Pushary

One permission policy
for every AI agent.

Decide once which tools run on their own, which are blocked, and which need your tap. The policy follows your agents wherever they run, so you only hear about the actions that need you.

99,9 %Délivré
Hacker NewsMis en avant sur Hacker News
3-4xvs E-mail

The policy makes the easy calls

A good policy decides most things on its own, so the few that reach your phone are the ones actually worth your judgment.

Auto-approve, deny, or ask

Each tool gets one of three answers: let it run, block it outright, or push it to your phone for a decision. You decide which tools fall where.

Approve by exception

Wave through the safe work, hard-block what should never run, and spend your attention only on the consequential middle. No more rubber-stamping every prompt.

Set it once, across every agent

The same policy applies whether the work runs in Claude Code, Codex, Cursor, or Hermes, so you are not keeping five different permission setups in your head.

A timeout you control

Decide what happens when an escalated action goes unanswered: keep waiting, deny by default, or fall back to the agent's own prompt.

Enforced where it can be

On agents with hooks, an action that needs approval is physically blocked until you answer. On plain MCP it is cooperative, meaning the agent chooses when to ask.

Every decision recorded

Each call the policy handles, auto-approved or escalated, is written to the audit trail, so you can see what the rules actually did.

Write the rules once.

Connect an agent and your policy is in force from the first command.

Frequently asked questions

What is an AI agent permission policy?

It is the set of rules that decides, for each action your agent tries to take, whether to let it run, block it, or ask you first. Pushary applies that policy across all of your agents.

What can a rule do?

Each rule maps a tool to one of three actions: auto-approve, deny, or escalate, which pushes the action to your phone for a yes or no. Escalated rules also have a timeout action for when you do not respond.

Is the policy per-tool or per-argument?

Both. A rule can match a whole tool or a specific command. You can let git status run on its own and still make git push ask you first, and the most specific rule wins: an exact command beats a prefix, which beats the bare tool. Proven read-only commands auto-approve by default.

Does one policy really cover every agent?

Yes. Claude Code, Codex, Cursor, and Hermes all read the same policy, so a rule you set once applies everywhere instead of being reconfigured per tool.

Is the policy enforced or just advisory?

Both, depending on the agent. With hooks, in Claude Code, Codex, the Cursor plugin, and Hermes, a gated action is blocked until you approve it. With plain MCP clients it is cooperative, so the agent decides when to ask.

How much does it cost?

Paid agent plans start at $9.99 per month with a 7-day trial, and include the permission policy, phone approvals, and the audit trail.