Guide

Who approves a coding agent's changes on a team?

Every coding agent can ask before risky actions. Almost all of them ask one person.

Every major coding agent can stop and ask before it edits files or runs commands, and almost all of them ask exactly one person: whoever is running it. As of October 2026 Claude Code starts in auto mode, where a classifier model approves actions instead of you, and Codex starts in a sandbox and asks only when it wants to step outside. Teams bring other people in three ways: rules an admin sets in advance (managed settings in Claude Code and Codex, team settings in Cursor, allow rules in Claude Tag), review afterwards (a pull request someone else must approve, as GitHub Copilot requires), or a live approval that anyone in the room can give (Slack Code channels, Claude Code's channel relay and Poly).

Key takeaways

  • Claude Code: auto mode has been the default for new sessions on Pro, Max and Team since August 14, 2026, and on every plan since v2.1.284 on September 28.
  • People approve 97% of Claude Code's permission prompts, Anthropic says, and in its study human review caught 13.6% of dangerous commands.
  • Codex: a workspace-write sandbox with on-request approvals in a git folder. Approvals go to you or to an AI reviewer; there's no teammate option.
  • Approving from a phone works in both, but only from the same person's account.
How coding agents ask for approval, from each vendor's docs, October 5, 2026.
Starts inWho can approveTeam controls
Claude CodeAuto mode, a classifier reviews actionsYou; anyone in a channel relay (preview)Managed settings; can remove auto and bypass
CodexWorkspace-write sandbox, on-request approvalsYou, or an AI reviewerA requirements file limits policies and reviewers
CursorAuto-reviewYou; cloud agents don't askTeam settings and rules override personal ones
GitHub Copilot cloud agentWorks in a pull requestSomeone else with write access, at reviewBranch protection and required checks
Claude Tag (Slack)Auto mode with admin allow rulesRules set in advance; guests can't approveAdmin allow rules
Slack CodeA code channel per taskEveryone in the channel signs off; high-stakes changes go to a personSlack's permissions and admin controls
PolyJust build; four modes per roomAny member, before each change, in the modes that askThe owner can lock the room's mode

How do approvals work in Claude Code?

Claude Code's permission modes: Manual stops and asks before most edits, shell commands and network access; Accept edits lets file changes in the working directory through; Plan researches and proposes without changing anything; Auto has a second model, the classifier, review actions instead of you; dontAsk denies anything not pre-approved, for CI; and bypassPermissions is for isolated containers and VMs only. Shift+Tab cycles them. Settings add allow, ask and deny rules, checked deny first, and a deny at any level can't be overridden; PreToolUse hooks can allow, deny or ask, but can't get around the rules (permissions).

Auto became the default in two steps. Anthropic announced on August 7 that new sessions on Pro, Max and Team would start in auto mode from August 14 (Anthropic). Claude Code v2.1.284, on September 28, made auto the starting mode on every plan and provider whenever no mode is configured (changelog). If auto mode blocks three actions in a row, or twenty in a session, it falls back to manual approvals.

What is approval fatigue?

Approval fatigue is saying yes without reading, because the agent asks so often. Anthropic's own numbers make the case (Anthropic):

  • Users approve 97% of permission prompts in Claude Code. In March, Anthropic's figure was 93%.
  • In a study of 1,053 paid testers, human review caught 13.6% of dangerous commands; auto mode caught 89%.
  • People blocked about 17% of dangerous commands early in a session, and about 5% after 50 or more prompts.
  • People reject plans far more often than single steps: 39% of plans, against 3% of permission prompts.
  • A quarter of interactive sessions start in bypass mode.

For a team, the lesson is that a stream of yes-or-no prompts to one tired person isn't much of a control. Approving plans, approving fewer and bigger steps, and having a second person in the loop for those all help.

How do approvals work in Codex?

Codex pairs a sandbox with an approval policy (OpenAI). The sandboxes are read-only, workspace-write and danger-full-access. The policies are on-request and never, plus granular rules; OpenAI retired the untrusted policy in August 2026 and deprecated on-failure in February, and a stricter untrusted trust level remains for projects. In a git folder Codex starts in workspace-write with on-request approvals and the network off; elsewhere it starts read-only. The desktop app calls the settings Ask for approval, Approve for me and Full access.

Approval requests go to you, or to Auto-review, a separate reviewer agent. There's no setting that sends them to a teammate. Codex Cloud tasks end with a diff you review before committing or opening a pull request.

Can you approve from your phone?

Yes, as yourself. Claude Code's Remote Control sends push notifications for permission prompts and keeps them open until you answer, in the Claude app or on the web, and it grants no one else access (Anthropic). Codex Remote lets you follow progress and approve actions from your phone, signed in to the same ChatGPT account and workspace (OpenAI).

One Anthropic feature does let other people answer. Claude Code's channels, a research preview for Telegram, Discord and iMessage, can relay permission prompts, and anyone who can reply through the channel can approve or deny tool use in your session; whichever answer arrives first wins (Anthropic). Team and Enterprise organizations have to switch channels on first.

Can someone else approve an agent's changes?

Teams get there in three ways.

  • Rules set in advance. Claude Code's managed settings can't be overridden by users and can remove bypass and auto mode (Anthropic). Codex's requirements file can limit approval policies, sandbox modes and reviewers. Cursor's team settings and required team rules take precedence over each person's. Claude Tag works this way too: its sessions in Slack run in auto mode, an admin pre-approves routine actions with allow rules instead of anyone approving in the moment, and guests can't approve requests (Anthropic).
  • Review afterwards. GitHub Copilot's cloud agent can't approve or merge its own pull requests, the person who asked for the pull request can't approve it, and workflows wait for someone with write access (GitHub). Cursor's cloud agents never ask for approval while they run, and an admin setting called Team follow-ups decides whether teammates can direct someone else's agent; Cursor warns this lets one user act with another user's secrets (Cursor). Zed's Delta has no agent permission system: its agent doesn't ask before calling tools, even destructive ones, and review happens afterwards in subthreads (Delta).
  • Live, from anyone in the room. Slack Code's code channels give everyone involved the ability to suggest changes, view them and sign off on the agent's output, and high-stakes changes can go to a person for approval (Slack). Claude Code's channel relay lets anyone who can reply approve. Poly does it for every change.

How do approvals work in Poly?

Each Poly room chooses how much the agent does on its own: show a plan first, ask before big steps, ask about everything, or just build, which is where new rooms start. In "ask about everything", every file edit and every shell command becomes a plain-language card on every member's screen before it happens; in "ask before big steps", edits go through and commands ask. Any member can approve or reject a card, the first decision counts, and the timeline records who made it. The room's owner can lock the mode, every turn is a commit anyone can undo, and turns run in a sandbox whose network reaches only an allowlist: a new domain is held while the room decides, and nothing is approved automatically (Security).

The difference from the tools above is who the card goes to. It's not one person, and not only a rule written in advance: it's anyone in the room, live, including people who don't code.

Which setup fits your team?

  • One engineer on a trusted repository: auto mode, or Codex's defaults, with deny rules for anything that must never happen.
  • A company rolling out agents: managed settings and a requirements file, so nobody can switch the protections off.
  • Code that ships to production: an agent that opens pull requests, and branch protection so someone else approves them.
  • A team that wants a person, from any seat, to say yes before changes land: a shared session like Poly, or Slack Code if you live in Slack.

More on sharing one agent safely: Secure shared coding-agent workspaces.

Common questions

What is auto mode in Claude Code?

A permission mode where a second model, a classifier, reviews the agent's actions instead of you. It has been the default for new sessions on Pro, Max and Team since August 14, 2026, and on every plan since v2.1.284 on September 28. Admins can remove it with managed settings.

How do I stop Claude Code asking for permission every time?

Switch modes with Shift+Tab: Accept edits lets file changes through, and auto mode lets a classifier decide. Allow rules in settings pre-approve specific commands, and deny rules block others in every mode.

Can a teammate approve my Claude Code session?

Not natively, except through the channels research preview, where anyone who can reply in the channel can approve or deny. Remote Control is for your own account. In a shared room such as Poly, any member approves.

Does Codex still support the untrusted approval policy?

No. OpenAI retired it in August 2026. The current policies are on-request, never and granular rules, and a stricter untrusted trust level remains for projects.