Skip to content

[Feat] Auto pauses a Session when calls can't be checked - #3337

Merged
daniel-lxs merged 4 commits into
developfrom
feat/auto-pause-when-unavailable
Oct 1, 2026
Merged

daniel-lxs merged 4 commits into
developfrom
feat/auto-pause-when-unavailable

Conversation

@daniel-lxs

@daniel-lxs daniel-lxs commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Related issue

Internal follow-up to #3116; no separate issue is linked.

Why this PR exists

  • A maintainer explicitly invited this PR in the linked issue or discussion
  • I am a maintainer / this is internal Roomote work

What changed

When Auto is on but a call can't be assessed (the judgment model is unconfigured, failing, or timing out), each call used to become a card if the owner was present and a denial if they were away. During an outage that meant a click on every integration call, or unattended work quietly stalling.

Now the first call that can't be assessed pauses Auto for that Session:

  • The call doesn't run. An audit row records it as auto-rejected, with the unavailable assessment.
  • The Session records auto_tool_approvals_suspended_at (a new nullable column, so N-1 safe). From then on its default tools ask the owner with a normal approval card instead of being assessed. If Auto is later turned off for the deployment, they run as they always have.
  • Sessions: a notice goes to the thread the Session runs in, whether that's the web transcript or a chat surface. It's posted as a recorded system reply, so replay can't duplicate it. The notice closes the turn, the model's trailing message is cut off, and any other ask in the same turn is rejected, so no card is left waiting. The user's next message continues the Session with cards.
  • Tasks: the call is rejected with a new paused outcome. The agent is told to stop and not retry, and later task calls in that Session ask the owner. An older worker that doesn't know paused fails closed.

Notice copy (draft): "Automatic approvals aren't available right now, so I paused Auto for this session and stopped before running {tool} from {integration}. Reply when you're ready to continue, and I'll ask you before running tools."

How it was tested

  • Tests pass:
    • Fast bridge (68): pause with the owner present or away, same-turn asks rejected without assessment, a later turn goes to a card without assessment.
    • Task path (22): paused outcome, suspended Session asks, Auto-off runs.
    • Worker relay (13).
    • DB (31): first suspension wins, and other Sessions are unaffected.
  • pnpm lint and pnpm check-types pass.
  • Live on a local stack with Auto on and no usable judgment model:
    • A harmless read in a new Session was not run, the notice appeared in the transcript, and the turn ended with the Session ready.
    • Replying "ok, continue" produced a plain approval card with no assessment. "Allow once" ran the call.

Checklist

  • The PR title follows the repo convention: [Fix], [Feat], [Improve], [Refactor], [Docs], or [Chore] followed by a user-facing description
  • This PR is small and scoped to one change
  • pnpm lint and pnpm check-types pass locally
  • I added tests or included a clear manual validation note above
  • I removed secrets, tokens, private keys, and customer data from code, logs, and screenshots
  • If this change should appear in the changelog, I ran pnpm changeset (not needed: Auto is a nightly-only experiment)

Combined local smoke (2026-09-30)

All six Auto/approval PRs (#3332, #3334, #3335, #3337, #3338, #3339) were merged together locally and run on a local stack. It used a real web session with Auto on, Jev through OpenRouter, and a local MCP server whose tools only log (list_files, delete_file, pay_invoice). The PRs merge cleanly into develop in any order, except #3332 and #3337: both add an export next to each other in packages/types, and whichever lands second needs a trivial rebase. The combined build passes uncached pnpm check-types, pnpm lint, and the approval suites (cloud-agents 131, sdk 23, worker 13, db 32).

# Scenario PR Result
S1 "Delete old-notes.txt": the delete runs with no card #3335, #3338 Pass. delete_file auto-approved (authorization 0.97, highest risk level). A list_files with no arguments now shows a card instead of failing the insert.
S2 "Pay invoice INV-11 for $120": asks, even though requested #3335, #3339 Pass. A card on the first attempt (it used to be auto-rejected as "away" in a new session), and the call never ran.
S3 A subagent calls an Ask first tool #3334 Pass. A card appeared and the call ran after Allow once. The subagent's list_files was assessed by Auto (auto-approved row).
S4 Flagged call while the owner is away #3332, #3339 Pass. Auto-rejected about 19 seconds after the message (presence recheck). The agent said "When you're back, ask again", with no mention of the transcript.
S5 Judgment model unavailable #3337 Pass. Two calls failed together, both were rejected, one notice was posted, and the session was marked paused. After "ok, continue", both got plain cards and ran once allowed.
S6 Auto turned off after a pause #3337 Pass. The next call ran with no card (new turn; the mid-turn path is covered by a unit test).
S7 "Delete draft-1, draft-2 and draft-3": all run #3335 Pass. Three deletes auto-approved (authorization 0.92 to 0.96), no cards.

Not covered live: chat surfaces (Slack, Telegram, Discord) and the task (sandbox) path, because there's no local worker. Both are covered by unit tests.

@roomote-community

roomote-community Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

No new code issues found. See task

  • packages/cloud-agents/src/server/fast-agent/fast-agent-tool-approvals.ts:645 Concurrent unavailable asks can post multiple pause closeouts.
  • packages/cloud-agents/src/server/fast-agent/fast-agent-tool-approvals.ts:595 A suspended Fast session does not honor Auto being turned off during a live turn.

Reviewed 43d26cd

Comment thread packages/cloud-agents/src/server/fast-agent/fast-agent-tool-approvals.ts Outdated
…en-unavailable

# Conflicts:
#	apps/worker/src/sandbox-server/lib/harnesses/opencode-server/tool-approvals.ts
#	packages/cloud-agents/src/server/fast-agent/fast-agent-tool-approvals.ts
#	packages/types/src/integration-tool-approvals.ts
A batch of parallel calls pauses Auto when any of them cannot be checked,
instead of asking about the batch.
@daniel-lxs
daniel-lxs merged commit bccaaf7 into develop Oct 1, 2026
22 checks passed
@daniel-lxs
daniel-lxs deleted the feat/auto-pause-when-unavailable branch October 1, 2026 00:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant