Skip to main content

What this helps you do

Predict which actions in Trellis run immediately and which pause for a person, so you can set up permissions and agent access with confidence. Every action a teammate or AI agent takes belongs to one of five classes, and the controls in Settings > Team & Permissions and each agent’s Access & Safety follow the same model.

The five classes

A wrong change can be corrected inside Trellis. A wrong delivery has already reached a guest or an external system. That is why reads, drafts, and changes run at full speed while deliveries and spending pause for review.

Where the controls live

1

Roles

Go to Settings > Team & Permissions. Each role is a matrix of resources and actions — View, Create, Edit, Delete, Assign, and Approve. Property access notes: “Restrict which properties this role can see and act on. Empty selection = all properties.”
2

Agent tool access

In an agent’s Access & Safety, every tool is Allowed, Ask first, or Off, with View and Change access set separately per work area.
3

Agent autonomy

Above tool access sits the autonomy mode: Observe only, Ask before acting, Act within limits, or Paused. Even in Act within limits, tools set to Ask first still stop for a person.
4

Deliveries

Drafted guest replies wait as suggested replies for Approve & send. Agent actions set to Ask first stop at a Requires approval prompt showing exactly what would run.

Judge each request on its class

Before an unfamiliar action, ask which class it is. If the answer is deliver or spend, expect an approval — and treat declining as normal operation, not a failure. The prompt shows the exact content and input, so judge each item on its own evidence.

Common problems

Review the tool’s setting in Access & Safety. Tools set to Allowed run without a prompt in Act within limits; move sensitive tools to Ask first.
Their role grants View but not Edit on that resource. Review the role matrix in Settings > Team & Permissions.
Reads, drafts, and changes never require approval. If routine internal edits are prompting, the affected tools or permissions are set more strictly than the action class requires.