Choosing identity per session
Some agents shouldn't have their identity fixed in advance — the right answer depends on the task. For those,
ask and dynamic put the choice to the person at the start of the session, before the
agent touches anything.
The choice
At session start, the agent pauses and asks whose identity to use. It's a real interaction card with three options — run as the agent, run as me, or cancel — and only the person who started the session can answer it.

ask vs. dynamic
askpresents the choice blank: two buttons, no lean.dynamicadds an advisory recommendation. An isolated recommender LLM looks at what's being asked and suggests one option — here, because Jordan asked codebot to push to their fork, the recommendation is "Run as me," shown as a highlighted button with a short reason. The suggestion is only a suggestion; the person still confirms.
Notice how the recommendation is presented: the suggested action and the "Why" are shown as inert text, boxed off from the buttons. That's deliberate — the recommender's reasoning can reflect the conversation, which may be attacker-influenced, so it's never rendered as live markup that could smuggle in an instruction.
Nothing runs until you answer

Once Jordan chooses "Run as me," the session resolves to userPassthrough and codebot proceeds under Jordan's
identity — the push and the PR are Jordan's. If the person cancels or the prompt times out, the session fails
closed rather than silently defaulting to the agent's own account. A userPassthrough or ask/dynamic
session always pauses on identity — it never guesses.