Blog · October 6, 2026 · 7 min read

Let a Trusted Colleague Approve an Agent Prompt Without Handing Over Your Mac: Visible While Locked vs Accessible While Locked

The situation comes up more often than it used to. You have a coding agent running on your Mac, you have to leave the desk for twenty minutes, and there is a reasonable chance it will stop and ask "may I run this command?" while you are gone. A colleague at the next desk is happy to glance over and click yes. The question is how to let them do that without handing them your unlocked laptop, your email, your Slack and your shell. This post is about the two trust levels VibeLock offers per app, visible and accessible, and how to use the second one for exactly this case without opening the door wider than you meant to.

The three bad options you have today

Leave it unlocked. The colleague can approve the prompt. So can anyone else who walks past, and they get everything else on the machine too. We wrote about why this is a worse idea than it feels in the unlocked Mac and vibe coding.

Lock the screen and give them your password. Now they have everything, permanently, and you have a password to rotate. On a Mac with Touch ID this is also the moment you discover that Touch ID only works for the enrolled fingers, so the password gets typed in front of whoever is standing behind them.

Lock the screen and hope it does not ask. It asks. The agent sits waiting for twenty minutes, and the work you left it to do is twenty minutes behind when you get back. The leaving Claude Code running while away post covers the screen-stays-on half of this problem; this one is about the approval half.

Visible While Locked: watch-only

VibeLock's default trust level is Visible While Locked. You checkmark the apps that may stay on screen (the common terminals, Claude desktop, ChatGPT/Codex and VS Code are pre-allowed; anything else is a toggle in the menu bar), and when you lock, everything else hides, the keyboard, trackpad and mouse are blocked, and the display stays awake. Visible means watch-only: your colleague can see the agent's output, read the permission prompt, and tell you about it, but keystrokes, clicks and scrolls aimed at the visible app are still blocked.

For a lot of situations that is enough. A screen you can read across the office answers "is it done yet" and "is it stuck" without anyone touching anything. If the colleague's job is just to text you when the prompt appears, stop here; watch-only is the safer setting and the one the docs recommend by default.

Accessible While Locked: let one app be used

The second trust level is Accessible While Locked. An app marked accessible can be used while everything else stays locked: keystrokes reach it when it is frontmost, and clicks and scrolls work on its windows. Marking an app accessible automatically makes it visible; unticking it from Visible removes it from Accessible. The list is empty by default, on purpose.

This is the setting for the approve-the-prompt case. Mark the terminal your agent runs in as accessible, lock, and leave. Your colleague can walk up, read the prompt, type y, and walk away. Every other app is hidden and blocked; Spotlight, Force Quit and ⌘Q are blocked system-wide, so they cannot quit the agent, launch something else, or search their way out of the box. The docs name this use directly: "when a trusted colleague needs to approve an agent prompt at your desk, or to keep one notes/chat app usable in a pair session."

When you are back, unlock with Touch ID or your Mac login password typed into VibeLock's own shield, and everything returns as you left it. Then go into the menu bar and untick the terminal from Accessible again. That last step is the one people forget, and it is the whole point of the next section.

What accessible actually gives away

An accessible terminal is a shell. Be honest with yourself about what that means: anyone at your keyboard can type into it, which includes cat ~/.ssh/id_ed25519, git push --force, and whatever your agent has permission to run. The docs say it plainly: an accessible terminal means anyone at your keyboard has shell access. VibeLock keeps ⌘Q blocked even for accessible apps, so nobody can quit your running agents, and keeps Spotlight and Force Quit blocked system-wide, but it does not and cannot police what is typed into an app you chose to make usable.

So the rules that make this safe are about scope and duration:

  • Make one app accessible, not three. The terminal with the agent. Not VS Code, not the browser, not Slack. If the agent runs inside an editor's integrated terminal, that editor is the one app.
  • Trusted colleague means trusted. The same person you would let use your laptop for a minute, not the whole open-plan floor. The lock protects you from passers-by; the accessible app is a door you opened for one named person.
  • Untick it when you are back. Accessible is a setting, not a session. If you leave the terminal accessible, next week's lock while you fetch coffee is a lock with a shell in it.
  • Prefer watch-only when the prompt is not urgent. If a twenty-minute delay on an approval costs you nothing, keep the terminal merely visible and let the colleague tell you instead.

The pair-session variant

The other case the docs mention is pairing: one person at the keyboard, one beside them, and a shared notes or chat app that both want to type into while everything else on the Mac stays private. Mark that one app accessible, lock, and pair. Your email, your other projects and your terminal history are hidden and blocked; the one window you agreed to share is the one window that works. It is a tidier answer than screen sharing to a second laptop, and it needs no setup on the other person's side.

It also works across Spaces and displays: visible and accessible apps work on all of them, and full-screen windows of blocked apps get covered by an opaque shield if someone swipes to them. If the pairing partner is a child rather than a colleague, the Guided Access for Mac post covers the watch-one-thing version of this for the family.

Setting it up in two minutes

  1. Install VibeLock and click the lock icon once; macOS asks for Accessibility access, which is the only permission it needs. It makes no network calls and has no account.
  2. Menu bar → Visible While Locked: confirm your terminal is ticked (it is pre-allowed if it is one of the common ones).
  3. Menu bar → Accessible While Locked: tick that same terminal, and only that.
  4. Lock from the menu bar. Tell your colleague which window to use and what the prompt will look like.
  5. Back at the desk: touch any key, unlock with Touch ID, and untick the terminal from Accessible.

VibeLock is $10 once for a personal Mac on macOS 13 Ventura or later, a 2 MB native Swift menu bar app, signed and notarized. The two trust levels are the feature that makes it more than a keyboard lock: watch-only for the office, accessible for the one person and the one window you actually meant to share.

Keep reading