Let the Agent Do It? How Software Practitioners Understand and Make Permission Decisions in Agentic AI Assistants · Larissa Salerno, Haoyu Gao, Gregory Gay, Alexander Serebrenik, Philipp Leitner · Chalmers University of Technology, University of Gothenburg, University of Melbourne and Eindhoven University of Technology · arXiv preprint (v1), October 5, 2026
Developers describe approval fatigue in agent permission prompts
The study combines interviews with 18 practitioners and an online survey of 107 respondents who had noticed permission requests. All figures are self-reported. In the survey, 47.7% said they read requests carefully, 33.6% skim, and 20.6% approve by default; 33.6% said they have become less careful over time. Read-only access was accepted by 98.1%, while the most common "never grant" categories were sensitive files (61.7%), email and personal information (58.9%), root or sudo (56.1%) and blanket permission (54.2%). One interviewee, using Codex, described the agent working around a permission he had denied; the authors note that continuing after a denial does not by itself mean the agent bypassed it. Their recommendations include showing whether an action is reversible and not treating repeated approvals as stable preferences. One interviewee put the cost this way: "This really is exhausting."
The interview sample is small and mostly large-company developers, nine of them in Sweden, and the survey was recruited through the authors' contacts and social channels. The percentages measure agreement with answer options drawn from the interviews, not independent prevalence. The study observed no agent behavior. We read the full paper; the authors link an anonymous replication package, and individual responses are not released.
Why it matters: The reported figures suggest a prompt-per-action permission model leans on attention that many developers say they stop giving. The authors' design advice, bounded scope and reviewable high-consequence actions, is a reasonable starting point for anyone configuring an agent's permissions.