Human-in-the-loop approval
Critical actions require explicit human sign-off while the gate is on. Every employee starts that way; you decide, per employee, when it may act on its own.
the platform
What you get Who works for you What it connects to How you stay in controlmeet a few
Ad monitorstops the ad that is bleeding, before you open the account Shopify managerfound 340 customers who bought once and never came back Outreach employeewakes the leads that went quiet Email employeereads 142 emails, hands you the 9 that need you The full roster →by domain
Strategy & Intelligence Marketing & Growth Sales & Revenue Operations Customer Operations Commerce & Supply Chain Operations & Delivery Finance & Backoffice People & Organisation Oversight & compliance Data & knowledge All use cases →spotlight
142 mails came in. It handled 128 on its own, put 9 drafts in front of you and passed 5 to a colleague. That was one Tuesday.
One employee · an ordinary day
Open its file →Every digital employee has one job, a name, and a file you can open. You see what it did, what it decided, and the rules it worked inside, all of which you set.
the process
The scan & workflow mapping Role selection & configuration Build & integration Controlled go-live Monitoring & tuningspotlight
Almost everyone starts at “it advises”: it prepares the work and waits for your yes. You move the dial when you trust it, and you can move it back.
Autonomy · on your terms
How control works →From the first scan to the day it runs by itself. We map the workflow, build it inside the tools you already use, and stay on it after go-live.
spotlight
Not pilots, they run every working day on real work, and you can ask them about it.
Worked-out scenarios · a call with a client on request
Read the cases →We are an implementation studio, not a software vendor. We build the employee, connect it to your systems, and keep it running afterwards.
07security & control
A digital employee is only useful if you can trust it on Monday morning. Every implementation runs inside a control layer: scoped permissions, human approval on critical actions for as long as you want it, full audit trails and continuous monitoring.
THE CONTROL LAYER, every action passes these gates before execution
Is this action inside the employee's defined role and data boundaries? If not, it stops here.
Business rules you set, thresholds, exclusions, escalation triggers, are applied automatically.
Critical actions, sending, ordering, paying, publishing, wait for an explicit human decision, for as long as that gate is on. You set it per employee.
The action, its inputs and its outcome are logged. Anomalies alert a human and trigger safe fallbacks.
→governance in detail
Critical actions require explicit human sign-off while the gate is on. Every employee starts that way; you decide, per employee, when it may act on its own.
The employee holds its own scoped credentials, never a person's account, with least-privilege permissions.
Which data may be read, written or never touched is agreed in writing before integration begins.
Every action, input and decision is recorded and reviewable. "What did it do?" always has an exact answer.
Performance and behavior are tracked against agreed metrics, with alerts on anything unexpected.
When the employee is unsure, it stops and hands over to a human, it never improvises past its confidence.
Data minimization, purpose limitation and EU-conscious processing choices are part of the design phase.
You can see, per employee, exactly what it is allowed to do, and change it whenever you want.
No digital employee ever takes open-ended autonomous action. Scope is explicit; everything else is out of bounds.
Payments, orders, publications and outbound messages are always reviewable before they leave the building.
Encrypted connections, scoped tokens, and no credentials stored outside managed secrets.
You log in to your own dashboard: what the employee did, what it returned, and everything that waited on your decision. Live, not once a month. No black box, and you never have to ask us.
What we do not promise: that a language model is never wrong. It can be. What these twelve are for is that it can never act on being wrong unnoticed, the gates, the logs and the stop button exist precisely because the model is fallible.
→common questions
No. Every action is logged, and critical actions require explicit approval before execution as long as you keep that gate on. Switching it off is your call, per employee, and it never changes what gets logged. You can review the full activity trail at any moment, and monitoring alerts a human when anything falls outside expected behavior.
You do. The role, permissions and data boundaries are agreed during design and remain yours to change. Expanding autonomy is always your decision, based on results, never a default.
It stops and escalates. Uncertain cases are routed to a human with full context. That handover behavior is designed and tested before go-live, not improvised in production.
With data minimization by design: the employee accesses only the data its workflow requires, within agreed boundaries, over encrypted connections. GDPR considerations are addressed in the design phase and documented per implementation.
Yes. Every digital employee has a stop mechanism that pauses all activity immediately, with work safely queued for human handling. Nothing about the setup locks you in technically.