Your agents. Your rules.

What an agent can do, what it can’t, and what it costs: decided by you, enforced by the system.

Inside an actionILLUSTRATED
Permission

The action is checked against the agent’s allowed tools, actions, and workspace permissions.

Approval before action

Every job carries a setting: watch only, ask me first, or run on its own. Approval policies define which actions require a decision before execution.

Money and deletion never graduate automatically. Those always ask.

A spend cap that actually stops

Your limit is checked before each paid action, not totalled afterwards. Hit it, and agents pause and tell you. That applies to everything that costs money (text, images, search, browsing, connectors), not just one category.

A runaway bill isn’t something we’d rather avoid; it’s something the system won’t permit.

Your data is your workspace

Each customer’s data lives in its own isolated workspace, enforced at the database level rather than by application code that could be bypassed. Access is scoped by who you are: owners see their company, team members see their own work.

Your data is exportable whenever you want it. Nothing we produce for you is locked in.

Least privilege for every agent

An agent gets access to specific tools and specific actions, not to your whole account. A finance agent might read Stripe but need approval to refund and be unable to send email at all. Permissions are per-agent, not per-account, and they’re enforced outside the AI, so the model does not decide its own authorization.

Everything is recorded

Every action, approval, failure and cost is written to an append-only log. Who asked, what ran, what it used, what happened, what it cost. The record supports investigation. Undo is available only for actions that are reversible and supported by the connected tool.

Illustrative record · sample data

Weekly product post
Content · Recorded run
  1. 1

    Research the topic

    Pulled last week’s release notes and related threads.

    Done
    12s
  2. 2

    Draft the outline

    Three beats, one CTA, held to the house voice.

    Done
    8s
  3. 3

    Write the post

    Full draft, ready for the image and your eye.

    Done
    41s
  4. 4

    Generate the cover image

    First attempt failed. The image tool rejected the size.

    Read the error, retried at 1200×630, and the image came through.
    Caught & undone
    19s
  5. 5

    Hold for approval

    Draft and image queued. Nothing published yet.

    Approved
    n/a
  6. 6

    Publish on schedule

    Posted after approval. Delivery checked.

    Done
    6s
This run4¢

A real run. Note step 4: the first attempt failed, the agent read the error, corrected it, and continued. Nothing hidden.

What we don’t claim

Being straight with you matters more than sounding impressive:

  • We host your workspace, which means we can technically access your data to operate the service. So we won’t tell you it’s “end-to-end encrypted”, because that would be untrue.
  • Agents act through your connected accounts, and a mistaken action can have real consequences. That’s exactly why approval gates exist and why we default to cautious.
  • We use the best available AI models under the hood and route between them. We’re not claiming to have built our own. We built the system, which is the harder part.

If a security page never tells you what it can’t do, it isn’t a security page.