
Gartner has published new research on the permission model behind agentic coding tools, and Arnica was named in it as a sample vendor.
Independent analysts are now tracking and managing the governance of AI coding agents as a distinct problem, separate from scanning the code those agents produce. That is the problem Arnica set out to solve, and it’s encouraging to see the category recognized by people who talk to hundreds of security and engineering leaders about what affects them every day.
On August 14, 2026, Claude Code began defaulting new sessions to auto mode on Pro, Max, and Team plans. Per-action approval prompts, the checkpoint many developers assumed would catch a risky command before it ran, are no longer the default gate.
Per Anthropic's August 7 announcement, auto mode routes each tool call through a separate classifier that blocks actions it judges irreversible, destructive, or aimed outside your environment. When something is blocked, Claude looks for a safer path or asks the user directly. Repeated blocks fall back to manual approvals.
Developers aren’t being removed from the loop. Task initiation and code review still happen, and merge gates haven’t moved. What has changed, however, is approval at the individual tool-call level, and Anthropic's own published data suggests that control was never doing the work that people assumed.
Anthropic reports that users approve 97% of permission prompts, and that in a controlled study of 1,053 paid testers, human reviewers caught 13.6% of dangerous commands while the classifier caught 89%. It also reports that 62% of users have bypassed permission prompts or clicked "don't ask again" on Bash, and that a quarter of interactive sessions start in bypass mode. Anthropic is direct about the limits, too: the classifier relies on classification systems, does not eliminate risk, and high-stakes production changes should still be reviewed by a person.
Per-action human approval won’t scale with the volume of code agents produce, and auto mode made that gap visible. The answer has to come from a layer that doesn't depend on a developer reading one prompt at a time.
AI agents write code faster than any security team can review by hand. The risk doesn’t stop at the moment of generation; it carries through every tool call an agent makes on its own.
Arnica covers the full lifecycle: enforce agentic rules before code is generated across the enterprise, AI SAST that allows you to bring custom prompts to review code as it’s pushed or reviewed, posture scanning and management across the enterprise at scale, plus an inventory of every MCP, skill, and agentic rule running in the environment, with developer feedback loops and human-driven code reviews that keep the right humans in the right loops. All at the source-control layer, so there is no adoption dependency and no gap in coverage.
AppSec was built for human-written code. ADLC, the Agentic Development Lifecycle, is what comes next, and Arnica is uniquely positioned to do both.
If your teams run Claude Code, Cursor, or Copilot in agentic modes, don’t wait for an incident to find your policy gaps. Talk to Arnica about setting agent permissions, mapping your agentic asset inventory, and putting a governance layer around every AI coding platform your developers already use.
Gartner, First Take: Claude Code Is Defaulting to Automated Permissions — Update Your Governance Controls, Shiva Varma, Mark O'Neill, August 2026.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.
Integrate Arnica ChatOps with your development workflow to eliminate risks before they ever reach production.