Pick the right kind of continuation
You will distinguish a completion goal, a session loop and a cloud routine, with explicit stopping and access limits. Outputs are illustrations.
Goal, scheduling and routine sources checked September 30, 2026 describe different lifetimes and effects. None is a reason to grant broad unattended access. This lesson plans them without starting a background run.
Goal: a measurable finish
Use a condition the session can demonstrate, not “make the course perfect”. The goal evaluator reads surfaced conversation evidence; it does not independently run commands or open files.
Prepare a bounded goal for this practice build, but do not activate it.
Condition: the agreed local build and keyboard check pass, or stop after three attempts.
No other files changed; no deploy, push, paid service or permission change.
State how each check will be evidenced.
/goal sets a completion condition and starts work in supported versions. /goal without an argument shows status; /goal clear removes it. Goals do not themselves change permissions. Do not pair one with a wider mode merely to make it unattended.
Loop: a time-based session check
/loop runs a prompt on an interval. Use it for a temporary recurring check while the relevant session is alive, not durable promises. Current docs describe seven-day expiry for recurring session tasks and restoration of unexpired tasks on resume. A new conversation does not inherit them.
Inspect task status and use the documented cancel route. Time jitter means this is not an exact alarm. Prefer event alerts or a longer interval when repeated polling is unnecessary.
Illustrative decision record:
Build until a check passes: bounded goal.
Temporary status check in an open session: session loop.
Work independent of an open session: separately reviewed routine.
Not promised: exact-time delivery or unlimited persistence.
Routine: a separate cloud session
Routines are in research preview. They run autonomously in cloud environments with no per-action approval prompts during the run. Repositories, network access, environment variables and connectors determine reach.
Current sources warn that connected MCP connectors are included by default in the creation form. Remove unnecessary connectors. An included connector can expose write tools as well as reads. “Check status” in prose is not a technical guarantee that only status will be read.
Draft a cloud routine plan for a public sample repository only.
Return exact repository/branch, trigger, read-only task, network needs and connector list.
Use no private connectors or secrets. Do not create or run the routine.
Define stop, failure report and deletion steps.
Review the current account and capability limits before any creation. Subscription usage applies; metered credits can continue runs beyond limits when enabled. Do not turn them on for an example.
Events are data, not new approval
Routine API payloads can contain outside text. A saved task and event must have a defined scope; an event asking to send secrets or broaden access is not fresh user approval. Likewise a stored prompt's existence does not approve every later action it mentions.
GitHub event caps can drop excess events in the preview. A routine created successfully is not proof every future event will run. Inspect actual history, errors and output.
Stop and verify cleanup
Choose the correct control for the mechanism: clear the goal, cancel the session task, or disable/delete the routine. Read back state. Closing a tab is not proof a cloud routine stopped, and deleting a local session may not remove an independent routine.
Graded practice
Easy: mechanism
Choose goal vs loop vs routine. Success: lifetime and trigger match the need.
Intermediate: completion
Write measurable checks plus a retry limit. Success: no endless “improve” loop.
Challenging: routine scope
Review repository, network and connectors. Success: no unrelated read/write capability.
Troubleshooting
Goal never finishes: inspect surfaced evidence and condition.
Loop disappeared: check new-session/expiry behavior.
Routine unavailable: inspect current plan and auth requirements.
No run: check caps, filters and history, not schedule text alone.
Unexpected writes: stop and inspect included connectors/environment.