Undoing what an agent changed in your notes
You asked an agent to tidy a project branch. Now a line you wrote in March says something else, a heading with twelve bullets under it is gone, and three others sit under a parent you did not choose. The reflex is Ctrl+Z, and it reaches none of them, because undo only takes back what you did yourself, in this tab, since it last loaded.
A bullet an agent deleted is in the Trash, and one press puts it back with everything under it. A line an agent rewrote has no undo button, so ask the agent, in the same conversation, to put back the old words it read or was handed, or restore a copy you made with Back up now before it started.
A delete waits in the Trash, whole
Nothing an agent deletes is erased. Its delete is the same one you make in the app: the bullet and everything under it leave your outline and your searches, and wait in the Trash, newest first. Open it from the sidebar, or type trash in the command palette, and press the row: it is back where it was, and the row shows how many more bullets that press brings with it.
The Trash has no timer, and a full free plan does not stop you putting one back: the 1,000-bullet limit refuses new bullets, not restored ones. Twelve bullets the agent deleted side by side, not as one branch, are twelve rows and twelve presses.
An agent on the connector cannot put it back for you. There is no restore tool, so that press is yours. What the agent can do is tell you what went: Pando’s answer to every delete says how many bullets left and gives the first few of their texts.
A rewritten or moved line: no button brings it back
Undo, Ctrl+Z at a desk or Cmd+Z on a Mac, walks back through your own changes in this tab, and nothing an agent wrote is ever on it. If an agent rewrote a line after you changed it, Undo does not take the agent’s change back: it drops your own step and says “That step is gone”.
A move has no undo either. Changes lists a moved bullet as edited and opens it where it is now, and the agent that moved it can move it back in the same conversation, if it read the branch first. Pando’s answer to a move names where the bullet went, not where it was.
Getting the old words back
- Ask the agent, in the same conversation. When it rewrote one bullet’s whole line or note, Pando’s answer carried replaced, the old words whole, so one more call puts them back. With prependText or appendText nothing was lost, since the old line is still inside the new one, and with replace or ifText the old words are in its own call. A batch of edits is answered with ids only, so after a batch the old words are in the conversation only if the agent read the branch first, which Pando tells every agent to do. A new conversation has none of them.
- Restore a copy you made. In Settings, under Backup, Back up now makes a copy of your outline as it is this minute, and Restore a copy puts one back. It replaces the whole outline, so the button asks “Replace the outline?” and needs a second press, and it copies what is there first. For one line, restore the copy, copy the line, then restore the safety copy the restore just made, which puts everything since back. Stop your agents first, because anything written between the two restores leaves the outline and is kept only in the second safety copy.
- Open an older nightly file. If Nightly backup is on, under the same Backup heading, your Google Drive holds a file from a night before the job, with the old line in it. Restore a copy does not read that file, so the line comes out by hand.
- Retype it. Open Changes, keep created and edited, and tap the row to go to the bullet. The row shows the words the bullet has now, never the ones it had, so Changes finds the line and the old words have to come from you.
Back up now keeps one copy per day, counted in UTC, and a second press the same day replaces it. So once the damage is done, do not press it again that day: it would replace the good copy with the damaged outline.
What Changes shows, and what it does not
Changes is in the sidebar, or Alt+Shift+C at a desk: one row per bullet written in the last hour, day or week, with its current text and the time, for your own outline only. It does not say who made a change, so an agent’s rewrite and yours look the same there. While an agent writes, its chip in your top bar pulses, which is the moment to look. A key made with Make a key acts as you, so no chip pulses for its writes.
Next time, less to undo
- Lock what you cannot afford to retype. Open the bullet’s menu and choose Protect it from changes, then open it again, choose How it is protected…, and under Refuses pick Agents only. Every agent is then refused a change or a delete there and anywhere under it, and you still edit it. A lock stops changes, not reading.
- Press Back up now before a big job, not after. It is the one copy you can make that Restore a copy puts back, and copies expire on their own.
- Ask for a count before a delete. The delete tool takes dryRun, which answers how many bullets would go and deletes nothing.
- Keep an agent’s reach small. A connector you approve starts with your whole outline, and you choose read and write, or read only. Any agent can then be held to one branch with one press on its row, and it may write in that branch even if you approved it to read only. Keeping an agent out of the rest of your notes, below, has the steps.
- In ChatGPT, read the confirmation. OpenAI’s docs say “Write actions by default require confirmation,” and Pando marks update and delete as write actions, so by default ChatGPT asks before each one runs.
Where this falls short
No screen in Pando opens an earlier version of a line. Every write is kept in your outline’s log, and a program holding a key to your whole outline can page through it over the REST API, raw, 500 writes at a time, but that is a door for developers, not a history you can browse. For words that matter that much, the lock against agents is the honest answer, because an edit that was refused needs no undo.
Set it up
- Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
- Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.
What it costs
Nothing, for 1,000 bullets, with every feature included, the Trash and Back up now among them, and no payment card.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this