---
url: https://docs.mochiexec.io/reference/cli/mochi_trust.md
description: Manage which workspaces can run tasks without asking
---

# mochi trust

Manage which workspaces can run tasks without asking

## Synopsis

Workspace trust decides whether the desktop app asks before running a task, and whether agents connected over MCP may run it at all. A workspace starts out unknown until you trust or restrict it. Rules refine that per task: 'allow' runs matching tasks in a workspace you haven't trusted, 'ask' confirms matching tasks in one you have.

Rule patterns are '\[verb ]name-glob', matched against 'name' or 'namespace:name', where '\*' matches anything: 'build *', 'deploy *', '*:prod-*'. Typing a command in a terminal is never blocked by trust.

## Options

| Flag | Type | Description |
|------|------|-------------|
| `-h, --help` |  | help for trust |

## Options inherited from parent commands

| Flag | Type | Description |
|------|------|-------------|
| `-L, --log-level` | `string` | Log verbosity level (debug, info, fatal) (default "info") |
| `--sync` |  | Sync flow cache and workspaces |

## See also

* [mochi](mochi.md) — Run and organize your development tasks
* [mochi trust check](mochi_trust_check.md) — Report whether an executable can run without asking
* [mochi trust list](mochi_trust_list.md) — List every workspace's trust
* [mochi trust reset](mochi_trust_reset.md) — Forget a workspace's trust and rules, so you are asked again
* [mochi trust rule](mochi_trust_rule.md) — Allow or ask for specific tasks within a workspace
* [mochi trust set](mochi_trust_set.md) — Trust or restrict a workspace
