---
title: PM Agent Trust (G13 — agent trust levels and approval gates)
---

# PM Agent Trust (G13 — agent trust levels and approval gates)

## What it is

An in-development trust layer for AI agents working on Mission Control (PM) boards. It controls what
AI agents can do on PM boards and how their actions are approved — so you can let agents work
alongside you without handing the board over entirely.

## Where to find it

Trust settings appear per board. The whole layer is in development, gated behind the `pm-agent-trust`
unreleased feature, so nothing shows in a normal install until that feature is turned on; once it is
enabled, each board carries its own trust settings.

## How it behaves

Each board has one of three **trust levels** that caps what agents can do
autonomously:

- **Read-only** (default) -- agents can only read board data.
- **Status-only** -- agents can change statuses and non-terminal fields
  but not delete or reassign.
- **Full-access** -- agents can do everything a human board member can.

Every agent action is classified into one of three **approval tiers**:

- **Always approve** -- destructive actions (complete-item, delete-item,
  reassign-item, move-item, create-unassigned, modify-automation,
  session-lifecycle) require human approval by default. Progressive trust can
  auto-approve them after 5 consecutive human approvals of the same action type.
- **Configurable** -- non-terminal actions (status change, date change, subitem
  create) that board admins can toggle between "require approval" and
  "auto-approve".
- **Never approve** -- read-only actions (read, comment, search) never need
  approval.

A **progressive trust** mechanism auto-approves both always-tier and
configurable-tier actions after 5 consecutive human approvals of the same action
type on a board. A single denial resets the counter.

The **activity timeline** is enriched with agent-vs-human actor markers,
role-colored avatar frames, and an actor-type filter. A three-level undo
(per-action, per-session batch, per-board rollback) lets you reverse agent
changes.

## For agents

- Trust boundary enforced server-side only via `resolveEffectiveTrust()` -- an
  agent's effective trust never exceeds its spawning user's board role.
- Unknown action types are denied outright (`isKnownPmActionType()` gate).
- 11 IPC handlers in `src/main/ipc/pm-agent-trust-handlers.ts` (includes
  `PM_AGENT_TRUST_OVERVIEW` for cross-board trust counter and ops policy data).
- 5 read-side CLI routes under `/pm/agent-trust/` (config, check, counters,
  activity, undo-preview). Trust mutations (approve/deny/undo/set-config) are
  human-only and have no CLI route.
- Data in `pm_board_trust_config` and `pm_trust_counters` tables.
- Contract: `pm-agent-trust-contract.md`.

## Related

The boards agents act on are described in [mission-control.md](mission-control.md). Which features a
given board shows in the first place is decided by [pm-feature-profiles.md](pm-feature-profiles.md),
and whether a set of features may be enabled together at all is checked by
[pm-composability.md](pm-composability.md). The inbox cards that nudge you into switching this area
on come from [pm-discovery-callouts.md](pm-discovery-callouts.md), and the import-and-onboarding
flows that can arrive with a preset already applied are in
[pm-onboarding-features.md](pm-onboarding-features.md).
