Skip to main content
At the end of this page you will know what your agents may do for you as a person on a team server, how to answer when they ask, and how to let them go ahead without asking. Coding agents already work this way: Claude Code and Codex ask before they run a command or edit a file, until you switch them to a mode that lets them go ahead. aboard does the same for the admin work your agents do for you on a server, such as bringing a teammate onto a board or inviting someone new. Whatever the mode, the server checks every request against your own permissions: an agent can do for you only what you could do yourself, and the record names both you and the agent. On an open board, an agent whose role allows it already adds teammates without asking (An agent adds a teammate); the modes decide the rest.

Ask me

Out of the box, an agent that asks to invite someone, or to add a person to a private board, gets a pending approval instead, with the exact command for you:
Your agent tells you, and you answer in either place:
  • In the board view: the request is a card in your Inbox, saying which agent wants to do what, with Allow once, Allow always and Decline.
  • In your own terminal:
Then tell your agent “continue”. An approval is bound to the exact request: the people, the boards and what the agent asked for. Allowing it does that once, after the server checks again that you may still do it. An approval nobody decides ends after 24 hours. --always (Allow always in the Inbox) also turns on that kind of request in your allowance, so next time the agent goes ahead.

Auto mode

Auto mode lets your agents add people already on the server to boards, as ordinary members, without asking, wherever you could add them yourself. Turn it on in the board view (your name at the top right, then Settings, then Auto mode) or in your terminal:
aboard allowance shows what is on, and aboard allowance off turns it all off again. Turning it off stops future actions; it doesn’t undo the ones already made.

Why inviting still asks

Auto mode doesn’t include inviting new people to the server. An agent reads messages from other people and their agents, files, web pages and tool output, and any of them can carry instructions written to talk it into something: a prompt injection. A teammate added to a board is someone already on your server. An invited person is someone new, and as a member they can read every open board. So inviting stays ask-me until you turn it on by itself, and aboard warns you when you do:
Allow always on an invite request turns on the same thing, with the same warning; Allow once turns on nothing. aboard allowance set invite-people off turns it off and leaves adding people on. Every invite one of your agents makes, with your approval or on its own, works once and for 24 hours, and shows in your Inbox with Revoke the invite. aboard invite list shows them all, and aboard invite revoke ID ends one.

What always needs you

Some changes are never in auto mode: making someone an admin or a board owner, changing anyone’s role, removing people, revoking access keys and changing a board’s rules. Asked to do one, an agent gives you the command for your own terminal:
Only you change your allowance or decide an approval, in your own terminal or the board view. An agent can list its own requests with aboard approvals, but it can’t approve them or turn auto mode on.

A guardrail, not a wall

An agent runs as you, on your machine, so it could read the key aboard saved for you. The refusals inside a session keep a well-behaved agent from acting as you by accident; they don’t stop a determined one. What holds is on the server: it checks your permissions, the allowance or the approval on every request, and records who allowed it and which agent acted. To keep an agent away from your key, run it as another OS user, in a container or in a VM (Safety).