Skip to content

Control what agents can delete

All plans Owner or Admin

AI agents can read and update your projects: connected agents (Claude Code, Cursor, ChatGPT and other MCP clients), the in-app assistant, and the Onplana agent. The Governed operations group, at the top of Agent Policies, lets an Owner or Admin decide which high-impact operations those agents may run.

Until your organization saves a choice, the recoverable deletes (task, project, list and document) are on. Each one moves the item to the recycle bin, where a manager can restore it. Turn off anything you do not want agents to do, then save, and your choice sticks.

  • On until you choose. An organization that has never saved this policy gets the recoverable deletes. Once you save, the saved list is the whole answer, including a list with everything turned off.
  • One operation at a time. Each operation has its own switch (for example, “Delete a task” on and “Delete a project” off).
  • Still permission-checked. An enabled operation does not bypass permissions. The agent still needs the underlying right (for example, permission to delete a project), and a project-scoped connection still only reaches its own projects.
  • Audited and recoverable. Every agent deletion is recorded in the audit log, and every operation in the group moves items to the recycle bin.
  1. Go to Settings → Agents → Agent Policies and find the Governed operations group pinned at the top. If you have never saved it, a note under the heading says the defaults are in effect.

  2. Find the operation. Each row shows whether it is recoverable (restorable from the recycle bin) and its blast radius (what it affects).

  3. Toggle it off, or on.

  4. Click Save policy. The change takes effect on each agent’s next call, and is recorded in the audit log.

To turn every operation off, toggle all of them off and save. Agents are then told the operation is disabled for your organization, and nothing is deleted.

Today the group covers the recoverable deletions:

  • Delete a task: removes a task and its subtasks. Recoverable from the recycle bin.
  • Delete a project: removes the entire project and all its tasks, sprints, epics, and milestones. Recoverable from the recycle bin. This is the highest-impact operation. Turn it off if you would rather agents never remove a whole project.
  • Delete a list: removes a workspace list (table) and its rows. Recoverable from the recycle bin.
  • Delete a document: removes a workspace document. Recoverable from the recycle bin.

To restrict deletes only in a certain scope rather than turn them off entirely (for example, “no deletes in finance projects”), leave the operation on here and add a rule in the Agent Policies list below the group.

Editing the policy requires the Manage agent destructive-op policy permission, which defaults to Owner and Admin. You can tighten it to Owner-only (or adjust it) in the Permissions matrix. Anyone who can open the tab can view the current policy; only authorized roles can change it.

Does this affect the in-app assistant and “Run with Onplana Agent”? Yes. The policy covers every AI agent, not only connected MCP clients. Undoing an assistant action from the chat is not blocked, because that is a person reversing it.

What happens when an agent tries an operation that is off? The request is denied and the agent is told the operation is disabled for your organization. Nothing is deleted.

Are deletions reversible? Yes. Every operation in the group (delete task, project, list, document) moves items to the recycle bin, where a manager can restore them.

We saved this policy before the defaults changed. Did anything change for us? No. A saved choice is kept exactly as saved. Only organizations that had never saved it get the defaults.

  1. Decide deliberately. The defaults suit most teams because everything is recoverable, but save your own choice so it is written down.
  2. Use contextual rules to scope by project. “No deletes in finance projects” via the Agent Policies rules list below the governed-ops group.
  3. Consider turning off Delete a project. It has the widest blast radius, and few agent workflows need it.
  4. Review the policy periodically. Check what is on against what your agents actually do.
  5. Test with a low-stakes agent first. Before relying on agent deletes, verify with a project-scoped agent on a sandbox project.
  • Agent’s delete request denied. The operation is off. Toggle it on and save.
  • Operation on, agent still can’t delete. The permission check failed: the agent (or the person it acts for) lacks the underlying permission.
  • Saved, but an agent still sees the old policy. The policy is checked on every call, so the agent’s next call uses the new one.
  • Toggle disabled for me. You need the policy permission (Owner and Admin by default).
  • Deleted item not in the recycle bin. Every operation in the group routes through the recycle bin. If an item is missing, report it.
  • Governed operations + Agent Policies rules. Pinned destructive operations plus the contextual rule list. Two sections, one panel.
  • Governed operations + Audit log. Every agent deletion writes to the audit log. See Read audit logs.
  • Governed operations + Recycle bin. Every operation routes through the recycle bin. See Restore from the recycle bin.
  • Governed operations + Agent connections. Per-agent project scoping further limits blast radius. See Connect an external agent.
ToolMapping
Custom RBAC for AIOnplana’s per-operation governed list
Microsoft Copilot data controlsDirect concept
Salesforce Einstein scopingSimilar
ServiceNow AI governanceDirect
Custom firewall for AIOnplana’s app-level enforcement