RiskMandate v1.38.0
Rule RM-R0018 · v1.0.0 · ask me first

Do you want your agent to start other agent sessions on its own?

To finish faster it starts more sessions, or schedules one to carry on later. Each has the same access, and nobody is watching them.

What you get: Every agent running for you is one you said yes to, with a way to stop it.

The capability: Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) (create.schedule.tenant). Undo: undone by the same actor with no loss.

All rules: the index · This page as markdown: start-other-agents.md

01 · The line

Paste this into your agent's instructions, and it should ask you first.

For Claude Code, that is CLAUDE.md in the project or in your home directory; for Claude on the web or the desktop, a project's instructions or your personal preferences. The one line is enough to try it; the paragraph tells the agent why, and what counts.

The one line
Do not start other sessions or background agents that keep running after this one without asking me first; tell me what each will do and how to stop it.
The paragraph
Helpers that finish inside this session are fine. Starting a new session, a routine, or any agent that runs after this one ends needs my yes: tell me what it will do, what it can reach, when it stops, and how I can stop it, then wait.
02 · What that line is

A request to the agent, not a control.

In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.

If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.

setting · a switch the agent's own account can flip

An ask rule in Claude Code's settings on the tool that creates routines and sessions on claude.ai

{
  "permissions": {
    "ask": [
      "RemoteTrigger"
    ]
  }
}
“Ask rules prompt for confirmation whenever Claude Code tries to use the specified tool. (The tools reference: RemoteTrigger creates, updates, runs, and lists Routines on claude.ai, with Permission required: No.)”

code.claude.com/docs/en/permissions · code.claude.com/docs/en/tools-reference · read 8 October 2026

03 · Where your agent already has it

This is a row in 2 published behaviour policies, with what stands in the way today.

Read from each vault's own grant, as published. The barrier is what was found in that deployment, before any rule.

AgentBarrierWhat the behaviour policy says
Claude Code on the websettinga routine or a scheduled trigger resumes this session or spawns another later: it outlives the container
Claude's Gmail connectorsettinga Gmail filter is a standing rule that acts on every future message without the agent present — labelling, archiving, forwarding — which is what this primitive names: "something that outlives the session, on the platform". The tool is on the directory listing (captured 2026-09-16); it is not on Google's reference page for the server (2026-07-21), and the scope that filters need, gmail.settings.basic — "See, edit, create, or change your email settings and filters in Gmail." — is not among the three lines on the consent screen. Whether the tool works under the consented scopes is open; the row records what is listed. Asked in the measured session, Claude said: "the Gmail connector I have access to only exposes labels/messages, not account-level settings like forwarding rules, filters, vacation responder, IMAP/POP config, or signatures" — self-reported, and against the listing.
04 · Before and after

Not run yet. It will be, on our own deployment.

Every rule gets one run without the line and one with it, on a deployment we are entitled to run, dated, stopped before anything irreversible. How these are run.

05 · Did it work for you?

Tell us, and the rule gets better.

Each link opens the contact form with this rule's id and version filled in. It is encrypted in your browser and read by a person. Nothing is sent until you press send.

06 · One row, and the whole agent

A rule is one row. The ABP is every row, for your agent.

If this one made sense, the Agent Behaviour Policy is the same idea for everything your agent can reach: what it can do, what you authorised, the gap, and what stands in the way of each thing.

Versions

  • v1.0.0 · 8 October 2026 · First version, written from the published rows with nothing in the way.