness’s observed behavior), and lives in gate4agent_catalog – the
crate that owns launch policy – not here; this type only names the
levels. Where a provider has no verified intermediate flag (grok and
kimi do not have one for Moderate or ReadOnly as of this writing),
the catalog’s mapping falls back to Unmanaged behavior (no injected
flag) rather than fabricating one – see
gate4agent_catalog::approval_level_args.
Variants§
FullAuto
No restriction: the provider CLI is launched with whatever flag
grants it full autonomy (Claude --permission-mode bypassPermissions,
Codex --dangerously-bypass-approvals-and-sandbox, Grok
--always-approve / --yolo, Kimi --auto). Default –
restricting is opt-in, not asking a human is the norm.
Moderate
The provider’s own middle ground, when one is verified (Claude
--permission-mode acceptEdits, Codex --sandbox workspace-write --ask-for-approval on-request). A provider with no verified
intermediate flag falls back to Unmanaged – never a fabricated
flag.
ReadOnly
Read-only: no writes, no command execution (Claude
--permission-mode default, Codex --sandbox read-only --ask-for-approval never). A provider with no verified read-only
flag falls back to Unmanaged.
Unmanaged
Impose nothing: launch with no approval-related flag at all and let the provider CLI use whatever it is configured with on its own.