Pimp My IDE / garage dispatchBack to dispatches
Persistent agents / authority / 29 SEP 2026

Always-on needs a shift breaker.

A cloud computer that keeps working after you leave is useful. It also turns every connected app, standing rule, and forgotten task into an operating boundary.

The new control

Uptime is not permission

OpenAI describes Dots as always-on agents with their own cloud computers. A Dot can use connected apps, work on several projects, carry context across ChatGPT, Slack, and Teams, and request decisions from the user. OpenAI says the system can connect through an ecosystem of more than 4,000 apps.

The same announcement draws an important line around background work. When a user is not actively working with a Dot, OpenAI says its "proactive research" uses read-only tools. Custom Rules can allow, block, or require approval for other actions. Auto-review checks actions that could affect accounts or share information. Certain sensitive tasks remain with the user.

That is a better model than one global autonomy switch. Observation, preparation, and action need different authority. A task that may read a calendar overnight should not inherit permission to send mail, change a repository, or use a connected laptop.

Put the unattended shift on a lease. Name the identity, reachable systems, approval boundary, expiry time, and stop event before the agent starts.
Interactive makeover / always-on shift breaker

Set the shift. Cut the power.

A normal always-on toggle hides what the agent may do. This control separates authority mode, shift length, and required receipt sections. It writes a plan. It does not grant access or prove that a stop works.

SELECT MODESET LEASEADD BRAKESRUN AND PROVE

Shift controls

The native controls own every displayed state. The key, lease bar, readout, and receipt mirror them.

Authority mode
Unattended shift lease4 hours
1 hour24 hours
Include receipt sections

Shift card

Prepare may collect evidence and write drafts inside the named workspace. It cannot publish, send, merge, or change external state.

2 of 4 sections selectedRuntime proof is still required.
AuthorityDraft only
Lease4 hours
Expiry actionStop and report
Why this is now an IDE problem

The editor is joining the night shift

Zed 1.21 added agent.prevent_idle_sleep. The setting is enabled by default and keeps the system awake while agent threads run. That is a narrow editor feature, not an always-on service. It still marks a practical change. Agent work can now outlast the user's active attention and the machine's normal sleep schedule.

Keeping the machine awake solves continuity. It does not define authority. The shift card above adds the missing questions. Which identity is active? What may be read or written? Which events need approval? When does the lease expire? What output proves that work stopped?

OpenAI's Dots announcement and Zed's release notes describe different products. One supplies persistent cloud work. The other prevents local sleep during an agent turn. They do not prove each other's safety, reliability, or operating behavior.

Read-only still has reach

A read-only task can collect sensitive context. Limit which apps, folders, channels, and identities it can inspect.

Approval needs a deadline

Define what happens when nobody answers. The safe default is to pause, preserve the draft, and report the blocked action.

Test the stop

A policy statement is not a brake. Expire one short lease, revoke one credential, and confirm that no further write succeeds.

Separate incident boundary

Capability raises the cost of a loose shift

Anthropic reported separate tests of GLM-5.3 on exploit-development tasks. Its researchers ran the models against isolated offline targets. Anthropic says GLM-5.3 produced end-to-end exploits in 50 of 410 attempts on ExploitBench. The report also describes human-guided sessions against a sandboxed browser build.

Those results do not test Dots or Zed. They do show why persistent access policy should be designed for the capability available now, not the assistant people remember from last year. More capable models make narrow identities, isolated targets, bounded network access, and hard expiry more valuable.