A developer is building a support agent with the Claude Agent SDK. The agent must pause execution, ask a human operator to approve a refund above $500, and resume the exact same session with the operator's decision injected as a new message. Which SDK capability should the developer configure to accomplish this reliably?
Permission callbacks let the SDK intercept a sensitive tool invocation and hand the decision to your code before execution, while session persistence saves the full conversation and pending state. Resuming the same session with the operator's decision injected as a new message continues the run exactly where it paused, which is the intended approval pattern.
Why this answer
Approval gates require an enforcement point plus durable state. Permission callbacks intercept the sensitive tool call before it executes, and session persistence stores the conversation so the run can be resumed later with the operator's decision appended. Together they suspend and continue the same session deterministically, which prompt instructions, blocking handlers, or retry loops cannot provide.
Exam trap
The trap here is assuming that telling the model to ask for confirmation in the system prompt is equivalent to an enforced human-approval pause.