PM Agent Trust (G13 — agent trust levels and approval gates)
Controls what AI agents may do on Mission Control boards. Each board carries one of three trust levels (read-only, status-only, full-access) that caps autonomous action, and every agent action falls into an approval tier that either always needs a human yes, can be toggled, or never needs one. Progressive trust promotes repeat-approved actions, and a three-level undo reverses agent changes.
What it is
An in-development trust layer for AI agents working on Mission Control (PM) boards. It controls what AI agents can do on PM boards and how their actions are approved — so you can let agents work alongside you without handing the board over entirely.
Where to find it
Trust settings appear per board. The whole layer is in development, gated behind the pm-agent-trust
unreleased feature, so nothing shows in a normal install until that feature is turned on; once it is
enabled, each board carries its own trust settings.
How it behaves
Each board has one of three trust levels that caps what agents can do autonomously:
- Read-only (default) -- agents can only read board data.
- Status-only -- agents can change statuses and non-terminal fields but not delete or reassign.
- Full-access -- agents can do everything a human board member can.
Every agent action is classified into one of three approval tiers:
- Always approve -- destructive actions (complete-item, delete-item, reassign-item, move-item, create-unassigned, modify-automation, session-lifecycle) require human approval by default. Progressive trust can auto-approve them after 5 consecutive human approvals of the same action type.
- Configurable -- non-terminal actions (status change, date change, subitem create) that board admins can toggle between "require approval" and "auto-approve".
- Never approve -- read-only actions (read, comment, search) never need approval.
A progressive trust mechanism auto-approves both always-tier and configurable-tier actions after 5 consecutive human approvals of the same action type on a board. A single denial resets the counter.
The activity timeline is enriched with agent-vs-human actor markers, role-colored avatar frames, and an actor-type filter. A three-level undo (per-action, per-session batch, per-board rollback) lets you reverse agent changes.
For agents
- Trust boundary enforced server-side only via
resolveEffectiveTrust()-- an agent's effective trust never exceeds its spawning user's board role. - Unknown action types are denied outright (
isKnownPmActionType()gate). - 11 IPC handlers in
src/main/ipc/pm-agent-trust-handlers.ts(includesPM_AGENT_TRUST_OVERVIEWfor cross-board trust counter and ops policy data). - 5 read-side CLI routes under
/pm/agent-trust/(config, check, counters, activity, undo-preview). Trust mutations (approve/deny/undo/set-config) are human-only and have no CLI route. - Data in
pm_board_trust_configandpm_trust_counterstables. - Contract:
pm-agent-trust-contract.md.
Related
The boards agents act on are described in mission-control.md. Which features a given board shows in the first place is decided by pm-feature-profiles.md, and whether a set of features may be enabled together at all is checked by pm-composability.md. The inbox cards that nudge you into switching this area on come from pm-discovery-callouts.md, and the import-and-onboarding flows that can arrive with a preset already applied are in pm-onboarding-features.md.
Last verified 2026-09-23