Autopilot
allowAutopilot is configured on the agent and may be overridden per Workplace member.
For managed agents, Monad resolves the effective value before creating the provider
runtime:
- When Autopilot is on, the adapter adds the provider’s verified unattended-mode arguments where supported. Any approval request that still leaks through is denied.
- When Autopilot is off, Monad delegates provider approvals only if the created session
reports
capabilities.approvalResolution: true. - If the runtime cannot resolve approvals, the settings UI keeps Autopilot locked and explains why. The daemon never guesses support from the provider name or process topology.
A provider with no approval resolution can still run: Monad keeps Autopilot locked for
it and denies any request that leaks through, rather than silently letting the call
proceed. Always read the session’s effective
capabilities.approvalResolution; do not
infer it from this table alone, since an adapter can change driver between releases.
Delegated flow
- The managed-runtime launcher creates the provider driver and reads its effective capabilities.
- The provider emits
approval_requested; Monad records it in the session’s pending approval map and publishesmesh.approval_requested. - The project UI sends the human’s allow or deny decision to the Mesh approval endpoint.
- The daemon calls the active driver’s
approvalResolution.resolvemethod and publishesmesh.approval_resolved.