Plan gating & approvals

For anything more than a single step, an OAP agent doesn't just start calling tools — it proposes a plan: a short list of phases, each declaring what it will do. A human approves the whole plan once, and that approval is scoped to exactly the plan it saw — to those phases, and to the specific resources named in them. Approve "open a PR on acme/widget" and the agent can act on acme/widget, and nothing else.

codebot proposes a plan to open a PR on acme/widget; one approval covers the plan and slots that repo.

The agent proposes a plan, not a pile of tool calls

In the clip, codebot is asked to fix a flaky test and open a PR on acme/widget. Rather than clone, edit, push, and open a PR as four separate asks, it lays out a plan — clone and read, make the change, then push and open the PR — and asks for one approval that covers all of it. You approve the shape of the work, not each keystroke.

The plan-gate approval card: each phase and the blast radius of its permissions — read, write, and the external step that opens the PR.
The plan-gate approval card: each phase and the blast radius of its permissions — read, write, and the external step that opens the PR.

The approval card is computed from the plan

The card isn't the agent's sales pitch — it's computed from the plan. It lists each phase and, under it, the blast radius of what that phase may do, in three tiers:

  • read — nothing leaves; the agent only looks.
  • write — it changes state, but the change stays inside the session and is reversible.
  • external — the effect leaves the session and can't be undone. Opening the pull request is the one external step here, and the card makes it impossible to skim past.

The agent's own justification is shown too, but under a label that says "the agent's words" — so a persuasive-sounding reason can never be mistaken for the system's own account of what is being approved.

Approval is scoped to the exact repo

Look at every phase in the card: each one reaches acme/widget. That isn't decoration — approving this plan slots acme/widget, granting the agent access to that repository and no other. The approval is bound to the exact repo it named.

The approval was slotted to acme/widget — a different repo needs a fresh one.
The approval was slotted to acme/widget — a different repo needs a fresh one.

Inside the plan, steps don't ask again; outside it, they do

Once you approve, the steps within the plan — clone, edit, push, open the PR — run without prompting you for each one. That's the point of approving a plan instead of a tool call.

Approved in one click; the steps inside the plan then run without prompting again, ending in an opened PR.
Approved in one click; the steps inside the plan then run without prompting again, ending in an opened PR.

But the moment the agent tries to do something the plan didn't cover — a permission it didn't declare, or a different resource — it stops and asks again. The approval buys exactly the plan you saw, and not one step more.