Agents

An agent that works. You review.

Four modes for different jobs. Tools follow your permission level. Nothing is written to disk in silence.

Eyeban · shop/checkout.py Balanced
41 def charge(order, wallet):
42     tax = order.subtotal * 0.09
43     total = order.subtotal + tax
44     if wallet.balance < total:
45         raise InsufficientFunds(total)
46     wallet.debit(total)
47     return Receipt(order.id, total)

Split regional tax from the hardcoded rate, and check coverage before debit.

Read 6 files · 2 searches · 1 test

charge still hard-codes 0.09. tax_for(region) exists. I will wire can_cover to the wallet.

12-line patch across two files. Review the diff.

main Agent Balanced You stay in review

Agent

Hand the work over

Agent reads files, writes patches, and uses shell and git with permission. For a concrete implementation.

Plan

Path first

Plan writes the approach. Product-code edits and shell are limited in this mode until you agree.

Ask

Just ask

Ask reads the repository and explains. It writes nothing to disk.

Debug

Evidence, then the fix

Debug gathers reproduction and a failure trail first; the fix waits for your OK.

Human in the loop

Every patch is readable. Apply happens when you say so. Switch modes mid-run; context is kept.

Permissions

Ask, Allow safe, or Allow all. Shell sandbox is Off / Soft / Restricted. Computer Use follows the same levels.

Questions

When should I pick each mode?

Concrete implementation with Agent. Design with Plan. Questions with Ask. A muddy failure with Debug.

Will the agent commit without me?

No. You see the diff. Nothing ships without you.

What does Allow all mean?

Tools run with less friction — review is not removed. Keep Ask or Allow safe on a sensitive tree.