Your phone is now an AI agent controller
Mobile apps for AI agents (OpenClaw-style controllers, Gemini, Claude, and friends) all converge on the same core design: agents run in the cloud, and your phone becomes the approval surface. The biggest mistake new users make is turning that surface off. Here's why the approval gate matters — interactively.
The Autonomy Dial
Mission control
The four autonomy levels
The agent reads and summarizes only. It can tell you the flight got delayed; it can't rebook anything. Zero blast radius.
The agent drafts actions — an email, a calendar hold, a purchase — and your phone buzzes for a one-tap approve/reject. The sweet spot for most people.
Pre-approved categories run automatically (reply to scheduling emails, spend up to $20). Anything outside the allowlist still gates on you.
No gates. Fast — and the mode where prompt injection, wrong-recipient emails, and duplicate purchases actually happen. Use only for sandboxed, reversible work.
Set it up right: 5-point checklist
- Start at level 2. Watch a week of proposals before granting any auto-approvals — you'll learn what the agent misjudges.
- Scope credentials. Give the agent a payment card with a hard limit and an email alias, never your primary accounts.
- Whitelist, don't blacklist. "Can send email only to these 12 contacts" fails safer than "can email anyone except my boss."
- Keep voice for input, not approval. Voice is great for assigning tasks; approvals should require a deliberate tap so you actually read them.
- Review the audit log weekly. Every serious controller app keeps one. Ten minutes of review catches drift before it compounds.