LLM agency: using a separate agent to monitor for dangerous behavior

https://simonwillison.net/2026/Mar/24/auto-mode-for-claude-code/#atom-everything

“the classifier runs on Claude Sonnet 4.6, even if your main session uses a different model.”

#jgshare

Auto mode for Claude Code

Really interesting new development in Claude Code today as an alternative to --dangerously-skip-permissions: Today, we're introducing auto mode, a new permissions mode in Claude Code where Claude makes permission decisions …

Simon Willison’s Weblog