Research report · data-report
Agent permissions: a census of 126 listings
64 of 126 listings answer yes for “Agent permissions”. Counted from our own datasheet, with the query that reproduces every figure.
On this page
Agent permissions, across 126 settled listings
Of the 126 Published listings whose datasheet settles “Agent permissions”, the largest group is “Yes” at 64 (51%). Measured 2026-09-16.
Explore the matching agents
Agent permissions · Datasheet criterion agent_permissions · Report counted .
Current listings as of ; this set may differ from the report's original sample. Includes “Yes” and “Qualified” answers only. Read the conditions on qualified answers before treating them as a match. “No”, “Not applicable” and “Not established” answers are excluded.
View 125 current matching records
- 11x Yes
Messages can be gated behind approval workflows, or the worker can run unattended on autopilot.
Source retrieved 2026-09-03
- Ada Yes
Every connected tool starts off and is enabled one at a time, write tools can be gated behind a Playbook, and availability rules limit what content the agent may reach mid-conversation.
Source retrieved 2026-09-09
- AgentBridge Qualified
Two states only: max-permission by default, or --safe to restore each CLI's normal prompts. The vendor states it is not a security boundary.
Source retrieved 2026-09-02
- Agentix Labs Yes
Permissions are scoped per workflow and anything consequential or external stops for a human, with dry-run modes and action receipts around writes.
Source retrieved 2026-09-09
- AgentsKit.js Yes
Tool-level allow, deny and require policies plus per-tool quotas and confirmation-gated tools decide what runs unattended, though every constraint is opt-in code you write.
Source retrieved 2026-09-09
- Agno Qualified
Runs are unattended unless a tool is marked for approval; then the run pauses in your database until an admin resolves it.
Source retrieved 2026-09-02
- Aide Yes
Permissions are enumerated per intent as a Scenario: the team fixes the conditions and the allowed actions, and anything outside escalates instead of firing.
Source retrieved 2026-09-03
- Aider Qualified
It applies edits and git-commits them without asking, while prompting before adding files or running suggested shell commands; those prompts can be switched off wholesale, and shell suggestions disabled entirely.
Source retrieved 2026-09-09
- Aisera Agent Studio Qualified
The brake is a node you place, not a policy the platform enforces: a workflow author drops an Ask Approval step where a human must sign off, and anything without that step runs unattended.
Source retrieved 2026-09-03
- Amplemarket Qualified
The agent may research and draft freely but stops before the send, and the prompts steering it are gated: admins alone edit the per-signal nudge and competitor battlecards, while reps get edit, regenerate or send.
Source retrieved 2026-09-10
- Antigravity CLI Yes
Every sensitive action is an action(target) resource sorted into deny, ask and allow lists with deny winning, and unconfigured commands, MCP tools and out-of-workspace files default to asking.
Source retrieved 2026-09-10
- Artisan Yes
Guardrails are explicit and per campaign: approve before sending, locked tone and CTAs, banned phrases, escalation rules and DNC lists, with full autonomy as the default setting.
Source retrieved 2026-09-10
- AudioCodes Live Hub Qualified
Limits are set at design time: tool allow-lists, valid transfer numbers, Max turns. The vendor warns prompt guardrails are not a security boundary, and there is no runtime human approval step.
Source retrieved 2026-09-03
- Augment Code Yes
allow/deny/webhook/script rules per tool and per shell regex, committed in .augment/settings.json.
Source retrieved 2026-09-02
- AutoGen Qualified
Permission is code you write: an approval callback invoked before each code execution, a UserProxyAgent that blocks for human input, max_turns and termination conditions. Nothing is gated by default.
Source retrieved 2026-09-02
- Auto-Respond Qualified
It acts unattended inside limits you preset - pricing on or off, services it must decline, transfer criteria, custom rules - but there is no per-action approval queue; a human reply in the thread is what stops it.
Source retrieved 2026-09-11
- Bitsclan IT Solutions Qualified
Escalation to a human is named as the boundary and agents write into live systems, but no published control describes what an agent may do before it has to ask.
Source retrieved 2026-09-11
- Bland Qualified
Guard rails bound what an agent may say and can end, transfer or reroute a call; custom rails are Enterprise-only.
Source retrieved 2026-09-11
- Bolt Qualified
Plan Mode keeps it read-only until you approve, and Code view lets you target or exclude files, but there is no per-action approval or permission policy.
Source retrieved 2026-09-11
- Botpress Qualified
A human can approve AI output before it is sent, and an Autonomous Node cannot read or write variables until access is granted; no approval gate exists before a tool call executes.
Source retrieved 2026-09-02
- Botsify Qualified
Access is scoped by explicit authorisation of APIs and documents and can be withdrawn at any time, but no approval prompts, action allowlists or human-confirmation steps are documented before an agent acts.
Source retrieved 2026-09-13
- Browserbase Qualified
Per-session domain allowlisting restricts navigation, but the feature is marked experimental and covers top-frame navigation only.
Source retrieved 2026-09-02
- Cartesia Qualified
Limits are prompt-level guardrails plus per-tool execution settings (timeout, immediate vs async, speak-before-acting); there is no separate policy engine.
Source retrieved 2026-09-02
- Claude Agent SDK Yes
Six permission modes plus allow/deny rules, hooks and a canUseTool callback, evaluated in a documented six-step order.
Source retrieved 2026-09-02
- Claude Code Yes
Starts read-only and asks per action in Manual mode; allow/ask/deny rules, six permission modes, and a bash sandbox set the boundary.
Source retrieved 2026-09-02
- Cline Yes
Approval is per tool call across eight named categories - reading, editing, safe commands, all commands, browser, MCP - each toggled separately, with outside-workspace access gated behind the base toggle.
Source retrieved 2026-09-12
- CodeRabbit Qualified
The agent inherits your Git permissions and branch protections and cannot push around them, and Plan mode adds an approval gate, but there is no per-action policy engine documented.
Source retrieved 2026-09-15
- Codex CLI Yes
OS-enforced sandbox with workspace-only writes, network off by default, and configurable approval policy.
Source retrieved 2026-09-02
- CommentKeyword Qualified
The agent acts inside a configured objective, required fields and handoff rules, and stops for a human when the buyer's conditions trigger; it cannot act outside Instagram DMs.
Source retrieved 2026-09-05
- Crescendo Yes
A named Safe Action Framework splits autonomous actions from ones needing human approval, and published integration tools carry typed inputs, permissions and review before the agent may call them.
Source retrieved 2026-09-12
- Cresta Qualified
Agents act within escalation policies, compliance boundaries and an always-on guardrail library, and supervisors can steer or take over a live call; Cresta publishes no per-action approval or confirmation model.
Source retrieved 2026-09-13
- CrewAI Qualified
Code execution is off by default in the framework and the platform adds human-in-the-loop checkpoints and guardrails, but the governance layer described here is an Enterprise plan feature.
Source retrieved 2026-09-13
- Cursor Yes
Run Modes set how much runs unasked, with a sandbox and a review classifier; permission tokens allow or deny shell, read, write, web fetch and named MCP tools.
Source retrieved 2026-09-02
- Decagon Yes
The agent executes real operations such as refunds and identity verification, and how far it may go before escalating is set by AOP guardrails and guidelines.
Source retrieved 2026-09-14
- Deepgram Voice Agent API Qualified
What the agent may do is bounded by the function definitions you send in Settings, and you choose whether each function executes client-side or against an endpoint you host. No approval or confirmation gate is documented: once a function is defined, the model may call it mid-conversation.
Source retrieved 2026-09-02
- Devin Yes
Graded modes from prompt-before-writing up to full bypass, plus an OS-sandboxed autonomous mode.
Source retrieved 2026-09-02
- Devin Desktop Yes
Deny/Ask/Allow rules per action class, OS-level sandboxing with filesystem and domain filtering, and MCP tool calls prompting by default; Enterprise admins can enforce all of it.
Source retrieved 2026-09-03
- Dify Qualified
Autonomy is bounded by design, not by a permission prompt: a Human Input node pauses a run for review, approval or edits, with a timeout branch.
Source retrieved 2026-09-02
- Dust Qualified
Tools carry stake levels: high-stake ones such as scheduling a wake-up require user confirmation, and the code sandbox only reaches domains an admin allowlisted.
Source retrieved 2026-09-09
- ElevenLabs Agents Yes
Tool use is gated per MCP server and per tool: always ask, fine-grained (auto-approved, requires approval, disabled), or no approval at all.
Source retrieved 2026-09-02
- Elicit Qualified
The agent runs a whole plan unattended once launched; the only documented gates are the clarifying questions it asks up front, an effort slider, and an explicit approval before a new skill is saved.
Source retrieved 2026-09-14
- Factory Yes
Four autonomy levels (Off/Low/Medium/High) gate tool risk, plus allowlists, denylists and an unbypassable blocklist.
Source retrieved 2026-09-02
- Fin Yes
Field-level data access restriction, OAuth-scoped integrations, and escalation instead of answering when it cannot answer safely.
Source retrieved 2026-09-02
- Firecrawl Qualified
Any caller can fence a run per request with strictConstrainToURLs, a maxCredits ceiling defaulting to 2,500, and a low/medium/high effort budget. A server-enforced, non-bypassable organisation policy exists only on Enterprise, and only team admins may set it.
Source retrieved 2026-09-03
- GC AI Yes
Permissions are set per action type rather than per app, so searching an inbox and sending mail are separate grants, and an in-chat card offers Approve, Always approve or Deny before anything leaves.
Source retrieved 2026-09-14
- Gemini Code Assist Yes
Plans and tool calls are approved during execution; VS Code coreTools/excludeTools allow and deny lists reach individual shell commands. JetBrains offers approve or auto-approve only.
Source retrieved 2026-09-02
- Genspark Qualified
Controls exist but the vendor states their limits plainly: the local workspace folder is guidance rather than a boundary, while Claw DMs default to approved contacts and AgentBase advises draft-only sending.
Source retrieved 2026-09-15
- GitHub Copilot Qualified
Read-only actions run unattended; destructive shell commands, file writes and URL access need explicit approval, which you can persist per repository or waive entirely with --allow-all.
Source retrieved 2026-09-02
- Glean Qualified
Write actions require confirmation and are checked before execution; source-system permissions are re-checked on every request, but read work proceeds unattended.
Source retrieved 2026-09-02
- Google Agent Development Kit (ADK) Yes
Autonomy is set per tool by the developer: a tool can be configured to pause and ask a human or a supervising system before it runs, though the vendor labels this confirmation feature experimental.
Source retrieved 2026-09-15
- goose Yes
Four permission modes span full autonomy to chat-only, with per-tool Always allow / Ask before / Never allow rules, switchable mid-session; the default grants shell and file writes without asking.
Source retrieved 2026-09-16
- GPT Researcher Qualified
There are no approval prompts mid-run; you constrain it beforehand through configuration such as domain allow-lists, report source and depth, and its actions stay read-only research.
Source retrieved 2026-09-16
- Gumloop Yes
Per-app presets (always allow, ask each time, ask for writes and deletes, custom), per-tool never-allow, and CEL rules on the actual arguments decide what runs before it asks.
Source retrieved 2026-09-09
- HeyRik Qualified
The agent acts freely inside the flow you draw but can only take actions you explicitly wire up: each tool or custom API must be registered and authorised first, and money and KYC workflows stay out of its reach in the dashboard.
Source retrieved 2026-09-10
- HOL Guard Yes
This is the core of the product: every supported action routes to block, review, warn or allow, with project and team overrides layered in a defined precedence order.
Source retrieved 2026-09-07
- IrisAgent Yes
Permissions are set per intent: guardrails and escalation rules are written as plain-English procedures, and auto-send only happens above a confidence threshold you choose.
Source retrieved 2026-09-03
- jobfinder-ai Yes
Approvals and automation settings sit with the account holder: the first email batch is manual, every form or email can be reviewed, and sending is rate-limited per account.
Source retrieved 2026-09-14
- Juggler Yes
Tool calls pass through approval gates whose width you choose per tool, per read-only set or per server, and strategies decide which tools exist at all in a given turn; nothing destructive runs unasked by default.
Source retrieved 2026-09-17
- Julius AI Qualified
Roles and permissions govern what members may do, and that row is ticked only for Business and Enterprise.
Source retrieved 2026-09-02
- Junie Yes
Deny-by-default for sensitive actions, an "Always allow" persistent allowlist file, and a three-level brave mode dial (Off, Auto, On).
Source retrieved 2026-09-02
- Kilo Code Qualified
Auto-approve exists, but the OS-level sandbox that bounds it is experimental and Linux/macOS only.
Source retrieved 2026-09-02
- LangChain Yes
Three approval modes: Manual asks before every gated action, Auto has a model classify routine ones, YOLO asks nothing.
Source retrieved 2026-09-02
- Langflow Qualified
Default is ungated tool calling; approval is opt-in per tool, and then the run checkpoints and waits for a human Approve or Reject before continuing.
Source retrieved 2026-09-03
- LangGraph Qualified
There are no preset permission tiers: you decide where the agent must stop by placing interrupt() calls, which pause the graph and wait for approval before continuing.
Source retrieved 2026-09-02
- Lead Scorer Qualified
It may discover, enrich, score, draft and queue on its own; spending and sending are fenced. Billable tools estimate first and refuse oversized calls, and no tool can put a campaign into sending.
Source retrieved 2026-09-02
- Leaping AI Qualified
Boundaries are expressed as transfer and escalation rules: the agent hands the call to a person or another system, including over SIP. No approval gates, action allow-lists or per-tool permission model are documented.
Source retrieved 2026-09-09
- Letta Yes
Four modes from strict to unrestricted, plus allow/deny tool patterns and a cross-agent memory guard.
Source retrieved 2026-09-02
- Lindy Yes
Per-integration guardrails offer Always allow, Require approval, or Don't offer, and they cover writes only; approval prompts land in the Slack thread with Approve and Deny buttons.
Source retrieved 2026-09-02
- LiveKit Agents Qualified
No built-in human-approval gate: the model calls whichever tools the developer exposes. Bounding is by construction: MCP toolsets can be filtered by tool name or set to require confirmation on a duplicate call.
Source retrieved 2026-09-02
- LlamaIndex Qualified
Framework exposes human-in-the-loop and state as building blocks the developer wires up; the vendor publishes no policy engine that gates agent actions.
Source retrieved 2026-09-02
- LuMay Yes
Human-in-the-loop gates sit in the orchestration layer, so an agent's reach before it must ask is a configured policy rather than a fixed product behaviour.
Source retrieved 2026-09-09
- Manus Qualified
Authorisation is per task and per connector, with watch-and-interrupt for the browser and confirmation gates on terminal commands and high-credit runs, but not per-action approval for cloud tasks.
Source retrieved 2026-09-02
- Mastra Yes
Tool approval can gate any tool call, per server or by predicate on tool name/arguments; approvals propagate up a subagent delegation chain.
Source retrieved 2026-09-02
- Maven AGI Yes
Permissions are hard constraints fixed before the agent runs. Access, actions and the escalation threshold are set by surface, role and policy, so the model cannot widen its own scope mid-conversation.
Source retrieved 2026-09-03
- Microsoft Agent Framework Yes
Approval is per tool and declarative: LocalShellTool asks for every command and disabling that requires acknowledge_unsafe, ShellPolicy pre-filters commands, and the Copilot backend cannot touch shell, files or URLs without a permission handler.
Source retrieved 2026-09-02
- MindStudio Yes
Checkpoint blocks pause a run for human review and revision before it proceeds, and per-agent and per-user spend limits cap what a run may consume.
Source retrieved 2026-09-02
- Moveworks Yes
Agents act with the user's own OAuth-delegated access, and builders gate actions with the Approvals Engine (sequential, parallel, conditional) and Policy Validators.
Source retrieved 2026-09-02
- Muse Code Yes
Three approval modes, stage-by-stage shell review, per-workspace trust, and an OS sandbox that refuses to run a command when it cannot prove containment.
Source retrieved 2026-09-02
- n8n Yes
Approval is wired per tool: the workflow pauses and a reviewer approves or denies through Chat, Slack, Discord, Telegram, Gmail or Outlook. Tools with no review step execute unattended.
Source retrieved 2026-09-02
- NeverApply Yes
Guardrails are explicit and pre-set by you: Ask pauses on a missing required answer, Send composes and submits, plus a daily cap, skip-list and minimum gap between sends.
Source retrieved 2026-09-05
- OmniDimension Qualified
The agent acts alone inside limits you write in advance: natural-language transfer and hang-up conditions, a hard call-length ceiling and per-campaign calling hours, so escalation is pre-configured rather than requested mid-call.
Source retrieved 2026-09-09
- OpenAI Agents SDK (Python) Yes
Per-tool approval rules pause the run; approvals can be manual interruptions, per-call callbacks, or sticky always-approve decisions, and callable rules fail closed on malformed arguments.
Source retrieved 2026-09-02
- OpenAI Realtime API Yes
Tool surface is constrained per session with allowed_tools and require_approval; an approval request becomes a conversation item your client must answer before the tool runs.
Source retrieved 2026-09-02
- OpenClaw Qualified
Four session permission modes (read-only, guarded, workspace, full) plus exec approvals and tool policy exist, but the shipped default is a single trusted operator with no prompts.
Source retrieved 2026-09-02
- OpenCode Yes
Each action resolves to allow, ask or deny, with per-command and per-path granularity plus guards for external directories and repeated calls.
Source retrieved 2026-09-02
- OpenHands Yes
Three confirmation policies: approve everything, nothing, or only actions an LLM security analyzer rates risky. The same modes are switchable mid-session in the CLI and IDE surfaces.
Source retrieved 2026-09-02
- Perplexity Qualified
API runs are bounded by the connected account's own permissions, an allowed_tools allowlist and a max_steps loop cap; no per-action human approval prompt is documented.
Source retrieved 2026-09-02
- Pickaxe Qualified
Control is up-front rather than interactive: you scope what an agent may do with trigger prompts and by choosing whether an Action runs through your account or the end user's, with no documented approval prompt before it fires.
Source retrieved 2026-09-09
- PolyAI Qualified
Wren plans and waits for approval by default, always asks before writing to the live environment, never receives secret values, and its API discovery requests are GET-only.
Source retrieved 2026-09-02
- Pydantic AI Qualified
You choose the ceiling: shell tools take allow/deny lists and default only to a destructive-command denylist, and individual tools can be marked as requiring human approval.
Source retrieved 2026-09-02
- Qualified Qualified
Acts unattended inside admin-set goals, guardrails and rules-of-engagement; no per-action human approval step is published.
- Relevance AI Yes
Per-connection approval modes: Auto Run, Approval Required, or Let Agent Decide, with a Max auto runs cap
Source retrieved 2026-09-02
- Replit Agent Yes
Plan Mode reads the project without touching files, background tasks need an explicit apply, and paid escalations ask first.
Source retrieved 2026-09-02
- Retell AI Qualified
The agent completes calls without asking, but a human can monitor live and seize the call, and guardrails plus PII removal are configurable metered add-ons.
Source retrieved 2026-09-02
- Ringly Qualified
It acts alone inside the skills you switch on, but the riskiest action ships locked down: order cancellation defaults to logging a request, and even in full mode you can cap the order value it may refund.
Source retrieved 2026-09-09
- Rox Yes
Agentflows are scoped to a chosen tool set, agents inherit the acting user's record and field permissions, and sequence sends can be scheduled, previewed or cancelled before they go out.
Source retrieved 2026-09-03
- SafeNet Creations Yes
Permitted and forbidden actions are fixed at design time in the written scope, with confirmation steps documented before implementation rather than tuned by the buyer later.
Source retrieved 2026-09-04
- Salesforce Agentforce Qualified
Guardrails and filters bound which topics and actions an agent may reach and data access honours existing Salesforce permissions, but an approval-before-every-action mode is documented only for the Agentforce Vibes coding agent.
Source retrieved 2026-09-03
- SalesTouch Yes
Per-tool permissions plus an approval gate on sensitive actions, on top of daily limits, working hours and pacing.
Source retrieved 2026-09-03
- SEObot Qualified
Auto-Publish decides whether the agent goes live on its own; disabling it forces every article through human review as a CMS draft. No finer permission model is documented.
Source retrieved 2026-09-03
- Sierra Qualified
Autonomy is configured, not fixed: messaging is fully autonomous by default while you declare which steps need human sign-off, and unresolved cases hand off to your care team.
Source retrieved 2026-09-03
- Sim Yes
A Human in the Loop block pauses a run indefinitely for approval; Enterprise permission groups block disallowed models and block types mid-execution.
Source retrieved 2026-09-03
- sipgate flow Qualified
In-call actions are open, but the powerful ones (outbound dialling, SMS sending, voice-to-voice mode) stay locked until sipgate support reviews the account.
Source retrieved 2026-09-03
- SkipCalls Yes
The owner draws the boundary up front: greeting, hours, services, what to collect, what it must never say. The agent then works inside it without asking mid-call.
Source retrieved 2026-09-03
- Spiich Qualified
Wide latitude with named stop conditions: it will not overwrite a populated CRM field it was not told about, act across a batch, or destroy a file without asking first.
Source retrieved 2026-09-15
- StackAI Yes
Builders choose the stop points: an Ask Human tool pauses a run for approval, while admins allow or block individual tools, connectors and LLMs org-wide.
Source retrieved 2026-09-09
- Synthflow Yes
Flow logic, approved knowledge sources, end-call reasons and handoff triggers bound what an agent may say or do.
Source retrieved 2026-09-03
- TecAdRise Qualified
Boundaries are fixed by TecAdRise when the agent is designed and proved out in supervised pilot runs; the buyer does not get a console in which to widen or narrow them later.
Source retrieved 2026-09-12
- TelEcho Yes
Scope is bounded at setup rather than per action: guardrails, escalation and handoff conditions, business hours and response policies are configured before an agent goes live, and no per-step approval prompt is described.
Source retrieved 2026-09-16
- Telnyx Voice AI Agents Qualified
Scope is set by what you attach: built-in tools, webhook tools, integrations and MCP servers with selected tools. Telnyx documents no approval gate that pauses an action mid-call for a human to confirm.
Source retrieved 2026-09-09
- TinyFish Qualified
Runs unattended, but credentials are scoped per run through a connected password vault and the agent never sees them.
Source retrieved 2026-09-03
- UiPath Agent Builder Yes
The agent can act only through tools you explicitly grant it, per-tool guardrails evaluate deterministic rules before and after each call with Log, Filter, Block or Escalate actions, and a max-iterations setting caps its reasoning loops.
Source retrieved 2026-09-03
- Undermind Qualified
Scope is agreed up front through follow-up questions rather than by approving individual actions; no per-action permission model is published.
- Unify Qualified
Reps can view but not edit Plays or exclusion settings; only Admins configure what the agent may act on.
Source retrieved 2026-09-03
- Vapi Qualified
Tools fire mid-call without human approval; a per-tool rejection plan is the mechanism that withholds an action.
Source retrieved 2026-09-03
- Vecbase Yes
Each agent is limited to the tools, file spaces and connections you grant it, and sensitive actions can be held for human approval.
Source retrieved 2026-09-03
- Vellum Yes
Four risk-tolerance tiers (Strict, Default, Relaxed, Full access) with per-context thresholds, glob trust rules and gateway-side deterministic classification.
Source retrieved 2026-09-03
- VoiceAgents Qualified
Behaviour is bounded by per-agent call settings: greeting, interruption threshold, silence timeout, end-call phrases, transfer number, a hard max call duration and a recording toggle. There is no per-action approval gate.
Source retrieved 2026-09-03
- Warmly Qualified
Agents act on their own; humans get visibility and an override on each decision rather than an approval gate.
Source retrieved 2026-09-03
- Warp Yes
Four autonomy levels per action type, plus regex allowlist and denylist; the denylist wins, except that Run until completion bypasses your personal denylist while admin-enforced rules still hold.
Source retrieved 2026-09-03
- Webhound Qualified
Control is a dollar budget plus plain-language checkpoints and mid-run steering; there is no per-tool permission model.
Source retrieved 2026-09-03
- Zed Yes
Per-tool allow/deny/confirm rules with Rust regex patterns, un-overridable built-in rm -rf rules, plus an OS-level sandbox for the terminal and fetch tools.
Source retrieved 2026-09-03
- Zencoder Yes
Every saved preset carries a permission mode, MCP tool calls prompt per invocation unless marked always-allow, and committing or pushing is a separate opt-in setting.
Source retrieved 2026-09-09
- Zendesk AI agents Yes
Admins set policies and guardrails, review the decision path, and every interaction is scored by built-in QA; Enterprise adds approval workflows.
Source retrieved 2026-09-03
- zot Yes
Free-running by default, with three brakes: --no-yolo confirms every call in the TUI, /jail confines tools to the working directory, and a zotfile manifest caps file and bash access.
Source retrieved 2026-09-03
The population
126 listings in this index are Published. This is the population as of 2026-09-16. 126 of the 126 published listings in this index carry a settled answer for “Agent permissions”. That row asks: What can it do without asking? Every listing in the index is settled on this row, so nothing is left out.
Findings
-
64 of the 126 settled listings answer “Yes” for “Agent permissions”. That is 51% of the settled set.
-
61 of the 126 settled listings answer “Qualified” for “Agent permissions”. That is 48% of the settled set.
-
1 of the 126 settled listings answer “No” for “Agent permissions”. That is 1% of the settled set.
1 of those yes answers is Maven AGI, which still answers yes for “Agent permissions”. Its listing carries the stored answer and links to the source recorded for it. This is one worked example, not an independent audit of every source in the census.
What we counted, and how
Each figure above is a count over the “Agent permissions” row of the listing datasheet, taken from the same stored answer the listing page renders. The denominator is the 126 listings whose answer is settled, meaning one of yes, qualified, no, does not apply, not established. On this row that is the whole index, because every listing has a recognised stored answer. Every number here is stored with the read-only query that reproduces it and re-run every sixty seconds against the live corpus, so a figure that stops reproducing surfaces as drift rather than as a stale sentence nobody notices. Our full method covers how a datasheet row is settled in the first place.
Limitations
This counts stored datasheet answers, not independently tested capabilities. A sourced answer can record a vendor statement or our reading of published evidence; this census does not re-fetch those sources. “Not established” means we have not established an answer. That can reflect vendor nondisclosure, blocked evidence, or unfinished research, not a no. An absent or unrecognised answer is excluded rather than treated as a researched finding. The figures are restated when the stored corpus changes; the date above is the count used for this published version, not a new verification of the vendors.
Get the next report
New agents rankings and fresh data reports. One short email, one-click unsubscribe.