For the complete documentation index, see llms.txt. This page is also available as Markdown.

Autopilot vs approval-first

The autonomy dial: approval-first by default, autopilot where you have deliberately opened it.

Approval-first

The platform starts with a simple posture: approval-first, everywhere. Nothing commits spend, sends, or record changes without a human saying yes. That is not a training-wheels mode; it is the default contract.

Autopilot

Autopilot is not a switch, it is a dial you open deliberately, per tool and per kind of action, using the gate modes: move a specific action from needs-approval to always-allow, and iHarness handles that class of work without asking, while still recording every decision as if it had asked.

How trust is supposed to build

1

Start approval-first

Read the reasoning on proposals; approve, modify, reject.

2

Notice what you always approve

When a class of action has earned a streak of unedited approvals, that is the candidate.

3

Open that gate, narrowly

One tool, one action type. Not "autopilot everything."

4

Audit by trace, not by trust

Autonomous decisions carry the same receipts as approved ones; the reasoning stays inspectable whether or not you were asked.

What autopilot never overrides

Suppression lists, consent, caps, and the one-cadence-per-contact rule bind autonomous actions exactly as they bind approved ones. And the whole dial closes instantly: return any gate to needs-approval, or blocked, at any time.

Practical recommendation: run approval-first for your first weeks. The approvals are how you calibrate the system, and how it calibrates to you.

Last updated