The logs read themselves, the root cause surfaces itself, the fix proposes itself - but only with approval. Vercel Agent keeps its own identity, defaults to read-only, and every further action runs through a tightly scoped plan.
- Vercel Agent reads logs on its own, finds the root cause and proposes fixes (rollback, config, cache, code review).
- It runs under its own identity, read-only by default; every action requires access scoped exactly to an approved plan.
- Generated code runs in an isolated, single-use Firecracker microVM.
An agent that touches production - that's exactly what makes my hair stand up. Vercel clearly feels the same, and built the whole product around that worry.
Look at what this is NOT. It's not an agent running around your server with your admin key. It doesn't inherit your permissions. It lives under its own identity - it sees, but it doesn't touch. If it needs to touch something, it asks for exactly as much power as that task needs. That much. No more.
I'll say it plainly - this is the same logic we build by. Every agent: its own identity, least privilege, a human gate before action, an isolated environment. It's satisfying to see a big platform arrive at the same conclusion - and turn it into a product, instead of a footnote.
There's a catch too, honestly. Read-only by default protects you only until someone starts handing out approvals on autopilot. The gate only works if the human behind it is still paying attention. The tool gives you the frame - the discipline is still ours.
If you're putting an agent anywhere near something live, start from zero permissions and add them one at a time, against a specific plan. Simply because that's the only way you don't end up regretting it one day.