Pattern: Every Major Harness Is Replacing Human Approval With a Model Reviewing the Model
Four vendors converged on the same conclusion within days: Claude Code makes classifier-screened auto mode the default on August 14, Codex CLI 0.147.0 shipped `--approve-for-me` for automatically reviewed approvals plus safer auto-review defaults specifically for cyber-capable models in 0.146.1, Zed 1.14.2 sandboxed its agent's terminal and fetch tools, and Devin Local added editable command approvals. The shared premise is that per-call human approval is security theater at a 97% approval rate. The practical consequence for builders: your defense-in-depth budget should move from 'read the prompt carefully' to blast-radius controls — disposable VMs, worktree isolation, scoped credentials, and hard-deny rules that no classifier decision can override.
Source
↳ Follow the thread