Skip to content

The datasheet for every AI agent

Research report · data-report

Agent permissions: a census of 126 listings

64 of 126 listings answer yes for “Agent permissions”. Counted from our own datasheet, with the query that reproduces every figure.

Sep 14, 2026updated Sep 16, 20262 min readSource-linked research

Agent permissions, across 126 settled listings

  1. Yes64 of 126

  2. Qualified61 of 126

  3. No1 of 126

Of the 126 Published listings whose datasheet settles “Agent permissions”, the largest group is “Yes” at 64 (51%). Measured 2026-09-16.

Denominator: 126 Published listings whose datasheet settles “Agent permissions”.Method: Counted from the stored datasheet answer for “Agent permissions” across every Published listing, all of which have a recognised stored answer on that row.Measured .
Cite this chart

Reuse this chart anywhere, with credit. Paste this HTML — it links back to the report the numbers come from.

<a href="https://theagentsindex.com/blog/agent-permissions-census/" target="_blank" rel="nofollow noopener"><img src="https://theagentsindex.com/charts/agent-permissions-census.png" alt="Agent permissions, across 126 settled listings — The Agents Index" title="Agent permissions, across 126 settled listings — The Agents Index" width="640" loading="lazy" style="max-width:100%;height:auto" /></a>

Explore the matching agents

Agent permissions · Datasheet criterion agent_permissions · Report counted .

Current listings as of ; this set may differ from the report's original sample. Includes “Yes” and “Qualified” answers only. Read the conditions on qualified answers before treating them as a match. “No”, “Not applicable” and “Not established” answers are excluded.

View 125 current matching records
  • 11x Yes

    Messages can be gated behind approval workflows, or the worker can run unattended on autopilot.

    Source retrieved 2026-09-03

  • Ada Yes

    Every connected tool starts off and is enabled one at a time, write tools can be gated behind a Playbook, and availability rules limit what content the agent may reach mid-conversation.

    Source retrieved 2026-09-09

  • AgentBridge Qualified

    Two states only: max-permission by default, or --safe to restore each CLI's normal prompts. The vendor states it is not a security boundary.

    Source retrieved 2026-09-02

  • Agentix Labs Yes

    Permissions are scoped per workflow and anything consequential or external stops for a human, with dry-run modes and action receipts around writes.

    Source retrieved 2026-09-09

  • AgentsKit.js Yes

    Tool-level allow, deny and require policies plus per-tool quotas and confirmation-gated tools decide what runs unattended, though every constraint is opt-in code you write.

    Source retrieved 2026-09-09

  • Agno Qualified

    Runs are unattended unless a tool is marked for approval; then the run pauses in your database until an admin resolves it.

    Source retrieved 2026-09-02

  • Aide Yes

    Permissions are enumerated per intent as a Scenario: the team fixes the conditions and the allowed actions, and anything outside escalates instead of firing.

    Source retrieved 2026-09-03

  • Aider Qualified

    It applies edits and git-commits them without asking, while prompting before adding files or running suggested shell commands; those prompts can be switched off wholesale, and shell suggestions disabled entirely.

    Source retrieved 2026-09-09

  • Aisera Agent Studio Qualified

    The brake is a node you place, not a policy the platform enforces: a workflow author drops an Ask Approval step where a human must sign off, and anything without that step runs unattended.

    Source retrieved 2026-09-03

  • Amplemarket Qualified

    The agent may research and draft freely but stops before the send, and the prompts steering it are gated: admins alone edit the per-signal nudge and competitor battlecards, while reps get edit, regenerate or send.

    Source retrieved 2026-09-10

  • Antigravity CLI Yes

    Every sensitive action is an action(target) resource sorted into deny, ask and allow lists with deny winning, and unconfigured commands, MCP tools and out-of-workspace files default to asking.

    Source retrieved 2026-09-10

  • Artisan Yes

    Guardrails are explicit and per campaign: approve before sending, locked tone and CTAs, banned phrases, escalation rules and DNC lists, with full autonomy as the default setting.

    Source retrieved 2026-09-10

  • AudioCodes Live Hub Qualified

    Limits are set at design time: tool allow-lists, valid transfer numbers, Max turns. The vendor warns prompt guardrails are not a security boundary, and there is no runtime human approval step.

    Source retrieved 2026-09-03

  • Augment Code Yes

    allow/deny/webhook/script rules per tool and per shell regex, committed in .augment/settings.json.

    Source retrieved 2026-09-02

  • AutoGen Qualified

    Permission is code you write: an approval callback invoked before each code execution, a UserProxyAgent that blocks for human input, max_turns and termination conditions. Nothing is gated by default.

    Source retrieved 2026-09-02

  • Auto-Respond Qualified

    It acts unattended inside limits you preset - pricing on or off, services it must decline, transfer criteria, custom rules - but there is no per-action approval queue; a human reply in the thread is what stops it.

    Source retrieved 2026-09-11

  • Bitsclan IT Solutions Qualified

    Escalation to a human is named as the boundary and agents write into live systems, but no published control describes what an agent may do before it has to ask.

    Source retrieved 2026-09-11

  • Bland Qualified

    Guard rails bound what an agent may say and can end, transfer or reroute a call; custom rails are Enterprise-only.

    Source retrieved 2026-09-11

  • Bolt Qualified

    Plan Mode keeps it read-only until you approve, and Code view lets you target or exclude files, but there is no per-action approval or permission policy.

    Source retrieved 2026-09-11

  • Botpress Qualified

    A human can approve AI output before it is sent, and an Autonomous Node cannot read or write variables until access is granted; no approval gate exists before a tool call executes.

    Source retrieved 2026-09-02

  • Botsify Qualified

    Access is scoped by explicit authorisation of APIs and documents and can be withdrawn at any time, but no approval prompts, action allowlists or human-confirmation steps are documented before an agent acts.

    Source retrieved 2026-09-13

  • Browserbase Qualified

    Per-session domain allowlisting restricts navigation, but the feature is marked experimental and covers top-frame navigation only.

    Source retrieved 2026-09-02

  • Cartesia Qualified

    Limits are prompt-level guardrails plus per-tool execution settings (timeout, immediate vs async, speak-before-acting); there is no separate policy engine.

    Source retrieved 2026-09-02

  • Claude Agent SDK Yes

    Six permission modes plus allow/deny rules, hooks and a canUseTool callback, evaluated in a documented six-step order.

    Source retrieved 2026-09-02

  • Claude Code Yes

    Starts read-only and asks per action in Manual mode; allow/ask/deny rules, six permission modes, and a bash sandbox set the boundary.

    Source retrieved 2026-09-02

  • Cline Yes

    Approval is per tool call across eight named categories - reading, editing, safe commands, all commands, browser, MCP - each toggled separately, with outside-workspace access gated behind the base toggle.

    Source retrieved 2026-09-12

  • CodeRabbit Qualified

    The agent inherits your Git permissions and branch protections and cannot push around them, and Plan mode adds an approval gate, but there is no per-action policy engine documented.

    Source retrieved 2026-09-15

  • Codex CLI Yes

    OS-enforced sandbox with workspace-only writes, network off by default, and configurable approval policy.

    Source retrieved 2026-09-02

  • CommentKeyword Qualified

    The agent acts inside a configured objective, required fields and handoff rules, and stops for a human when the buyer's conditions trigger; it cannot act outside Instagram DMs.

    Source retrieved 2026-09-05

  • Crescendo Yes

    A named Safe Action Framework splits autonomous actions from ones needing human approval, and published integration tools carry typed inputs, permissions and review before the agent may call them.

    Source retrieved 2026-09-12

  • Cresta Qualified

    Agents act within escalation policies, compliance boundaries and an always-on guardrail library, and supervisors can steer or take over a live call; Cresta publishes no per-action approval or confirmation model.

    Source retrieved 2026-09-13

  • CrewAI Qualified

    Code execution is off by default in the framework and the platform adds human-in-the-loop checkpoints and guardrails, but the governance layer described here is an Enterprise plan feature.

    Source retrieved 2026-09-13

  • Cursor Yes

    Run Modes set how much runs unasked, with a sandbox and a review classifier; permission tokens allow or deny shell, read, write, web fetch and named MCP tools.

    Source retrieved 2026-09-02

  • Decagon Yes

    The agent executes real operations such as refunds and identity verification, and how far it may go before escalating is set by AOP guardrails and guidelines.

    Source retrieved 2026-09-14

  • Deepgram Voice Agent API Qualified

    What the agent may do is bounded by the function definitions you send in Settings, and you choose whether each function executes client-side or against an endpoint you host. No approval or confirmation gate is documented: once a function is defined, the model may call it mid-conversation.

    Source retrieved 2026-09-02

  • Devin Yes

    Graded modes from prompt-before-writing up to full bypass, plus an OS-sandboxed autonomous mode.

    Source retrieved 2026-09-02

  • Devin Desktop Yes

    Deny/Ask/Allow rules per action class, OS-level sandboxing with filesystem and domain filtering, and MCP tool calls prompting by default; Enterprise admins can enforce all of it.

    Source retrieved 2026-09-03

  • Dify Qualified

    Autonomy is bounded by design, not by a permission prompt: a Human Input node pauses a run for review, approval or edits, with a timeout branch.

    Source retrieved 2026-09-02

  • Dust Qualified

    Tools carry stake levels: high-stake ones such as scheduling a wake-up require user confirmation, and the code sandbox only reaches domains an admin allowlisted.

    Source retrieved 2026-09-09

  • ElevenLabs Agents Yes

    Tool use is gated per MCP server and per tool: always ask, fine-grained (auto-approved, requires approval, disabled), or no approval at all.

    Source retrieved 2026-09-02

  • Elicit Qualified

    The agent runs a whole plan unattended once launched; the only documented gates are the clarifying questions it asks up front, an effort slider, and an explicit approval before a new skill is saved.

    Source retrieved 2026-09-14

  • Factory Yes

    Four autonomy levels (Off/Low/Medium/High) gate tool risk, plus allowlists, denylists and an unbypassable blocklist.

    Source retrieved 2026-09-02

  • Fin Yes

    Field-level data access restriction, OAuth-scoped integrations, and escalation instead of answering when it cannot answer safely.

    Source retrieved 2026-09-02

  • Firecrawl Qualified

    Any caller can fence a run per request with strictConstrainToURLs, a maxCredits ceiling defaulting to 2,500, and a low/medium/high effort budget. A server-enforced, non-bypassable organisation policy exists only on Enterprise, and only team admins may set it.

    Source retrieved 2026-09-03

  • GC AI Yes

    Permissions are set per action type rather than per app, so searching an inbox and sending mail are separate grants, and an in-chat card offers Approve, Always approve or Deny before anything leaves.

    Source retrieved 2026-09-14

  • Gemini Code Assist Yes

    Plans and tool calls are approved during execution; VS Code coreTools/excludeTools allow and deny lists reach individual shell commands. JetBrains offers approve or auto-approve only.

    Source retrieved 2026-09-02

  • Genspark Qualified

    Controls exist but the vendor states their limits plainly: the local workspace folder is guidance rather than a boundary, while Claw DMs default to approved contacts and AgentBase advises draft-only sending.

    Source retrieved 2026-09-15

  • GitHub Copilot Qualified

    Read-only actions run unattended; destructive shell commands, file writes and URL access need explicit approval, which you can persist per repository or waive entirely with --allow-all.

    Source retrieved 2026-09-02

  • Glean Qualified

    Write actions require confirmation and are checked before execution; source-system permissions are re-checked on every request, but read work proceeds unattended.

    Source retrieved 2026-09-02

  • Google Agent Development Kit (ADK) Yes

    Autonomy is set per tool by the developer: a tool can be configured to pause and ask a human or a supervising system before it runs, though the vendor labels this confirmation feature experimental.

    Source retrieved 2026-09-15

  • goose Yes

    Four permission modes span full autonomy to chat-only, with per-tool Always allow / Ask before / Never allow rules, switchable mid-session; the default grants shell and file writes without asking.

    Source retrieved 2026-09-16

  • GPT Researcher Qualified

    There are no approval prompts mid-run; you constrain it beforehand through configuration such as domain allow-lists, report source and depth, and its actions stay read-only research.

    Source retrieved 2026-09-16

  • Gumloop Yes

    Per-app presets (always allow, ask each time, ask for writes and deletes, custom), per-tool never-allow, and CEL rules on the actual arguments decide what runs before it asks.

    Source retrieved 2026-09-09

  • HeyRik Qualified

    The agent acts freely inside the flow you draw but can only take actions you explicitly wire up: each tool or custom API must be registered and authorised first, and money and KYC workflows stay out of its reach in the dashboard.

    Source retrieved 2026-09-10

  • HOL Guard Yes

    This is the core of the product: every supported action routes to block, review, warn or allow, with project and team overrides layered in a defined precedence order.

    Source retrieved 2026-09-07

  • IrisAgent Yes

    Permissions are set per intent: guardrails and escalation rules are written as plain-English procedures, and auto-send only happens above a confidence threshold you choose.

    Source retrieved 2026-09-03

  • jobfinder-ai Yes

    Approvals and automation settings sit with the account holder: the first email batch is manual, every form or email can be reviewed, and sending is rate-limited per account.

    Source retrieved 2026-09-14

  • Juggler Yes

    Tool calls pass through approval gates whose width you choose per tool, per read-only set or per server, and strategies decide which tools exist at all in a given turn; nothing destructive runs unasked by default.

    Source retrieved 2026-09-17

  • Julius AI Qualified

    Roles and permissions govern what members may do, and that row is ticked only for Business and Enterprise.

    Source retrieved 2026-09-02

  • Junie Yes

    Deny-by-default for sensitive actions, an "Always allow" persistent allowlist file, and a three-level brave mode dial (Off, Auto, On).

    Source retrieved 2026-09-02

  • Kilo Code Qualified

    Auto-approve exists, but the OS-level sandbox that bounds it is experimental and Linux/macOS only.

    Source retrieved 2026-09-02

  • LangChain Yes

    Three approval modes: Manual asks before every gated action, Auto has a model classify routine ones, YOLO asks nothing.

    Source retrieved 2026-09-02

  • Langflow Qualified

    Default is ungated tool calling; approval is opt-in per tool, and then the run checkpoints and waits for a human Approve or Reject before continuing.

    Source retrieved 2026-09-03

  • LangGraph Qualified

    There are no preset permission tiers: you decide where the agent must stop by placing interrupt() calls, which pause the graph and wait for approval before continuing.

    Source retrieved 2026-09-02

  • Lead Scorer Qualified

    It may discover, enrich, score, draft and queue on its own; spending and sending are fenced. Billable tools estimate first and refuse oversized calls, and no tool can put a campaign into sending.

    Source retrieved 2026-09-02

  • Leaping AI Qualified

    Boundaries are expressed as transfer and escalation rules: the agent hands the call to a person or another system, including over SIP. No approval gates, action allow-lists or per-tool permission model are documented.

    Source retrieved 2026-09-09

  • Letta Yes

    Four modes from strict to unrestricted, plus allow/deny tool patterns and a cross-agent memory guard.

    Source retrieved 2026-09-02

  • Lindy Yes

    Per-integration guardrails offer Always allow, Require approval, or Don't offer, and they cover writes only; approval prompts land in the Slack thread with Approve and Deny buttons.

    Source retrieved 2026-09-02

  • LiveKit Agents Qualified

    No built-in human-approval gate: the model calls whichever tools the developer exposes. Bounding is by construction: MCP toolsets can be filtered by tool name or set to require confirmation on a duplicate call.

    Source retrieved 2026-09-02

  • LlamaIndex Qualified

    Framework exposes human-in-the-loop and state as building blocks the developer wires up; the vendor publishes no policy engine that gates agent actions.

    Source retrieved 2026-09-02

  • LuMay Yes

    Human-in-the-loop gates sit in the orchestration layer, so an agent's reach before it must ask is a configured policy rather than a fixed product behaviour.

    Source retrieved 2026-09-09

  • Manus Qualified

    Authorisation is per task and per connector, with watch-and-interrupt for the browser and confirmation gates on terminal commands and high-credit runs, but not per-action approval for cloud tasks.

    Source retrieved 2026-09-02

  • Mastra Yes

    Tool approval can gate any tool call, per server or by predicate on tool name/arguments; approvals propagate up a subagent delegation chain.

    Source retrieved 2026-09-02

  • Maven AGI Yes

    Permissions are hard constraints fixed before the agent runs. Access, actions and the escalation threshold are set by surface, role and policy, so the model cannot widen its own scope mid-conversation.

    Source retrieved 2026-09-03

  • Microsoft Agent Framework Yes

    Approval is per tool and declarative: LocalShellTool asks for every command and disabling that requires acknowledge_unsafe, ShellPolicy pre-filters commands, and the Copilot backend cannot touch shell, files or URLs without a permission handler.

    Source retrieved 2026-09-02

  • MindStudio Yes

    Checkpoint blocks pause a run for human review and revision before it proceeds, and per-agent and per-user spend limits cap what a run may consume.

    Source retrieved 2026-09-02

  • Moveworks Yes

    Agents act with the user's own OAuth-delegated access, and builders gate actions with the Approvals Engine (sequential, parallel, conditional) and Policy Validators.

    Source retrieved 2026-09-02

  • Muse Code Yes

    Three approval modes, stage-by-stage shell review, per-workspace trust, and an OS sandbox that refuses to run a command when it cannot prove containment.

    Source retrieved 2026-09-02

  • n8n Yes

    Approval is wired per tool: the workflow pauses and a reviewer approves or denies through Chat, Slack, Discord, Telegram, Gmail or Outlook. Tools with no review step execute unattended.

    Source retrieved 2026-09-02

  • NeverApply Yes

    Guardrails are explicit and pre-set by you: Ask pauses on a missing required answer, Send composes and submits, plus a daily cap, skip-list and minimum gap between sends.

    Source retrieved 2026-09-05

  • OmniDimension Qualified

    The agent acts alone inside limits you write in advance: natural-language transfer and hang-up conditions, a hard call-length ceiling and per-campaign calling hours, so escalation is pre-configured rather than requested mid-call.

    Source retrieved 2026-09-09

  • OpenAI Agents SDK (Python) Yes

    Per-tool approval rules pause the run; approvals can be manual interruptions, per-call callbacks, or sticky always-approve decisions, and callable rules fail closed on malformed arguments.

    Source retrieved 2026-09-02

  • OpenAI Realtime API Yes

    Tool surface is constrained per session with allowed_tools and require_approval; an approval request becomes a conversation item your client must answer before the tool runs.

    Source retrieved 2026-09-02

  • OpenClaw Qualified

    Four session permission modes (read-only, guarded, workspace, full) plus exec approvals and tool policy exist, but the shipped default is a single trusted operator with no prompts.

    Source retrieved 2026-09-02

  • OpenCode Yes

    Each action resolves to allow, ask or deny, with per-command and per-path granularity plus guards for external directories and repeated calls.

    Source retrieved 2026-09-02

  • OpenHands Yes

    Three confirmation policies: approve everything, nothing, or only actions an LLM security analyzer rates risky. The same modes are switchable mid-session in the CLI and IDE surfaces.

    Source retrieved 2026-09-02

  • Perplexity Qualified

    API runs are bounded by the connected account's own permissions, an allowed_tools allowlist and a max_steps loop cap; no per-action human approval prompt is documented.

    Source retrieved 2026-09-02

  • Pickaxe Qualified

    Control is up-front rather than interactive: you scope what an agent may do with trigger prompts and by choosing whether an Action runs through your account or the end user's, with no documented approval prompt before it fires.

    Source retrieved 2026-09-09

  • PolyAI Qualified

    Wren plans and waits for approval by default, always asks before writing to the live environment, never receives secret values, and its API discovery requests are GET-only.

    Source retrieved 2026-09-02

  • Pydantic AI Qualified

    You choose the ceiling: shell tools take allow/deny lists and default only to a destructive-command denylist, and individual tools can be marked as requiring human approval.

    Source retrieved 2026-09-02

  • Qualified Qualified

    Acts unattended inside admin-set goals, guardrails and rules-of-engagement; no per-action human approval step is published.

  • Relevance AI Yes

    Per-connection approval modes: Auto Run, Approval Required, or Let Agent Decide, with a Max auto runs cap

    Source retrieved 2026-09-02

  • Replit Agent Yes

    Plan Mode reads the project without touching files, background tasks need an explicit apply, and paid escalations ask first.

    Source retrieved 2026-09-02

  • Retell AI Qualified

    The agent completes calls without asking, but a human can monitor live and seize the call, and guardrails plus PII removal are configurable metered add-ons.

    Source retrieved 2026-09-02

  • Ringly Qualified

    It acts alone inside the skills you switch on, but the riskiest action ships locked down: order cancellation defaults to logging a request, and even in full mode you can cap the order value it may refund.

    Source retrieved 2026-09-09

  • Rox Yes

    Agentflows are scoped to a chosen tool set, agents inherit the acting user's record and field permissions, and sequence sends can be scheduled, previewed or cancelled before they go out.

    Source retrieved 2026-09-03

  • SafeNet Creations Yes

    Permitted and forbidden actions are fixed at design time in the written scope, with confirmation steps documented before implementation rather than tuned by the buyer later.

    Source retrieved 2026-09-04

  • Salesforce Agentforce Qualified

    Guardrails and filters bound which topics and actions an agent may reach and data access honours existing Salesforce permissions, but an approval-before-every-action mode is documented only for the Agentforce Vibes coding agent.

    Source retrieved 2026-09-03

  • SalesTouch Yes

    Per-tool permissions plus an approval gate on sensitive actions, on top of daily limits, working hours and pacing.

    Source retrieved 2026-09-03

  • SEObot Qualified

    Auto-Publish decides whether the agent goes live on its own; disabling it forces every article through human review as a CMS draft. No finer permission model is documented.

    Source retrieved 2026-09-03

  • Sierra Qualified

    Autonomy is configured, not fixed: messaging is fully autonomous by default while you declare which steps need human sign-off, and unresolved cases hand off to your care team.

    Source retrieved 2026-09-03

  • Sim Yes

    A Human in the Loop block pauses a run indefinitely for approval; Enterprise permission groups block disallowed models and block types mid-execution.

    Source retrieved 2026-09-03

  • sipgate flow Qualified

    In-call actions are open, but the powerful ones (outbound dialling, SMS sending, voice-to-voice mode) stay locked until sipgate support reviews the account.

    Source retrieved 2026-09-03

  • SkipCalls Yes

    The owner draws the boundary up front: greeting, hours, services, what to collect, what it must never say. The agent then works inside it without asking mid-call.

    Source retrieved 2026-09-03

  • Spiich Qualified

    Wide latitude with named stop conditions: it will not overwrite a populated CRM field it was not told about, act across a batch, or destroy a file without asking first.

    Source retrieved 2026-09-15

  • StackAI Yes

    Builders choose the stop points: an Ask Human tool pauses a run for approval, while admins allow or block individual tools, connectors and LLMs org-wide.

    Source retrieved 2026-09-09

  • Synthflow Yes

    Flow logic, approved knowledge sources, end-call reasons and handoff triggers bound what an agent may say or do.

    Source retrieved 2026-09-03

  • TecAdRise Qualified

    Boundaries are fixed by TecAdRise when the agent is designed and proved out in supervised pilot runs; the buyer does not get a console in which to widen or narrow them later.

    Source retrieved 2026-09-12

  • TelEcho Yes

    Scope is bounded at setup rather than per action: guardrails, escalation and handoff conditions, business hours and response policies are configured before an agent goes live, and no per-step approval prompt is described.

    Source retrieved 2026-09-16

  • Telnyx Voice AI Agents Qualified

    Scope is set by what you attach: built-in tools, webhook tools, integrations and MCP servers with selected tools. Telnyx documents no approval gate that pauses an action mid-call for a human to confirm.

    Source retrieved 2026-09-09

  • TinyFish Qualified

    Runs unattended, but credentials are scoped per run through a connected password vault and the agent never sees them.

    Source retrieved 2026-09-03

  • UiPath Agent Builder Yes

    The agent can act only through tools you explicitly grant it, per-tool guardrails evaluate deterministic rules before and after each call with Log, Filter, Block or Escalate actions, and a max-iterations setting caps its reasoning loops.

    Source retrieved 2026-09-03

  • Undermind Qualified

    Scope is agreed up front through follow-up questions rather than by approving individual actions; no per-action permission model is published.

  • Unify Qualified

    Reps can view but not edit Plays or exclusion settings; only Admins configure what the agent may act on.

    Source retrieved 2026-09-03

  • Vapi Qualified

    Tools fire mid-call without human approval; a per-tool rejection plan is the mechanism that withholds an action.

    Source retrieved 2026-09-03

  • Vecbase Yes

    Each agent is limited to the tools, file spaces and connections you grant it, and sensitive actions can be held for human approval.

    Source retrieved 2026-09-03

  • Vellum Yes

    Four risk-tolerance tiers (Strict, Default, Relaxed, Full access) with per-context thresholds, glob trust rules and gateway-side deterministic classification.

    Source retrieved 2026-09-03

  • VoiceAgents Qualified

    Behaviour is bounded by per-agent call settings: greeting, interruption threshold, silence timeout, end-call phrases, transfer number, a hard max call duration and a recording toggle. There is no per-action approval gate.

    Source retrieved 2026-09-03

  • Warmly Qualified

    Agents act on their own; humans get visibility and an override on each decision rather than an approval gate.

    Source retrieved 2026-09-03

  • Warp Yes

    Four autonomy levels per action type, plus regex allowlist and denylist; the denylist wins, except that Run until completion bypasses your personal denylist while admin-enforced rules still hold.

    Source retrieved 2026-09-03

  • Webhound Qualified

    Control is a dollar budget plus plain-language checkpoints and mid-run steering; there is no per-tool permission model.

    Source retrieved 2026-09-03

  • Zed Yes

    Per-tool allow/deny/confirm rules with Rust regex patterns, un-overridable built-in rm -rf rules, plus an OS-level sandbox for the terminal and fetch tools.

    Source retrieved 2026-09-03

  • Zencoder Yes

    Every saved preset carries a permission mode, MCP tool calls prompt per invocation unless marked always-allow, and committing or pushing is a separate opt-in setting.

    Source retrieved 2026-09-09

  • Zendesk AI agents Yes

    Admins set policies and guardrails, review the decision path, and every interaction is scored by built-in QA; Enterprise adds approval workflows.

    Source retrieved 2026-09-03

  • zot Yes

    Free-running by default, with three brakes: --no-yolo confirms every call in the TUI, /jail confines tools to the working directory, and a zotfile manifest caps file and bash access.

    Source retrieved 2026-09-03

The population

126 listings in this index are Published. This is the population as of 2026-09-16. 126 of the 126 published listings in this index carry a settled answer for “Agent permissions”. That row asks: What can it do without asking? Every listing in the index is settled on this row, so nothing is left out.

Findings

  1. 64 of the 126 settled listings answer “Yes” for “Agent permissions”. That is 51% of the settled set.

  2. 61 of the 126 settled listings answer “Qualified” for “Agent permissions”. That is 48% of the settled set.

  3. 1 of the 126 settled listings answer “No” for “Agent permissions”. That is 1% of the settled set.

1 of those yes answers is Maven AGI, which still answers yes for “Agent permissions”. Its listing carries the stored answer and links to the source recorded for it. This is one worked example, not an independent audit of every source in the census.

What we counted, and how

Each figure above is a count over the “Agent permissions” row of the listing datasheet, taken from the same stored answer the listing page renders. The denominator is the 126 listings whose answer is settled, meaning one of yes, qualified, no, does not apply, not established. On this row that is the whole index, because every listing has a recognised stored answer. Every number here is stored with the read-only query that reproduces it and re-run every sixty seconds against the live corpus, so a figure that stops reproducing surfaces as drift rather than as a stale sentence nobody notices. Our full method covers how a datasheet row is settled in the first place.

Limitations

This counts stored datasheet answers, not independently tested capabilities. A sourced answer can record a vendor statement or our reading of published evidence; this census does not re-fetch those sources. “Not established” means we have not established an answer. That can reflect vendor nondisclosure, blocked evidence, or unfinished research, not a no. An absent or unrecognised answer is excluded rather than treated as a researched finding. The figures are restated when the stored corpus changes; the date above is the count used for this published version, not a new verification of the vendors.

Get the next report

New agents rankings and fresh data reports. One short email, one-click unsubscribe.