[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ferpdulk6060q":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":59,"categories":61,"source":63,"lang":66,"author":67,"audioState":70,"stats":71,"publishedAt":74,"renderer":75},"6abd07e4ca21c797c7ea176e","why-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0","Why APX Rejects Invalid Agent Autonomy Instead of Guessing","An agent autonomy setting looks like small metadata.","news",[10,14,19,24,29,34,39,44,49,54],{"headline":6,"body":11,"imageUrl":12,"images":13},"An agent autonomy setting looks like small metadata. It is not. It can decide whether a tool runs now or pauses for a human. That makes guessing the wrong response to invalid input.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F0.webp",{"local":12},{"headline":15,"body":16,"imageUrl":17,"images":18},"APC provides portable project context: agent files, roles","APC provides portable project context: agent files, roles, skills, and project metadata travel with the repository. APX is the local runtime that reads that context, runs agents, and enforces tool permissions on the machine. The boundary matters here: a portable agent declaration may request an autonomy mode, but APX must turn that declaration into a real, local permission decision. APX has three permission modes: total: tools run without confirmation.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F1.webp",{"local":17},{"headline":20,"body":21,"imageUrl":22,"images":23},"automatico: safe work can proceed; destructive, outbound, runtime","automatico: safe work can proceed; destructive, outbound, runtime, MCP, and filesystem-mutating work can require confirmation. permiso: only allowed_tools run directly; every other tool asks.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F2.webp",{"local":22},{"headline":25,"body":26,"imageUrl":27,"images":28},"A project has a baseline mode in its","A project has a baseline mode in its runtime configuration. An individual agent can declare Autonomy: to override that baseline for its own turn. An agent with no declaration inherits the project setting. Imagine a project whose normal setting is automatico, and a review agent should be more constrained:","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F3.webp",{"local":27},{"headline":30,"body":31,"imageUrl":32,"images":33},"Now imagine someone edits the card and writes","Now imagine someone edits the card and writes Autonomy: permissive. A permissive parser might map that to total, choose the nearest known word, or silently save a value that later means something else. Each path turns a typo into an authorization decision.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F4.webp",{"local":32},{"headline":35,"body":36,"imageUrl":37,"images":38},"APX does not invent a mode. When it","APX does not invent a mode. When it reads a stored autonomy field, an unrecognized value is dropped and the agent inherits the project baseline. That protects the runtime from treating garbage as a new, wider permission setting. It also keeps the effective policy explainable: either a recognized agent override applies, or the project policy applies.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F5.webp",{"local":37},{"headline":40,"body":41,"imageUrl":42,"images":43},"There is an important nuance. Inheritance is not","There is an important nuance. Inheritance is not a substitute for validation. If the project baseline is broader than the author intended for that agent, a malformed stored value will not magically preserve the intended restriction. That is why APX handles direct CLI input differently: apx agent ... --autonomy rejects an invalid value and tells the user the accepted modes, including inherit. A person at a terminal gets a visible error instead of a plausible-looking success message. Use these meanings consistently:","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F6.webp",{"local":42},{"headline":45,"body":46,"imageUrl":47,"images":48},"Then verify the result in the agent file","Then verify the result in the agent file and test an action that should pause. Configuration text alone is not evidence that the tool loop uses it. APX applies a valid agent override to the active turn configuration before its permission guard and risk handling run.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F7.webp",{"local":47},{"headline":50,"body":51,"imageUrl":52,"images":53},"The portable side should say who the agent","The portable side should say who the agent is and, when useful, its intended operating boundary. The runtime side must decide what the current machine can actually execute, prompt on, or deny. APC does not become a hidden authorization database; APX does not treat a typo as authority.","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F8.webp",{"local":52},{"headline":55,"body":56,"imageUrl":57,"images":58},"That division makes agent behavior safer to review","That division makes agent behavior safer to review. A teammate can inspect the declared agent contract in the repository. The local runtime can enforce it without copying private runtime state back into APC. And when an autonomy value is wrong, the system has one honest answer: stop guessing and fix the value. For further actions, you may consider blocking this person and\u002For reporting abuse","\u002Fapi\u002Fmedia\u002Fposts\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-733d2ff0\u002F9.webp",{"local":57},[60],"dev",[62],"Technology",{"name":64,"url":65},"Dev.to","https:\u002F\u002Fdev.to\u002Fagentprojectcontext\u002Fwhy-apx-rejects-invalid-agent-autonomy-instead-of-guessing-k04","en",{"handle":68,"displayName":69},"spots","Spots","queued",{"views":72,"likes":73,"saves":73,"shares":73,"completions":73,"opens":73,"skips":73,"depthSum":73},1,0,"2026-09-30T13:00:20.840Z","local"]