Trello enters a company from the bottom up
Trello rarely arrives through the IT department. A manager creates a board in a minute, drops a launch plan into it, invites three people, and the board lives its own life. Two years later the company holds dozens of them and nobody keeps the inventory.
An AI plugged into that material becomes useful immediately, because the cards say how the work actually gets done. It becomes dangerous just as fast if it treats a board open to the whole workspace as a team board. That is the only question worth asking before connecting Trello, and it is a question about refusal rather than access.
A card has one board, and one visibility can be read
Trello's permission model is simple, and that simplicity helps. A card lives on a single board. No permission is set on the card itself, so a card's audience is exactly its board's audience. Where an Asana task can answer to several projects at once, a Trello card has a single owner of its permissions.
That audience still has to be read. A board carries a visibility level, and your Kastel draws a conclusion from one of those values only, the one of a strictly private board. Its members can then be enumerated one by one and resolved into people in your organisation, and when they all belong to the same department the card is filed in that department.
Every other value leaves the card waiting for an administrator. A board visible to the workspace, a public board, a board whose visibility is not reported to us, and even a level Trello might introduce after us all produce the same outcome. The rule is written as the list of what is accepted rather than the list of what is refused, because a list of refusals would let through the value we had not anticipated. This is the kind of trade-off our approach to security describes.
Removing a member alters no card
Trello timestamps a card at its last activity. Removing a person from a board does not touch that timestamp on the board's cards, and nothing is reported at card level. Your Kastel therefore recomputes, on a regular cadence, the audience of every card it tracks, from its board's current members, and moves the card into the right department when the result has changed. The copy filed under the old department is withdrawn as the new one is written.
A second point deserves to be said, because it changes what an absence means. The walk over boards and cards either completes or fails outright, with no state in between. An absent card is therefore a card genuinely deleted or archived, never a page the connector failed to read. Without that guarantee, a partial read would conclude that perfectly live cards had gone, and an administrator's decision would rest on a false inventory.
The read scope, card by card
Two filters decide what the connector sees before it reads a single card. It walks only the connected account's open boards, and on each of those, only the visible cards.
Checklists are left out for a substantive reason. They carry the progress of the work, which goes stale within days, whereas a description and its comments carry decisions that stay true for a long time. Your Kastel keeps what stays true.
The questions we get asked about Trello
Five short answers, on the cases that come up when a manager looks closely at their boards.
Is an archived board still read?
No. The connector only walks the open boards of the connected account. Archiving a board therefore takes it out of scope, and its cards are marked as gone at the source on the next reconciliation pass. Their content stays in your Kastel, readable by the same people as before, until an administrator decides to erase it.
What happens to a card moved from one board to another?
Its audience changes with its board. The connector finds it under its new board on the next walk and recomputes its audience from that board's members. A move onto a board visible to the whole workspace therefore puts the card on hold, when it was readable the day before.
What if the connected account loses access to a board?
That board's cards drop out of what the connector can enumerate, and they are handled as deleted cards, which means marked and kept. A revoked access and a deletion look alike from here, and the connector does not pretend to tell them apart.
Do attachments and checklists come in?
No. The connector writes the card's name, its description and the text of its comments. Attachments, checklists, labels and due dates stay in Trello. Moves and assignments are not even requested from Trello, which can return comments alone.
Where does your Trello account token travel?
In the authorisation header of every call, and nowhere else. Trello does accept that token in the address itself, which would make it show up in every log along the way. The connector never does that, and the token appears neither in a copy of your cards, nor in a log, nor in the synchronisation cursor.
What this connector does not do
It does not work inside Trello. No card is created, moved, commented on or archived, because the client it uses exposes reads only. One honest qualification belongs here. The connector does not check the permissions of the token you hand it, so the read-only guarantee comes from how it is built rather than from any verification made on your token.
Many of your boards will not file themselves. A workspace where boards are shared broadly will see most of its cards on hold, and that list is the first honest inventory of your sharing. It is a decision workload we make no attempt to hide.
The audience recomputation runs on its cadence. Between two passes, someone removed from a board can still reach its cards through an AI working for their department, until the next reconciliation moves the card. We write it down rather than let anyone assume the effect is immediate.
A card only brings in what your teams write on it. A card with no description and no comment comes in with its title alone, and a card with no text at all does not come in. A board kept with one-word cards will therefore give an AI nothing to read, however well it is connected.
Start by checking what the free core contains.
Every Kastel connector, Trello included, sits in the free core and never leaves it. The pricing page says what that core installs on your side, what the plans above it cost, and from which point they start being useful.
See pricing