Give your coding agent an "ask... Note

Give your coding agent an "ask first" list, not just a "never" list

Agent configurations require three distinct modes for effective operation: 'never', 'ask first', and 'fine without asking'. A simple deny-list for actions is insufficient for real-world tasks. The 'never' bucket includes actions like inventing secrets, force-pushing, or deleting data outside the working tree. The crucial 'ask first' category prevents unintended consequences by requiring user confirmation for critical operations. This includes pushing to remotes, schema migrations on non-local databases, installing new dependencies, and altering CI or deploy configurations. Actions deemed safe and routine fall into the 'fine without asking' bucket. These involve editing files within the working tree, running tests and linters, and accessing logs or local documentation. This three-bucket system ensures agents fail safely on irreversible actions while remaining efficient for everyday tasks. It also streamlines code reviews by highlighting actions that required explicit user approval. New team members can quickly understand established guidelines by reviewing these concise rule lists.