A customer asking where their order is gets an answer from the store and the carrier. A $184 refund goes through, a request to refund everyone is refused, and a customer in Spain gets a reply on WhatsApp.
Tidewater Goods is a made-up online store. For each moment, Monday to Sunday: what happened, what the system did, which service it used, and the entry it wrote to the Ledger, the system’s record of every request and response.
An illustration. The business and the people are made up.
The AI assistant looks up order 4821 in your online store and in the carrier’s tracking, which is all it may read for this, and replies: shipped yesterday, arriving Thursday.
Someone asks the system to “refund everyone from last month”.
Refunds are allowed for one customer at a time, up to $500 each. No permission covers a refund to everyone, so the request is refused, and the refusal is written to the Ledger.
cloud job · overnight · one row per day written to your spreadsheet
········→········matches
Each Ledger entry carries a fingerprint of the entry before it.
The two codes under each entry above are the first characters of real SHA-256 fingerprints, calculated in your browser: the fingerprint of the entry before, then this entry’s own, which is calculated from its text plus the one before. Press “Change one word” to edit Thursday’s entry, then “Check every entry”: the check fails at that entry, because its text no longer matches its fingerprint. This is how a changed Ledger entry is detected.
Calculating fingerprints
Services used
The services this example uses
Each card is one service. A service is a set of actions from the Directory (the table of every action the system can run), set up for your business. The days on each card are the moments above that use it. The number on each card is how many actions in the Directory that service includes.
For each action you decide what information the AI assistant may read, what it may do, whom it may reply to, and limits such as an amount or a time window. A request outside the limits is refused, and the refusal is written to the Ledger.
Permissions switched on for an online store
What the AI assistant may read, what it may do, and whom it may reply to. Anything not listed here is switched off.
What it may read
Store ordersThe store or the carrier, read only
MessagesThe threads you choose, not all of them
PaymentsInvoices and subscriptions
What it may do
ReplyIn your writing style, within your permissions
Win back30, 60, 90 days, with a reason to return
Invoice and refundSend, finalize, refund within a limit
Refunds are allowed for one customer at a time, up to $500 each. Wednesday’s request to refund all of last month’s customers was refused and written to the Ledger.
Examples of actions with limits
Each card shows an action an online store would use, the limit on it, and what came back, as it appears in the Ledger. A refused request is recorded the same way.
Refund $184 to the original card
limit: ≤ $500 without you
used once
$184 refunded
Refund everyone from last month
limit: ≤ $500 per action, one customer per action
refused · no permission for this
Make 12 ad variants from the brief
limit: 36 renders per run
write: Meta, this account
limit: paused until you say go
uploaded, paused
Moments this week where a permission or limit applied
3 of the 8 moments above were decided by a permission or a limit. Each one is an entry in the Ledger, including any refusal.
The Directory is a table of every action the system can run. Dispatch is one web address that runs any of those actions. The Ledger records every request and response. The actions run on real computers and phones. Choose how much detail you want: for you, for your team or for your developer.
Numbers are live, read from this site just now.
The DirectoryEvery action the system can run
A table with one row for each action the system can run.
The Directory is a table. Each row is one thing the system can do for your business: send a text from your number, book a slot in your calendar, create an ad, read a web page, take a screenshot of your Mac. If an action is not in the table, the system cannot do it.
Each row stores everything needed to run that action: where it runs, what inputs it needs, what it returns, and every way to call it. Changing a setting is typing in a cell. Files added to the system’s folder are added to the table automatically.
One row per action. Each row has one column per way of calling it, and each of those cells holds the complete request (method, address, headers and body) that runs it, followed by the full response from the last run.
Why it matters to your online store
Every action your business can use is listed in one place, with where it runs and what it needs. You can see what the system is able to do before it does anything: if an action is not in the Directory, it cannot run.
—actions in the Directory
Actions in the Directory for each service this example uses
Dispatch is a single web address. You, your staff, a spreadsheet, an iPhone Shortcut or an AI model send it the name of an action and its inputs. It finds the action in the Directory, checks your permissions, runs it on the right computer, sends back the result, and writes an entry in the Ledger.
Because every request goes through the same address, the same permissions apply whether a request comes from a text message, a link, a spreadsheet cell, a Shortcut, the command line or an AI model, and every request is recorded the same way. One action can be switched off in one place.
Every action is invoked as an HTTP POST of {"key": "<action name>", "args": {…}}. REST, MCP, spreadsheet formulas, text tags and webhooks are different ways of making that same request. Actions run on Cloudflare servers, a Mac, an iPhone, a browser, a virtual machine or a phone.
Why it matters to your online store
One connection instead of a separate integration for every tool. Your staff, your AI models, your spreadsheets and your phone all use the same actions under the same permissions. Changing AI model or vendor does not mean rebuilding, and any action can be switched off in one place.
—ways to call each action
A text messageA web linkA spreadsheet cellAn iPhone ShortcutA command typed in a terminalAn AI model’s tool call
A table with one row for every request and response the system has handled.
The Ledger is a record of everything the system does: every message sent and received, every action run, every change, every AI model’s answer, and every request that was refused. Nothing in it is overwritten. To find out what happened, you read it.
Each entry stores the full request and the full response. Each entry also stores a fingerprint of the entry before it, so if anyone changes an entry later, the change shows up. Refused requests are recorded the same way as completed ones.
Every payload in or out is a Ledger row. Each action appends one row containing a SHA-256 hash of the previous row; nothing is updated in place. An action counts as working only when the declared surface itself ran and five things are stored for that run: why it ran, the exact request written before it ran, the confirmation, the exact response, and the record.
Why it matters to your online store
You can see exactly what was sent, to whom, when, and by which AI model, and settle a dispute from the record instead of from memory. You can check what an AI did before trusting it with more, and compare AI models on cost and results. Refused requests are recorded too.
Depending on the action, the work happens on Cloudflare’s servers (always on), on your Mac, on your iPhone, in a web browser signed in to your accounts, or on Android phones rented in a data centre for apps that only run on a phone.
A website or app with no way to connect to it can be recorded once — the steps a person clicks — and saved as a new action in the Directory that can be run again at any time. The browser uses your own signed-in sessions, not fake accounts.
Executors: Cloudflare Workers and containers, a Mac bridge program, iPhone Shortcuts and App Intents, persistent browser profiles, cloud Android phones and Mac virtual machines. Recording steps and compiling them turns any website into a Directory row callable through dispatch.
Pick the services and which phone number to use. The button opens a text message to me with your choices already written in, so my reply can be about your setup.
Tell me what your online store misses in a week: calls, follow-ups, reviews. I will reply with which moment above to set up first, and the entry it would write to the Ledger.