Zed Agent: Auto approval routing via classifier model #63092
gianpaj
started this conversation in
Feature Requests
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What are you proposing?
Add an
Autopermission mode to Zed Agent.In Auto mode, a separate reviewer model would inspect permission-gated actions before they run. It would decide whether each action is safe and consistent with the user's request.
The reviewer should return one of three decisions:
allow: run the action without interrupting the userdeny: block the action and tell the Agent whyask: use Zed's existing approval promptThe reviewer should be configured independently from the main agent model. Users could select any model available through Zed's existing LLM providers, including a local model through Ollama.
Existing permission rules would remain in place. Explicit deny rules, protected paths, and sandbox restrictions must always take precedence over the reviewer.
The reviewer model should be configured separately from the main Agent model. Users could choose any model available through Zed's LLM providers, including a local model through Ollama or an OpenAI-compatible server.
Auto mode should complement Zed's existing tool permissions and sandbox, not replace them. Deterministic deny rules, protected paths, and sandbox restrictions must remain authoritative.
Why does this matter?
Zed's current tool permissions work well for actions that can be described with stable rules. Users can allow, deny, or confirm terminal commands and other tools using patterns.
Many real actions depend on context, though.
For example:
git pushmay be expected when the user asks to publish a branch, but unexpected during a code review.Static rules cannot determine whether an action matches the user's request. This leaves users choosing between frequent approval prompts and broad allow rules.
Auto mode would reduce those interruptions without granting unrestricted access. It would help long Agent tasks continue on their own while preserving approval for actions that are risky, unclear, or outside the requested scope.
A configurable reviewer would also give users control over:
Are there any examples or context?
Claude Code's Auto mode uses a separate classifier to review actions before execution. Existing permission rules run first, common workspace operations skip the classifier, and unresolved actions receive model review. The classifier sees user instructions and tool calls but excludes tool results, which may contain hostile content. Repeated denials eventually pause Auto mode and restore normal approval prompts.
Existing open-source project that explores related designs:
pi-automodeapplies a separate configurable classifier to shell commands, file changes, MCP tools, network actions, and subagents. It is the closest example of a general-purpose Auto permission mode.This project suggests a useful combination for Zed:
pi-automodein supporting the full range of Agent tools and a separately configured model.askresult.Zed already has the main pieces: tool permissions, Agent sandboxing, configurable LLM providers and local models, and support for external agents through ACP.
Possible approach
Keep deterministic rules as the first layer:
The reviewer request could contain:
Raw file, terminal, and web content should not be included by default, as they may contain prompt injection.
The reviewer could return a small structured response:
{ "decision": "allow | deny | ask", "reason": "Short explanation" }Related GH discussions:
All reactions