Autonomy levels
An autonomy level says how much a worker does on its own before a person looks at it. Every kind of action of every installed worker has one level.
Who can do this
Section titled “Who can do this”- The administrator sees and raises the levels.
- Members see the level of their runs on the run card, and “Waiting for the owner’s check” when a result is held.
Before you start
Section titled “Before you start”At least one worker is installed. See First worker.
The five levels
Section titled “The five levels”Each level is shown as a colored label on run cards, approval cards and in the panel Autonomy levels.
| Level | Color | What happens |
|---|---|---|
| Runs on its own | green | It runs and is recorded. |
| Tells you after | blue | It runs. Afterwards you get a notice: on the run card (“Told you after: …”) and on the tab Approvals, panel Tells you after. |
| Waits for your check | yellow | The run finishes, but its result is held until you press Accept, or Send back with a note. See Checks. |
| Asks you first | orange | You approve before the action happens. |
| Always asks, with a reason | red | You approve before the action, every time, and your decision needs a reason. A standing approval never covers it. |
The default for each kind of action
Section titled “The default for each kind of action”Each kind of action starts at its default, the floor. You can raise it for one worker. You can never set it below the floor.
| Kind of action (as the panel names it) | Default | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised |
| Renders web pages in its sandbox | Runs on its own | cannot be raised |
| Reads repositories | Runs on its own | cannot be raised |
| Reads test results | Runs on its own | cannot be raised |
| Reads company knowledge | Runs on its own | cannot be raised |
| Reads the workboard | Runs on its own | cannot be raised |
| Hands work to other packages | Runs on its own | Tells you after, Waits for your check, Asks you first, Always asks, with a reason |
| Writes company knowledge | Tells you after | Waits for your check, Asks you first, Always asks, with a reason |
| Changes the workboard | Tells you after | Waits for your check, Asks you first, Always asks, with a reason |
| Comments on and reviews pull requests | Tells you after | Waits for your check |
| Creates and updates issues | Tells you after | Waits for your check |
| Pushes its own branches and opens pull requests | Tells you after | Waits for your check |
| Publishes | Asks you first | Always asks, with a reason |
| Sends messages outside the box | Asks you first | Always asks, with a reason |
| Chains further actions | Asks you first | Always asks, with a reason |
| Spends money (within its limit) | Asks you first | Always asks, with a reason |
| Uses credentials | Always asks, with a reason | cannot be raised |
| Deploys | Always asks, with a reason | cannot be raised |
The panel lists only the kinds of action a worker actually has permission for.
Some things are stronger than any level: spending above the worker’s per-action limit is refused outright, and no worker can ever merge on GitHub.
Raise a level
Section titled “Raise a level”- Open Administration, sub-tab Packages.
- Scroll to the panel Autonomy levels. Each installed package has its own table: What it does, Now, Level, Floor.
- In the row you want to change, open the menu in the column Level and choose the new level. A row that shows “Fixed” cannot be changed.
- Press Save levels under that package.
The box shows “Saved for” the package, with each change. The column Now shows the new level.
A level belongs to the package: every install of the same package gets the same levels.
Go back to the default
Section titled “Go back to the default”Choose the floor (the level in the column Floor) in the same menu and press Save levels.
Let a worker do one action without asking
Section titled “Let a worker do one action without asking”A standing approval moves “Asks you first” to “Runs on its own” for one installed worker and one action, within a monthly limit and until a date.
- Open the tab Approvals, panel Grant a standing approval.
- Choose the Package, the Action (Publish, Send messages outside, Spend money or Chain actions), the Limit per calendar month and Expires on.
- Press Grant.
Over the limit, after the expiry, or after Revoke, the worker asks again. “Uses credentials” and “Deploys” always ask, so they cannot get a standing approval. A grant for them made in an earlier release shows “not used: this action always asks”.
Make a worker do less
Section titled “Make a worker do less”- Raise a level, as above.
- Or remove the permission in Owner policy and press Save policy. This affects workers installed afterwards. For an installed worker, press Change and skip an optional install question, or uninstall and install it again.
What you see afterwards
Section titled “What you see afterwards”- Each run card shows the highest level the run reached, as a colored label.
- At “Tells you after”: “Told you after: …” on the run card, and a line in the panel Tells you after on the tab Approvals. Press Mark all as seen when you have read them.
- At “Waits for your check”: “Waiting for your check” on the run card and on the tab Approvals.
- At “Asks you first” or “Always asks, with a reason”: an approval card with the level label.
- The audit trail of each run records each held result, each check decision, each approval decision and each level change.
Your choices
Section titled “Your choices”| Choice | What it does | When to pick it | Can you undo it? |
|---|---|---|---|
| Tells you after | The worker acts, and you read a notice afterwards. | You trust it, but want to know. | Yes: choose the floor again. |
| Waits for your check | You read every result before others see it. | A new worker, or important results. | Yes. |
| Asks you first (knowledge and workboard writes) | Nothing is written before you approve. | Sensitive documents or boards. | Yes. |
| Always asks, with a reason | Every time, with a reason in the audit trail. | The most sensitive actions. | Yes. |
| Standing approval | One protected action without asking, within a limit. | A repeated action you trust. | Yes: Revoke. |
Raising “Writes files in its own workspace” to “Waits for your check” holds every result of that worker, because every run writes its result file. Raising a repository action to “Waits for your check” also holds every run of that worker.
A check holds the result, not what the worker already did: a pushed branch, a comment, an issue, a knowledge revision or a workboard change stays. To stop such writes before they happen, use “Asks you first” for knowledge and workboard writes, or remove the repository permission.
For “Hands work to other packages”: at “Tells you after” you get a notice each time work is handed over; at “Waits for your check” the result of a task that handed work over waits for your check; at “Asks you first” or “Always asks, with a reason” nothing is handed over before you approve. See Hand-offs between workers.