Autonomous coding agents run commands and edit files on your machine, but approvals are stuck at the desk. Stepping away means the agent either stalls or runs without review.
Approach
I built a local-first supervision layer: the agent keeps running on the local machine, and each command, file change and permission request goes to a private Telegram chat where one trusted operator approves, steers or denies it.
Result
A public alpha in 17k+ lines of TypeScript with SQLite state, a chat allowlist, stale-approval protection and a documented threat model.
How it works
Step 1 of 6: Agent requests an action
Highlights
Built a human-approval layer for autonomous coding agents: an operator approves, steers or denies each tool action from a private Telegram chat while execution stays on the local machine.
Directed AI coding agents to produce 17k+ lines of TypeScript with SQLite state, a chat allowlist, stale-approval protection and a documented threat model.
How it works
Connects to the coding agent's app server and streams turn and tool-call events to the operator.
Routes command, file-change and permission requests to Telegram with the project, thread and action shown.
Accepts replies only from allowlisted chat IDs and rejects expired or superseded approvals.
Records agent events and approvals in a local SQLite journal.
Safety decisions
Execution never leaves the local machine. Telegram is the control surface, not a remote runner.
Uploaded files are treated as untrusted context, and the threat model covers prompt injection and stale-approval replay.
Model and reasoning-effort changes apply to the next turn, never in the middle of an action.
Status
Public alpha for one machine and one trusted operator. The web console and hosted relay in the repository are experimental.