The trust ramp
Every agent sits on one of four rungs, from new to trusted. The rung decides what it may do alone and what it must ask about first. Only the owner can move an agent up.
Where you see it
On the Office, open the ... menu on an agent's row and pick What it may do. A sheet shows its rung, what it may do alone, and who it may contact. This sheet is read-only. To change anything, the owner uses dropdowns on the logbook page.
What happens, step by step
The four rungs:
- New. Proposes everything. The owner approves everything.
- Learning. The owner approves risky calls. Routine work goes through.
- Proven. Acts, then tells the owner after.
- Trusted. Runs on its own. The owner sees it at check-in.
The seven actions, and the rung each needs by default:
| Action | Plain meaning | Needs rung |
|---|---|---|
write-draft | Write a draft for someone to review | New |
ask-stakeholder | Ask the owner a question | New |
fix-own-files | Fix its own files | New |
add-milestone | Add a step to its own plan | Learning |
book-resource | Book a room, buy a thing | Proven |
send-to-person | Send a message to a real person | Proven |
post-publicly | Post something the public can see | Trusted |
There is a default row for each action. The owner can add a row for one agent to raise or lower it.
The allowed people list. A third table lists who each agent may message. Being on the list only means the rung rules apply. Being off the list always needs the owner's yes, at any rung, forever. The only way through is to ask.
Here is how it plays out:
- An agent on rung Learning wants to email a sign-up to confirm a date.
- The table says
send-to-personneeds Proven. Learning is lower. - So it cannot send. It writes a draft and asks the owner instead.
- Months later, the run log shows many good drafts. The owner moves the agent to Proven.
- Now it may send to people on its allowed list without asking.
- It still cannot write to someone who is not on the list. That still takes an ask.
What powers it
| Part | What it does |
|---|---|
settings.rung | One row per agent. Holds the rung word. |
permissions | Which rung each action needs, as a default plus optional per-agent rows. |
allowed_recipients | The people each agent may contact. |
logbook.py rung show, permissions show, recipients show | Read-only doors the agent can use to see its own limits. |
LOGBOOK_AGENT | A marker set during every agent session. When it is set, the change commands refuse. |
Why it works this way
The commands that change a rung, a permission, or the allowed list are refused whenever they run inside an agent's session. It does not matter who asks the agent to do it, or how the request is worded.
Trust is earned on evidence. The owner moves a rung only after reading the agent's run log. The agent cannot promote itself, and cannot talk its way up.
The rules are data, not code. That means the owner can change what an agent may do from a dropdown, with no rebuild. The same rows also shape how the agent's questions are worded. A card can truthfully say "If you say yes, I will do this myself" or "If you say yes, I will draft it for you to send," because it reads the same table.
In the reference install, every agent starts on New. One exception shows how a floor can be raised for one narrow thing. Otto, the routine fixer, is on New, but the owner lets him apply any fix from a fixed list of known repairs without asking. Everything else still goes through a question.
Connected to
- How an agent asks you: what happens when the rung says "ask first."
- The send guard: the check an agent's sends go through.
- Approvals: where the owner says yes or no.
- The logbook page: where the dropdowns live.
- Example agents: the rungs and limits of real agents.