Blog · 2026-09-18 · 7 min

What YOLO Mode Should Never Do.

Auto-approval is a decision about attention, not permission. The boundary lives in the sandbox, and there are jobs no amount of automation makes safe.

Direct answer

Every agentic tool eventually offers a flag that stops asking. The teams that get value from it are the ones who understand the difference between approving an action and permitting it, and who keep a short, boring list of jobs where the flag is never used.

01

Approval is not permission

An approval prompt answers 'should we attempt this?' A sandbox answers 'is this possible?' They are different axes, and conflating them is how an auto-approving agent becomes an incident. The test is simple: with auto-approval on, can the agent read outside the project, write outside it, execute an arbitrary command, or reach the network when the policy says no? If yes, the flag is a permission escalation wearing a convenience costume.

In Anvaya the two are orthogonal: --yolo auto-approves tool calls, and the same declarative policy still governs reads, writes, execution, network and child-process environments. A policy-violating call is refused and reported, not retried into a different shape until something slips through.

02

The never list

Some jobs do not become safe because the tool is good. Force-pushing shared branches; anything touching production credentials or secret stores; migrations without a verified restore path; changes to authentication or billing code without a human in the loop; and merges the agent authorizes for itself. These are not automation problems, they are irreversible-consequence problems, and irreversibility is exactly what a bounded loop cannot manage.

A practical corollary: never grant an agent merge authority it can exercise alone. Verified work should land somewhere reviewable (an integration branch, a draft PR) and stop there. Automation that can both decide and land is not a pipeline; it is an outage with good intentions.

03

Where auto-approval is actually safe

Use it where revert is one command: clean git trees, narrow path scopes, jobs whose output is gated by tests you trust. The preconditions matter more than the flag: a clean tree means every change is reviewable as a diff, a narrow scope means an out-of-bounds action is refused rather than silently attempted, and trusted tests mean 'it passed' is evidence instead of optimism.

Pair it with backups and observability. File tools take timestamped backups before destructive edits, per-agent token and memory counters are visible while the run is live, and long jobs are watched by process monitors rather than a hope that nothing hung.

04

Plan, then run

The highest-value pattern with auto-approval is two-phase: a read-only planning pass first (no writes, no execution, a plan out) then a human or a policy gate before the mutating run. It costs one extra invocation and catches the class of mistake that no sandbox can: the agent confidently doing the wrong thing within its permissions.

The flag is not the interesting part. The boundary, the exit codes and the review gate are. Get those boring, and auto-approval becomes what it was meant to be: permission to skip typing 'yes,' not permission to skip thinking.

Questions

Asked About This Post.

Q

Is --yolo safe?

It is a decision about attention, not confinement. It is safe where revert is cheap and the sandbox is tight; it is never a way to unlock capability the policy otherwise refuses.

Q

What should an agent never auto-approve?

Force-pushes, secret-adjacent work, production paths, irreversible data migrations, and any merge the agent can authorize by itself.

Q

How do I check a tool's boundary?

Read its policy surface: does auto-approval widen confinement, are all execution paths governed by the same check, and are refusals explicit? If a tool cannot answer that, assume the flag is an escalation.

Run Agents That Fit On Your Laptop.

25.6 MB median RSS. 25 agents ran in parallel on a Core 2 Duo with 4 GB RAM. Hundreds on your machine. Zero cloud required on the Ollama path.

Requires Rust/cargo to build from source. Linux and macOS today, Windows not yet supported. Pre-1.0, public beta. Pricing TBD.