
What happened
In a trial run, an agent set up .NET, built the core library, ran 34 unit tests and configured CI in about five minutes — then stalled awaiting approval to edit STATE.md under .claude/, just before push.
Why it matters
Because nothing had been pushed, the whole run's code, tests and CI were lost when the environment was discarded, and a second lane stopped in the same place — so the unattended setup produced almost nothing.
What to watch
The fix was not loosening permissions but moving progress notes to docs/routine/STATE-routine.md and committing at every meaningful checkpoint; the rerun passed 37 unit tests and built on GitHub Actions' Windows environment.
WHO IT HITSThis lands on solo developers and small teams running unattended coding agents in the cloud, who need progress written somewhere unprotected and results pushed out early.
Summaries like this, in your inbox every morning.
The setup was deliberately small: six scheduled Claude Code routines in the cloud — one daily monitor, four weekly implementers, and one month-end aggregator. Each was designed to fetch the repository, read its instructions and state files, advance one unit of work, and push to GitHub. The trial run looked like a success story: a Windows app lane handled .NET installation, core library work, 34 unit tests and CI in about five minutes. The stop came at the last line, when the agent tried to record its own progress.
What makes the episode interesting is the detour the author almost took. The first idea was to write to the protected location through Bash redirection instead of the Edit tool — a workaround that was accepted on the first agent. When the same instruction was attempted on the second, Claude Code's safety check refused it, saying the instruction told the agent to bypass protections. The author now argues that refusal was correct: such a rule would not treat STATE.md as a special case, and could become a general habit of looking for a side door around any protection.
The revised design separates configuration from working records, and treats stopping as normal rather than exceptional — commit and push as work reaches each meaningful boundary, so a run that dies partway still leaves something behind. The same day surfaced smaller traps too: outbound network access in the cloud environment was allowlist-only, personal GitHub connections did not cover organization repositories, and re-triggering a routine the same day did nothing because the agent judged the day's work already complete. The open question is how far this pattern generalizes: as agents get more capable, the design work may shift further toward where they stop and what they leave behind, not what they can do.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Google is paying about 100 digital publishers for content used in AI Overviews, AI Mode, and Gemini, with paym…

A Qiita walkthrough trained a five-label car-damage classifier on Gemini Enterprise Agent Platform AutoML usin…

Lauren Tan says she shipped about 2,000 pull requests a month to production on the SpaceX AI Grok Bot team

At its September 29, 2026 DevDay, OpenAI announced more than 20 items, including dots, an agent running on GPT…

A student made granite-code:8b and granite3.2:8b write a TORCS racing AI in 13 parts, checked by Python test s…

Alibaba's Qwen team open-sourced Qwen-Image-2.1 on September 20, 2026 — a 7B model generating 2048×2048 images…
