Permissions, Safety & Shipping
A coding agent that can run commands and edit files is powerful — and that is exactly why it needs guardrails. Permissions decide what the agent may do without asking you first.
How Permissions Work
Whatever the tool, the same three ideas keep you in control:
- Approve risky actions — the agent asks before doing something destructive, like deleting files or overwriting your work.
- Scope its reach — you decide which files, tools, and commands it is allowed to touch.
- Least privilege — grant only what the task actually needs, nothing more.
Limiting the Blast Radius
An agent acting on your machine can delete files, leak secrets, or run a bad command. Guardrails do not make mistakes impossible — they make them recoverable and keep the damage small.
Your Undo and Review Gate
The habits from Module 2 — version control and testing — are your safety net when an agent is doing the work:
- Commit small — frequent commits mean any bad change is a quick revert away.
- Open a pull request — a checkpoint to review the agent's work before it lands.
- Run CI — let the tests pass before merging, every time.
Trust, But Verify
Give the agent room to move fast — but keep the safety rails up. Permissions, small commits, and passing tests together mean a bad step is cheap to undo, so you can let the agent work boldly without betting the project on it.
Build It
How to implement: before letting an agent run freely, make sure your work is committed, decide which actions it must ask you about, and keep secrets out of its reach.
- Weekly AI Tasks tracker — never let the agent commit your API keys or messaging tokens; review any change to auth or the public webhook.
- Personal brand site — low risk, but still commit before big changes so you can revert a design the agent got wrong.
What you learned
Module 3 made you fluent with coding agents — directing them, and now working with them safely. Permissions scope what an agent may do; version control and tests make every step reversible.