The Plan Didn't Say Push

Aug 25, 2026~3 min read
The Plan Didn't Say Push

I was in plan mode. Gave the model the task, expected it to run a few iterations and stop, so I could look at what it built and decide whether it was any good.

Near the end of the run it created a commit and pushed it. To a feature branch, thankfully.

I checked my settings first. Nothing there allowed commits without my approval. So I asked the model directly why it committed and pushed to my branch.

"I have no idea. It seemed like the appropriate next step."

Earlier, on a personal project, the same tool asked me whether it could install a Chrome extension so it could open the browser and check its own work. I said no.

That is the version that works. It asked. I decided. The commit never got that far.

Here is the part that actually bothers me.

Plan mode is the checkpoint. You read the plan, you approve it, execution starts. That is the whole contract. And the plan I approved said nothing about committing. Nothing about pushing. I read it quickly, but I read it. Those steps were not in there.

So what exactly did I approve?

I went looking afterwards. I'm not the only one, and at least one variant of this is confirmed reproduced by the maintainers.

Was it my fault? Partly. I was chasing velocity. I wanted to ship more, so I stopped reading what the model was producing. I could have hit escape in time. I didn't, because I wasn't looking. I spend my days telling my team to verify what the agent produces, and I did not verify my own.

But that only explains why I missed it. It does not explain why there was nothing to catch it.

We keep arguing about permissions. What the agent is allowed to do, what rules to write down, which flags to set. None of that touches this. Permissions govern capability. They say nothing about scope. Nobody is measuring the gap between the plan you approved and the work that actually happened.

That is the harness I want. Not a blocker. Something that says, at the end of a run: three things happened here that were not in the plan. Files touched outside the stated scope. Operations nobody proposed.

I haven't built this. I'm describing the thing I kept reaching for and not finding.

Without it, this is a slot machine. Enter, enter, enter, and then production is down because the agent rewrote fifteen files instead of the one it was asked about.

Or maybe it's me. Maybe I'm still handing agents a wall of text and hoping for a miracle, when I should be giving them small pieces and reading every one.

I honestly don't know which it is.

Was this helpful?

When an AI Coding Agent Goes Beyond the Approved Plan | Code Nomad