Skip to content
The agents

What is actually running.

An agent here is four things: a brief written in plain sentences, a model that reads it, a short list of tools it is allowed to call, and a log of everything it did. There is no fifth thing, and the parts that make it safe are the third and the fourth.

If a page about AI does not tell you what the software may touch, it is selling you the model. The model is the least interesting part.

Anatomy

Four parts.

Two of them are the safety.

The brief and the model are what people expect. The tool list and the log are what decide whether any of this is a good idea in a business that has to keep working on Monday.

01

The brief

Plain sentences, in a file you are allowed to read.

What the role is for, what it must never do, how your business words things, and the exceptions — the supplier who is always net thirty, the customer who is never chased. When you correct the role, this file is what changes, which is why a correction sticks instead of being forgotten by Thursday.

02

The tools

A short list, and everything not on it is impossible rather than discouraged.

A role that files documents can read a folder, write a file and move a file. It cannot send mail, because sending mail is not on its list. This is a boundary in the software, not an instruction in the prompt — an instruction can be talked out of, a missing tool cannot.

03

The gate

The steps that stop and wait for a person, chosen by you.

Every action a role can take is marked as either its own to make or yours. You move that line per role and per client, and two of the marks cannot be moved at all: nothing spends money and nothing deletes.

04

The log

Written before the action, not after it.

What it was about to do, what it read to decide that, what it did, and what came back. Plain text, timestamped, kept on your side. It is the difference between a system you supervise and a system you hope about.

A log, in the form you get it. Written before the action rather than after it, so a run that stopped halfway still says what it was about to do and why it stopped.

What stops it

Four limits,

built in rather than promised.

A limit written into the prompt is a request. A limit written into what the software can call is a limit. These are the second kind.

It cannot reach what it was not given

Each role gets its own credentials, scoped to the one mailbox, folder or ledger it works on. There is no shared key that opens everything, so a role that misbehaves misbehaves in one room.

It writes in a place you check

Drafts, review folders, staged branches. In the first month everything a role produces lands somewhere a person passes before it leaves the building, and moving that line is a decision you make out loud.

Every change can be undone

Builds are commits, so the site goes back to the last good one in minutes. Files are moved and archived rather than deleted. Nothing a role does is a one-way door.

It stops when it is unsure

A role that cannot find the price, cannot read the PDF or has two of your rules pointing different ways does not pick one. It stops, writes down why, and the item lands on your pile with the reason attached.

Your data

Four questions,

answered without a footnote.

Where does my data live?

On your accounts. Your mailbox, your drive, your database, your ledger. We hold the briefs, the logs and the schedule that runs them — not your customer list.

Is it used to train a model?

No. The models are called through business agreements that exclude training on the content, and no copy of your data is kept anywhere for that purpose.

Where is it processed?

Hosting and storage sit in the EU or Switzerland. Model calls may leave that region; where that is not acceptable for a particular kind of document, that role is not sold to you rather than sold with a footnote.

What happens if we stop?

The logs and the briefs are exported to you, the credentials are revoked, and everything that was running on your own accounts keeps running. There is no export fee and no notice period on the data.

One key per room, and no master

The full privacy statement is on its own page, and it describes what the software does rather than what a template imagines it might.

Where it is weak

Four things it is bad at.

This list is not going to get shorter this year.

Every one of these is a reason somebody should not buy a role, and knowing them is the difference between a system that helps and a system that quietly makes a mess for six weeks.

Judgement about people

Whether a customer who is late is having a bad month or is about to stop paying is not in any document. That call is yours and the roles are built to hand it to you rather than to make it.

Anything that was never written down

A role can only work from what exists — a price list, a rule, an example. The parts of your business that live entirely in your head have to come out of it first, and the two watching weeks exist to find out which parts those are.

Being certain

It will read a scanned invoice wrong. The design assumption is not that it will not, it is that when it does the item stops, says so, and waits — which is why the flagged pile is a feature and not an apology.

Work that is new every time

The roles are for the jobs that repeat. Something that is different in every instance is not cheaper this way, and we will say so rather than sell you a role that spends its life stopping and asking.

Ask for the part of this you do not believe.

The log, the tool list for a role, the brief format, where a particular kind of document would be processed. All of it is showable, and a supplier who will not show you is telling you something.