The idea
Most "AI safety" for agents is a paragraph in a prompt: please don't send anything without asking. A prompt is a suggestion. Plainpaper draws the line in the product instead: the product itself decides, on every request, what an agent may do on its own and what needs your click. How well-behaved the model is feeling today doesn't come into it. You know the agent has to ask first, rather than hoping it will.
The line has two halves. On the board, statuses are earned: a card can't call itself approved until it's actually complete. Off the board, nothing leaves without a decision from you. The rest of this page walks through both.
Statuses that mean something
Every card moves through the same lifecycle: draft → awaiting approval → approved → live → done → archived.
Approved, live, and done are claims that the work was fit to ship, so they're gated. An email with an unfilled image placeholder can't be approved. A creative can't be approved without its mockup staging, and the ad shapes also need a CTA and a destination URL. Drafts always save: the gates only fire when a card tries to claim a shipped status, never while the work is still in progress. When a board says "approved", the card has already passed those checks.
Proposed actions
Before anything leaves Plainpaper (an email send, an ad upload), it becomes a proposed action waiting for your decision. The agent proposes; you approve or reject; only then does the agent execute the action externally, through the platform's own connector, and mark it done on the board. A decision can't be double-approved or replayed; one approval leads to exactly one execution.
Mail 1 on my "Summer sale" board is approved. Propose the Brevo send as an action for my approval, with the audience, the timing, and the exact email, and don't execute anything until I approve it on the board.
The decision drawer
At the moment you decide, Plainpaper shows you the full chain, pulled through the board's connections: the artifact itself, the audience it targets, the insight that informed it. You see the email, who it's going to, and why it exists before you click anything, rather than approving a one-line description of a send.
What's waiting for my approval on the "Summer sale" board in Plainpaper? Walk me through each pending action: what it is, which cards it came from, and what informed it.
What the agent may do on its own
Reversible board work: add cards and phases, move things around, connect things, edit drafts. This is the everyday drafting loop. If the agent had to ask before every card, you'd have a chat bot with extra steps. Anything it does here you can see happen live on the canvas, and undo by editing the board. The worst case of the agent working freely is a messy draft. The worst case of an unguarded send is a sent email, so the two are treated differently.
What always waits for you
Deleting a phase, reordering phases, bulk moves, and anything that spends money or can't be undone. These always need your click.
Enforced on the server, fail-closed. The line isn't a prompt instruction the agent could talk itself out of. It's enforced where the agent can't reach it, and anything not explicitly known to be safe is treated as human-only by default.
Approving from chat
Sometimes you want less clicking: you're in the conversation, the work is low-stakes, and "go ahead" should be enough. You can authorize your agent in chat to self-approve low-risk, reversible actions. It can never self-approve anything that spends money or can't be undone, though, no matter what it was told, by you or by anyone. The server refuses those outright. And every approval, yours or the agent's, records who decided and how.
The paper trail
The board's activity log is a history of what happened, including structural changes like a phase being removed. And because every approval records who decided and how, "who signed this off?" always has an answer on the board. The Review, steer & approve guide shows the whole loop in practice.