Approval before action
Every job carries a setting: watch only, ask me first, or run on its own. Approval policies define which actions require a decision before execution.
Money and deletion never graduate automatically. Those always ask.
What an agent can do, what it can’t, and what it costs: decided by you, enforced by the system.
The action is checked against the agent’s allowed tools, actions, and workspace permissions.
Every job carries a setting: watch only, ask me first, or run on its own. Approval policies define which actions require a decision before execution.
Money and deletion never graduate automatically. Those always ask.
Your limit is checked before each paid action, not totalled afterwards. Hit it, and agents pause and tell you. That applies to everything that costs money (text, images, search, browsing, connectors), not just one category.
A runaway bill isn’t something we’d rather avoid; it’s something the system won’t permit.
Each customer’s data lives in its own isolated workspace, enforced at the database level rather than by application code that could be bypassed. Access is scoped by who you are: owners see their company, team members see their own work.
Your data is exportable whenever you want it. Nothing we produce for you is locked in.
An agent gets access to specific tools and specific actions, not to your whole account. A finance agent might read Stripe but need approval to refund and be unable to send email at all. Permissions are per-agent, not per-account, and they’re enforced outside the AI, so the model does not decide its own authorization.
Every action, approval, failure and cost is written to an append-only log. Who asked, what ran, what it used, what happened, what it cost. The record supports investigation. Undo is available only for actions that are reversible and supported by the connected tool.
Illustrative record · sample data
Pulled last week’s release notes and related threads.
Three beats, one CTA, held to the house voice.
Full draft, ready for the image and your eye.
First attempt failed. The image tool rejected the size.
Draft and image queued. Nothing published yet.
Posted after approval. Delivery checked.
A real run. Note step 4: the first attempt failed, the agent read the error, corrected it, and continued. Nothing hidden.
Being straight with you matters more than sounding impressive:
If a security page never tells you what it can’t do, it isn’t a security page.