Help Center

Project Agent: project-scoped AI help and guarded fixes

Each project has its own AI assistant that reads live LaunchLayer evidence, stays scoped to the authenticated user's project, and routes changes through guarded approval paths instead of silent AI writes.

Complete LaunchLayer guide

Project Agent: project-scoped AI help and guarded fixes

Production

Each project has its own AI assistant that reads live LaunchLayer evidence, stays scoped to the authenticated user's project, and routes changes through guarded approval paths instead of silent AI writes.

Project isolation

The Project Agent conversation is created for one project and every user message carries that project ID plus a short-lived server-issued scope token as authoritative context. The token is bound to the authenticated user and exact project, and server-side access checks verify both before agent context or proposal data is returned. A different project ID or token typed into chat does not override the authoritative scope.

What it can answer

The agent can explain LaunchLayer, inspect the current project's safe project metadata, recent source inspection, build, deployment, QA, compliance, rejection, store-connection, native-feature, artifact, and release-autopilot evidence, then give project-specific next steps. It is instructed to distinguish verified project facts from suggestions.

Safe project updates

When a user explicitly asks for a local setting change, the agent can prepare a reviewable proposal only for project name, app name, app version, build number, GitHub branch, or target platforms. The proposal shows exact current and proposed values, expires automatically, and cannot apply itself. Applying it requires an explicit user approval in the Project Agent panel and a server re-check that the original values have not changed.

Guarded repair

LaunchLayer can also preview and, after explicit approval, execute the existing allowlisted stale local release-state reconciliation. The proposal and state fingerprints are revalidated immediately before execution and the underlying repair path preserves reversible state. Other failure categories remain guidance-only until they have their own bounded verified executor.

What it cannot change

The agent cannot directly change bundle IDs or Android package identity, signing material, provider credentials, store-review decisions, source code, arbitrary native code, binaries, provider-side records, or start paid builds or uploads. Those boundaries are deliberate because a language model should not receive unrestricted production mutation authority.

Usage safeguards

Server-side limits are independent of the UI: up to 40 agent messages per hour and 150 per day per user/project, 80 project-context reads per hour, 12 safe-setting proposals per hour, 6 approved safe-setting applications per day, 10 stale-state repair previews per hour, and 3 stale-state repair executions per day. Limits may be revised as LaunchLayer usage and plan enforcement evolve.

Auditability

Safe setting applications, repair previews/executions, dismissals, and related outcomes are recorded with the authenticated user and project. A retry or new proposal does not silently erase prior action history.

Important limitation

Project scoping and server checks substantially reduce cross-project drift, but AI output can still be mistaken. The agent's factual project answers are instructed to consult live evidence, and high-risk or unsupported changes remain blocked rather than being entrusted to model judgment.