Control
Real control, that can’t be used to break anything.
Every worker lives under two layers of rules. One layer is yours to change whenever you like. The other you cannot change, and neither can we on a whim, because those are the ones that make it safe to leave running.
Locked — nobody edits these
Not you, not us, not the worker itself. These aren’t settings switched off by default — in most cases the ability was never built, which is a different and much stronger thing.
It cannot move money.
No worker has ever been given a tool that touches a payment. Not restricted — absent.
It cannot contact someone who isn't on your list.
A stranger's message can't reach a worker and turn into an action. Untrusted input is refused outright, never handed to you as a question to approve.
It cannot delete your records.
The storage layer has no delete. Writes add; they don't replace. A change keeps the old value beside the new one.
It cannot overwrite your own edit.
If you touched a row after the worker read it, the write is abandoned and reported to you rather than forced through.
It cannot make up a number.
Figures are calculated in code and handed to the worker. A number that wasn't calculated is refused — the model's job is the wording, never the truth.
It cannot spend past its ceiling.
Every worker runs under a hard cap. One business's workers cannot eat another's, and yours cannot run away with your month.
Yours — change any time
In plain sentences, not settings-speak. You will never be asked to edit a prompt, and you will never need to know what one is.
- How often it runs — and it tells you what each choice costs.
- The tone it writes in.
- How long someone goes quiet before it counts.
- Quiet hours.
- What it should bring to you instead of handling.
You’re the one who sets policy, not the one clicking approve
Plenty of AI tools ask you to approve every single action. That sounds safe and it is actually the trap: it makes you the filter, which is more work than doing the job yourself. That is why those tools end up in the graveyard.
Here you authorise a kindof action once, with a cap on it, and the worker gets on with it. The things that genuinely can’t be undone still stop and wait for you.
And nothing retunes itself quietly. If a setting should change, it arrives as a suggestion with its reason attached, and it isn’t applied until you say so.
When something goes wrong
Workers stop sometimes — an account gets disconnected, a limit is reached, something changes shape underneath them. When that happens you get a sentence that says which one it was and the one thing that fixes it.
There is a difference between your staff is waiting and your staff is broken, and you will never be blamed for the first. Every way a worker can stop has a named way back, on a screen, that you can press yourself.
And a worker can never tell you everything went fine if something didn’t save. An all-clear cannot survive a failure — that is enforced in the code, not left to good intentions.
None of this will cost anything to find out.
The conversation will be free and there’s no account to make. You can read every rule above again before a single worker runs.