It drafts, you approve
01Everything outbound is a draft until a person approves it. The agent writes the reply, the post, the follow up. It does not decide to send.
HUMAN IN THE LOOP
Method
Anyone can get an agent to work once, in a demo, on clean data. Keeping it correct for a year is the job. These are the rules every system we ship is built under.
Everything outbound is a draft until a person approves it. The agent writes the reply, the post, the follow up. It does not decide to send.
HUMAN IN THE LOOP
Any change to a connected tool needs an explicit yes first, and the request times out if nobody answers. No agent of ours deletes on its own initiative.
EXPLICIT YES / TIMEOUT
Records get archived, never removed. When something goes wrong at three in the morning, you can still see exactly what was there before.
ARCHIVE, NEVER DELETE
Each client, clinic or team only ever sees its own data. That boundary is enforced in the code, not requested politely in a prompt.
ENFORCED IN CODE
New pipelines run in dry mode against your real data first. We read the diff, you read the diff, and only then does anything write.
DRY MODE FIRST
Calculations are audit logged, so a figure that looks wrong can be followed to its inputs. One dashboard we run is guarded by 1,415 tests.
AUDIT LOG / 1,415 TESTS
Anything that runs on a time window gets a reconciliation sweep behind it. Silent gaps, not loud crashes, are how automations actually fail.
RECONCILE, DO NOT ASSUME
Error handling and alerting are part of the first release. A system nobody is watching is not finished, it is just not broken yet.
ALERTS ON DAY ONE
None of this is visible on a demo. All of it is the difference between an agent that impresses you in week one and one you still trust in month twelve.