How the trust actually works

Staff you can audit

Every vendor in this category says “human in the loop” and “you stay in control”. This page is the mechanism behind those words here — what is enforced, where it is enforced, and how you can check it yourself without taking our word for anything.

The approval contract

enforced in the policy layer, not the prompt

Anything irreversible — an email that leaves, a quote that commits arithmetic to a customer — is drafted in full and stops in a queue. You read the actual words, then approve, redraft, or decline. Each decision is single-use and individually recorded: there is no “approve all sends” switch to flip, and a plan that was approved once cannot be replayed. Asking an agent nicely to skip the queue does not work, because the queue is not implemented in the agent — it is implemented in the layer that executes tools, which the agent cannot talk its way past.

The autonomy ladder

trust is earned from reviewed work, and it is always your call

L0 · Shadowing

Reads and suggests. Keeps its own internal records — notes, facts, research, "this needs nothing" — and lists each one for you to undo within seven days. Every email and message it writes waits for your approval. Every hire starts here — including one that was trusted in somebody else’s workspace, because trust is per-business, not per-agent.

L1 · Drafting

Earned after 20 reviewed actions with no more than 30% corrected. It may now also assemble a draft quote from your rate card and raise a quiet relationship with you without asking — neither reaches a customer. Every send still waits in the approval queue.

L2 · Trusted

Earned after 50 reviewed actions, no more than 2% corrected, and at least seven days at L1. A routine one-to-one reply to somebody you already correspond with may now go out without a click — which does leave the building.

At every level, some things never go out on an agent’s say-so. A first email to a new company — anyone at a domain you have never been in touch with — and anything addressed to more than one person come back to you for approval, as does opening or moving a deal or asking a customer for payment. A link that is not in your approved library is refused outright: the agent has to write the message without it, and the attempt counts against it.

“Reviewed” means you approved it after actually reading it — an approval in under two seconds does not count — and “corrected” means you declined it or undid it. The count starts again at each new level. Promotion is always an owner’s deliberate act, recorded with their name on it; you can choose to trust an agent before it meets the bar, and that is recorded as your call rather than as criteria met. An agent steps down a level automatically after a policy violation, or if its correction rate climbs well past its level’s bar, and you can step it down whenever you like. The app also shows an L3, earned after 200 reviewed actions, no more than 1% corrected and 30 days at L2; today it unlocks nothing beyond L2, and every rule above still applies.

Four things are never delegable

at any level, by any setting, for any agent

Quote a priceMoney is the owner’s voice. An agent that quotes is an agent that negotiates.
Offer a discountSame rule, sharper edge — a discount given twice is a price.
Agree contract termsTerms bind the business. Nothing that binds is delegable.
Commit to a meeting timeA calendar promise is a promise. Agents propose a booking link; humans commit.

These are not defaults you might accidentally loosen. They are not grantable — the capability system has no way to express giving them to an agent, which is a stronger statement than a checkbox that ships unticked.

The books

tamper-evident, and checkable by you

Every action lands in an append-only audit log where each entry cryptographically commits to the one before it. Editing, deleting, or reordering any row breaks every hash after it — including for us: the application role holding the database connection is never granted UPDATE or DELETE on that table at all.

Verify it: Settings → “Download everything” exports your whole workspace — contacts, pipeline, quotes, your agents’ charters, and the complete audit log — with the hash-chain recipe included, so a dozen lines of Python and a stock sha256 can confirm nothing was rewritten. Your data was never hostage, and leaving with all of it is one click, not a support ticket.

Your data and the models

stated plainly, because it determines what we are allowed to build

Nothing from your workspace trains a model — ours or a vendor’s. That one is contractual, and it is the commitment Google’s Workspace policy actually turns on.

What we do not have is a zero-retention agreement. This page said we did, and that was wrong: the provider we route to deletes inputs and outputs within 30 days, and anything its automated safety systems flag can be held for up to two years. Zero retention is negotiated per organisation with the provider, not a default anyone gets by asking. If your work needs it, bring your own key on an account that has it, and your customers’ mail travels under your contract instead of ours.

Model versions are pinned in the database, never floating aliases, so your agents’ behaviour cannot silently change overnight. If you prefer, bring your own Anthropic, OpenAI or Google key — or point at a local model on your own hardware — and your customers’ mail never touches a path you did not choose.

Outbound email your agents write carries an AI disclosure, as EU AI Act Article 50(1) has required since 2 August 2026 for anyone talking to a machine in a two-way exchange. We would do it anyway: the person on the other end is somebody’s customer.

Spending

a payroll, not a meter

Plans are flat with a hard cap: we notify at 80%, stop at 100%, and never auto-upgrade. There is no credit balance to watch, nothing expires at month-end, and a runaway loop cannot bill you — the stop is enforced against the same ledger the Settings page shows you.

Roster Solo·Sign in·Privacy·Terms·Questions about any claim here — ask at support@rostersolo.com, and expect a specific answer.
Trust · Roster Solo