Governance & control

Who can access what. What AI may do. Where a person signs off.

The mechanism, not the adjective: the roles and scope that limit access, the approvals AI passes through, the rules that apply to outreach and the log of who or what did what.

Off.

Nothing switches on by itself.

TAP THE SWITCH

Three promises

Approved. Reviewed. Recorded.

Every capability is approved before it starts, customer messages are reviewed unless an admin decides otherwise, and every action is recorded.

01

Approved.

02

Reviewed.

03

Recorded.

Nothing switches on by itself.

Every capability is requested by your team and approved by a workspace admin before it starts.

The customer-message setting

Customer messages wait for a person — unless an admin decides otherwise.

One setting for each hired capability. What each state does, who can change it and what gets recorded.

The default

Waits for a person

The capability prepares the message as a draft on the record. A team member reads it, edits it if needed, and sends or discards it. Nothing reaches the customer before that.

AI-drafted customer messages

set at hire

Review before sending

An admin decision

Admin decides otherwise

A workspace admin can allow a hired capability to send on its own. Its messages land on the record like any other, so your team can read every one.

AI-drafted customer messages

set at hire by Maria Rodriguez

Sends on its own

Who can change it

A workspace admin, when approving the hire

Team members can request a capability, not switch this

A later change is an admin action

What gets recorded

Every message, sent or drafted, on the record

Who sent or approved it, and when

Admin changes in the audit log

Per capability

Set for each hired capability on its own

One can send while another drafts

After approval

01

Acts only where allowed

A capability works on the records, channels and actions it was approved for — nothing outside that scope.

02

A person reviews

Drafts wait on the record until a team member sends them, unless the admin allowed sending.

03

The record is updated

Messages, tasks and stage changes land on the record; admin actions land in the audit log.

The control model

Six questions. People and AI answer them the same way.

Who is acting, what they can reach, what they can do, under which rules, with whose approval and where it’s recorded.

01

Who

A team member, with a role

A branch or team scope

A hired AI capability

A journey step

02

Can reach

Records in their scope

Documents on those records

Approved knowledge

Named tools

03

Can do

Read, request, classify

Draft for review

Act within scope

04

Under

Consent and opt-outs

Contact windows

Disclosure texts

Separation of duties

05

With

Hire approval

Review before customer messages go out

Publish approval

06

Recorded in

Record activity

Audit log

Runs

Answers on the record

The questions compliance asks, answered from the log.

Who switched it on, what it can do, who approved a message and what changed.

01

Who switched it on?

02

What can it do?

03

Who approved that message?

04

What changed?

A workspace admin.

Every capability is requested and approved before it starts. Nothing switches on by itself.

FAQ

Questions compliance and IT ask.

Can AI see every record in the workspace?

No. It works within the records and channels an admin approved at hire.

Who can add an AI capability?

Anyone on the team can request one; only a workspace admin can approve the hire. Billing starts after approval.

Can AI message a customer without anyone seeing it?

Only if your admin allows that at hire. Draft-for-approval is available for every capability, and every message — sent or drafted — is logged on the record.

What is logged?

Admin and compliance actions — access changes, hires, policy updates, connector changes — in an attributable audit log, and every message AI sends on the record it concerns.

Bring your compliance officer.

We’ll walk through roles, the three approvals, policies and the audit log on a demo workspace.