Evidence record EV-0016
Approval records omit the effects a command goes on to trigger
A preprint reports that coding-agent approval records name the approved command but omit effects its workflow exercises: across 111 approval and trace pairs, unrecorded residual effects fell from 40 with explicit fields to 17 with command semantics and 13 with decision-time metadata.
Preprint · Measurement · Retrieved
Evidence class: Preprint. Unreviewed. Many are by one author or a small team, and some authors have a stake in the result. Most AX research is in this class today. Pattern tags: approval, confirmation.
Effect, as the source reports it
- Residual (unrecorded) effects in approval records. Baseline: Explicit fields only: 40. With the change: With command semantics: 17; with decision-time metadata: 13. Direction: decrease. Size: 40 to 13. Sample: 111 fixed approval-object and trace pairs.
- Residual effects when approvals are bound to predicted effects. Baseline: Unbound: 10. With the change: Bound to source-backed predictions: 3. Direction: decrease. Size: 10 to 3; predictions reached 0.926 macro recall and 0.941 macro precision. Sample: 17 prespecified holdout workflows.
Agent profile
- Note on models: Not a model comparison; approval objects and traces from coding-agent frontends.
- Harness: Three product frontends (not named in the abstract); a Claude Code PreToolUse integration is described.
Conflicts of interest
None declared in the abstract. The full text was not checked for a competing-interest statement.
Source
Agent Approval Laundering: Transitive Effects Beyond the Approved Invocation, arXiv, Jinqian Zhang, Haojun Xia, Shujiang Wu, Jingkun Yue, Xia Zhang, Zhangpei Cheng, Bibo Tu, 23 September 2026, arXiv:2609.28586. Retrieved ; verification: abstract-only.
Every number in this record was checked against the live arXiv abstract page on 2026-10-08. The full text was not re-checked.
Limitations
- Preprint, not peer reviewed.
- The benchmark was built by the authors.
For designers
Approving a command is not approving everything it sets off, such as install hooks or network calls. Show the expected effects when you ask for approval, and record them with the decision.
Related checks
- ACT-01: Effects are stated before the step
- ACT-02: Your system enforces approval
- HANDBACK-04: Approvals are few and show the real action
Cite this record
Cite the original source for any number, and keep the evidence class and model set with the figure. To point at this record, use "AX evidence register, EV-0016" and this page's address, https://agentexperience.tech/evidence/ev-0016/. The record is also in /evidence.json. The register's licence will be confirmed before its source repository is published.
