One text box carries different kinds of authority.
"What are you doing?" asks for a report. "Use the smaller parser" changes the plan. "Approve this command" grants narrow authority. "Stop now" ends the run. They may look identical in a transcript, but a runner should not apply them the same way.
Codex 0.158 fixes one concrete version of this mistake. Its release notes say an approval review now retries when new user input arrives, so a status question does not cancel the pending action. The same release enables terminal-input approval by default for commands that run with elevated permissions.[1]
Conversation is the transport. It is not the control model.
A progress report is not a completion receipt.
Anthropic's Opus 5.5 prompting guide documents a related boundary. A long task can emit a text-only progress update with an end-of-turn reason. An unattended loop that equates that event with task completion can stop while checklist items remain open. Anthropic recommends checking explicit task state, limiting automatic continuations, and keeping confirmation for risky or irreversible actions.[2]
The same guide says progress updates may arrive in a distinct thinking-block form. A client that renders only ordinary text blocks can look silent. That is a display bug with operational consequences. The user cannot tell whether the agent is working, blocked, or done.
The editor is becoming a traffic controller.
VS Code 1.139 makes session rows expand when a session needs input or approval. It also summarizes progress from hidden chats on the parent row.[3] Zed 1.21 adds a setting that keeps the system awake while agent threads run.[4]
Those features improve visibility and continuity. They do not define what a new message means. The runner still needs a durable task state, a named pending action, and an explicit rule for each input type.
Wire four routes.
- A status query returns a report and preserves the pending action.
- A correction updates the plan, invalidates affected work, and resumes from a named checkpoint.
- An approval answer applies only to the action and environment shown to the operator.
- A stop command cancels active work, records what ended, and leaves recovery instructions.
Do not infer these routes from tone. Give the interface visible controls or parse the message into a typed event that the user can inspect before it changes execution.