Blog
Human-in-the-Loop: How Tactic Remote's Approval System Keeps Developers in Control
Tactic Remote's approval system intercepts Claude Code's tool calls via hooks, routes them to your iPhone as push notifications, and blocks execution until you explicitly approve or deny each action.
Follow product and engineering updates from this channel.
Browse categoryAI coding agents are powerful, but power without oversight is a liability. Tactic Remote was built around a single conviction: developers should approve every consequential action an AI agent takes in their development environment. Today, we're publishing a detailed look at how the approval system works, what it costs in latency, and where we're taking it next.
Why Approvals Matter
Claude Code can read files, write files, execute shell commands, and interact with external services. Each of these actions carries real consequences. A misunderstood prompt can lead to deleted files, incorrect git operations, or unintended API calls.
Anthropic built Claude Code with a permission system that prompts users for approval at the terminal. But if you're away from your Mac — commuting, in a meeting, or just in another room — those prompts block execution indefinitely. Your agent sits idle, waiting.
Tactic Remote solves this by routing every approval prompt to your iPhone in real time. You review the proposed action, see the full context, and tap to approve or deny. The agent resumes immediately. No context switch to your Mac required.
Architecture: Hooks and Interception
The approval system is built on Claude Code's hook mechanism. When Claude Code is about to execute a tool call — file write, shell command, or any other action that requires permission — the Tactic Remote Mac companion intercepts the event before execution.
Here's the flow:
- Claude Code initiates a tool call. For example, it wants to run
rm -rf node_modules && npm installin your project directory. - The hook fires. Tactic Remote's hook script captures the tool name, arguments, and full context of the proposed action. This happens synchronously — Claude Code is paused, waiting for the hook to return.
- The Mac companion evaluates the action. It checks the action against any configured auto-approve rules. If the action matches a rule (e.g., read-only file operations), it returns approval immediately without involving the iPhone.
- If manual approval is required, a push notification is sent. The notification includes the action type, a summary of what Claude wants to do, and enough context to make an informed decision.
- The iPhone app displays the approval request. You see the full command or file diff, the working directory, and the conversation context that led to this action.
- You approve or deny. Your response travels back to the Mac companion via WebSocket, which returns the result to the hook, which unblocks Claude Code.
The entire chain is synchronous from Claude Code's perspective. It called a hook and received a response. It has no awareness that approval was routed through a phone on a different network.
What You See on Your iPhone
The approval screen is designed for quick, informed decisions. Each request displays:
- Action type — file write, shell command, API call, or other tool invocation.
- Full payload — the exact command to be executed or the exact content to be written. Nothing is summarized or truncated for shell commands. File diffs show the specific lines being changed.
- Working directory — where the action will execute, so you can assess scope.
- Conversation excerpt — the last few exchanges that led Claude to propose this action, giving you the "why" behind the request.
- Session metadata — which tmux session, how long it's been running, and how many actions have already been approved in this session.
You can approve, deny, or deny with a message that gets sent back to Claude Code as feedback.
Performance: How Fast Are Approvals?
We track approval round-trip times across all connection modes. These numbers represent the time from when Claude Code's hook fires to when it receives the approval response and resumes execution.
| Scenario | Median | P95 |
|---|---|---|
| Local network, app in foreground | 85ms + human time | 140ms + human time |
| Local network, app in background (push notification) | 1.2s + human time | 2.8s + human time |
| Cloudflare Tunnel, app in foreground | 280ms + human time | 450ms + human time |
| Cloudflare Tunnel, app in background | 1.8s + human time | 3.5s + human time |
"Human time" is the dominant factor. In practice, most developers respond to approval requests within 3-8 seconds when actively monitoring a session. The system overhead is negligible compared to decision time.
Critically, the approval system adds zero overhead to actions that match auto-approve rules. Those bypass the iPhone entirely and resolve in under 5ms on the Mac.
Auto-Approve Policies
Not every action needs manual review. Reading a file is generally safe. Running a linter is low-risk. Tactic Remote supports configurable auto-approve policies that let you define which actions skip the iPhone and proceed automatically.
Current policy options include:
- Read-only file operations —
cat,read, file listing, and similar non-mutating actions. - Specific command prefixes — for example, auto-approve any command starting with
npm testorcargo check. - Directory scoping — auto-approve all actions within a specific directory (useful for scratch or test directories).
- Tool-type allowlists — approve all actions from a specific tool category.
Policies are configured on the Mac companion and synced to the iPhone app for visibility. You can see which policies are active from the session view and temporarily override them (e.g., switch to "approve everything manually" when working on a production deployment).
Deny with Feedback
When you deny an action, you can optionally include a message. This message is returned to Claude Code as if the user had typed it in the terminal. Claude Code treats it as guidance and adjusts its approach.
For example, if Claude proposes deleting a configuration file and you deny with "Don't delete that file, it contains local overrides that aren't in git," Claude will acknowledge the feedback and find an alternative approach. This creates a genuine feedback loop between the developer and the agent, even when they're not at the same machine.
Reliability Guarantees
The approval system is designed to fail safe:
- If the WebSocket connection drops mid-approval, the hook times out and returns a denial. Claude Code receives a "permission denied" result and stops the action.
- If the iPhone is unreachable (no network, phone powered off), pending approvals queue on the Mac companion for up to 10 minutes. If the phone reconnects within that window, queued approvals are delivered. After the timeout, they're denied automatically.
- If the Mac companion crashes, the hook script detects the missing process and returns denial. Claude Code cannot proceed without explicit approval.
The default behavior is deny-unless-approved. The system requires an affirmative approval to proceed. It is designed to avoid states where a dropped connection or crashed process leads to unreviewed action execution.
What's Next
We're working on several improvements to the approval system:
Granular policy builder. A visual interface on the iPhone app for constructing auto-approve policies without editing configuration files. Drag-and-drop rules with boolean logic: "auto-approve shell commands that match git status OR git diff but NOT git push."
Session-scoped trust escalation. The ability to temporarily elevate trust for a specific session. For example, "auto-approve all file writes in this session for the next 15 minutes" when you're actively supervising a large refactoring task and don't want to approve each file individually.
Approval analytics. A dashboard showing approval patterns over time — which actions you approve most, which you deny most, and suggestions for auto-approve policies based on your history.
Batch approvals. When Claude Code proposes a sequence of related actions (e.g., writing 5 files as part of a single feature), the option to review them as a batch and approve or deny the entire set.
The approval system is the core of what makes Tactic Remote viable for real development work. Autonomous AI agents are useful, but autonomous AI agents with human oversight are trustworthy. That distinction matters, and we intend to keep investing in it.
Try Tactic Remote
Control your coding Agents from your phone
Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.