The system
How the system worksThe DirectoryDispatchThe LedgerAI modelsAI agentsYour installationThe appThe research libraryWhat changes for your businessUse it from your softwareEverything it can do
Messaging
iMessageWhatsApp
Ads and leads
AdsCreativeLeads
Devices
Devices
Industries
RealtorsRestaurantsHome services
Explore
How it worksPermissions and limitsCompareSet upQuestionsText me

Permissions and limits

Choose what the AI assistant may read, what it may do, and whom it may reply to.

The AI assistant is an AI model that reads and replies to messages on your number. Each switch on this page is one permission. With a switch off, the assistant cannot use it, and it tells the person which part it cannot help with. Any request outside a permission or a limit is refused, and the refusal is written to the Ledger, the system’s record of every request and response.

All permissions

9 of 20 switched on

What it may read2 of 8 on
What it may do3 of 7 on
Whom it may reply to4 of 5 on
Messages
MMotheriMessage
Did you land?
Landed on time. Home by 6.

Location is off, so it says nothing about where you are. Calendar is on, so it knows when you are free.

LA leadiMessage
Saw your ad. How much for a site?
I can’t quote from here, but I can get you a number today. Want 15 minutes tomorrow? I have 10:00 or 2:30.

Approved prices is off, so it refuses to invent a number. Calendar and booking are on, so it offers real slots.

CA customeriMessage
Where is my order?
I’ll check with the team and text you back within the hour.

Store orders is off, so it promises a person, not an answer it does not have.

With these switches

It may read Calendar, Messages. It may reply, book, missed call text-back. It may reply to family, leads, customers, you.

The conversations are illustrations; the people are made up.

Your setup:

It may read Calendar, Messages. It may reply, book, missed call text-back. It may reply to family, leads, customers, you.

9 of 20 switched on

Text this setup

May read

What it may read.

Each switch lets the assistant read one kind of information. With a switch off, it cannot see that information.

Calendar

What is next, and which hours are open

On: the assistant can read your calendar, to see what is booked and which hours are free. It reads the calendar you already use.

ExampleA customer asks to move the 3pm. The event moves to 4:15, and the other person gets a text about it in your words.

Messages

The threads you choose, not all of them

On: the assistant can read and reply in the message threads you choose on your own number, not all of them. You choose person by person.

ExampleIt sends only prices you approved, and passes the conversation to you at the point you set.

Mail

Search and read, tracked sends

On: the assistant can search and read your email, and send emails that report when they are opened.

ExampleYou learn that invoice 118 was opened at 8:41, because it was sent as an email that reports opens.

Location

Only for the people you name, only on the triggers you set

On: the assistant can know where your iPhone is when it arrives at or leaves places you set. It shares this only with the people you name.

ExampleA family member asks “Did you land?” and gets a true answer, because location is on for that one person.

Store orders

The store or the carrier, read only

On: the assistant can read orders and delivery tracking from your online store and the delivery company. It cannot change them.

ExampleOrder 4821 shipped yesterday, arriving Thursday. Tracking is in the thread above this one.

Payments

Invoices and subscriptions

On: the assistant can read invoices and subscriptions in your payment account (for example Stripe).

Approved prices

The price list it may quote from

On: the assistant can quote prices from the price list you approved, and only those. Off: it never states a price.

ExampleNo reply and no ad states a price that is not on your list.

Files

The folders you point it at

On: the assistant can read, write, list and search the folders you choose on your Mac.

ExampleA brief saved to a folder is used to make ad variants.

May do

What it may do.

Each switch lets the assistant take one kind of action. Every action it takes is written to the Ledger.

Reply

In your writing style, within your permissions

On: the assistant sends replies on your number, written the way you write, within these permissions. Off: it reads, but never sends.

Book

Only into the hours you opened

On: the assistant can create calendar events, only in the hours you marked as open, and send the invitation.

ExampleA customer texts “2:30 works”; a calendar event is created and the invitation is sent.

Missed call text-back

From your number, within a minute

On: when you miss a call, the caller gets a text from your number within a minute, and the assistant carries on the conversation to book the job.

ExampleMissed call at 2:18. A text from your number at 2:19. The job booked at 2:21.

Follow up

Day 2, 5 and 10, with something useful to say

On: a quote with no reply gets a follow-up text on day 2, day 5 and day 10, each with something useful in it. The texts stop as soon as the person replies.

ExampleA quote sent on Monday with no answer gets a text on Wednesday, on Saturday and ten days after it was sent, unless they reply first.

Win back

30, 60, 90 days, with a reason to return

On: customers who have not been back for 30, 60 or 90 days get a text with a reason to return, such as the dish they usually order. The texts stop when they reply.

Invoice and refund

Send, finalize, refund within a limit

On: the assistant can create an invoice, send it in the text thread the customer already has with you, and refund up to the limit you set without asking you.

ExampleA refund to one customer, up to $500, allowed for ten minutes. After that the permission expires.

Home

Unlock for the cleaner at 10, lock at 10:15

On: the assistant can lock and unlock a smart door lock and turn lights on and off, only inside the time window you set.

ExampleThe door unlocks at 9:55 for the cleaner and locks at 10:15, and you get a text both times.

May reply to

Whom it may reply to.

Each switch lets the assistant reply to one group of people. Messages from anyone else wait for you.

You

Answers you using the same information

You can text the assistant instructions from your own phone: move a meeting, tell someone you are running late, send a file, unlock a door. It does the parts that are switched on and says which parts are off.

YYouiMessage
Move my 3, tell Dana I’m 20 late, unlock the door for the cleaner at 10.
3:00 moved to 4:15, she accepted. Dana texted, she said fine. The door isn’t mine to open.

It says which parts it cannot do, and why: home is off.

Friends, family, leads and customers

Limits

Every action has limits, and every result is written to the Ledger.

A limit is a maximum amount, a time window or a number of uses attached to an action. A request outside it is refused, and nothing runs.

The Ledger is a database table that stores every request and every response, in order and in full. Each entry includes a fingerprint (a SHA-256 hash) of the entry before it, so an entry changed afterwards can be detected. Below are seven example entries.

7 entries, not checked yet

Each entry’s fingerprint is computed from the fingerprint of the entry before it plus the entry’s own contents. Change one entry, then check again: from that entry on, the fingerprints no longer match. The requests are made-up examples; the SHA-256 fingerprints are real, computed in your browser.

start of the Ledger aeebad4a
Ledger entry#1

Text back the missed call

  • readMessages, this handle only
  • in your writing style, using only prices you approved

sent from your number

Text sent 52 seconds after the missed call. They replied. Diagnostic booked for 4:30 today.

fingerprint of the entry before aeebad4athis entry’s fingerprint 4cdc7072

Ledger entry#2

Send the invoice to Bright Roofing

  • limit≤ $5,000 without you
  • to the thread they already have with you

sent in the thread

Sent by iMessage to Bright Roofing. Opened 41 seconds later.

fingerprint of the entry before 4cdc7072this entry’s fingerprint cd3f1bc1

Ledger entry#3

Make 12 ad variants from the brief

  • limit36 renders per run
  • writeMeta, this account
  • limitpaused until you say go

uploaded, paused

36 files in the ad account, 12 ads created and paused. Nothing is spent until you turn them on.

fingerprint of the entry before cd3f1bc1this entry’s fingerprint 55086552

Ledger entry#4

Book the 2:30

  • writeCalendar, only hours you opened

invite sent

“2:30 works” becomes a calendar event with the invite sent.

fingerprint of the entry before 55086552this entry’s fingerprint b717c014

Ledger entry#5

Refund $184 to the original card

  • limit≤ $500 without you
  • used once

$184 refunded

$184 refunded and the customer told. It was under the limit, so it did not need to ask you.

fingerprint of the entry before b717c014this entry’s fingerprint ef58b2fb

Ledger entry#6

Unlock the door for the cleaner at 10

  • limit20-minute window, weekdays

unlocked, locked at 10:15

Scheduled. Door opens 9:55, locks 10:15, you get a text at both.

fingerprint of the entry before ef58b2fbthis entry’s fingerprint 3e2f843c

Ledger entry#7

Refund everyone from last month

  • limit≤ $500 per action, one customer per action

refused · no permission for this

Refused. No permission allows a refund to many customers at once. Nothing ran, and the refusal is written to the Ledger too.

fingerprint of the entry before 3e2f843cthis entry’s fingerprint 981c4bdd

Refused requests are recorded too

If no permission covers a request, nothing runs, and the refusal is stored in the Ledger.

  • Refund to everyone: refused
  • Texting a bought contact list: refused
  • Outside the time window: refused
10:00left

A permission for one job

A permission can be issued for a single job, with a limit and an expiry time. It stops working when the job is done.

Example: a refund for one customer, up to $500, valid for ten minutes. Or a door code for a contractor, valid for one afternoon.

Covers: one actionLimit: an amount or a time windowStops working after use

Never

What it never does.

Only people who contacted you or transacted with you. Opt-out in every thread.

  • No purchased lists.
  • No cold blasts.
  • No message without an opt-out.
  • No pretending to be you to someone who asked.

Warm only

WhatsApp is where a conversation continues, not where it starts. The assistant writes to people who have written first, on any channel.

WhatsAppwarm only

Opt-out in every thread

“Stop” is honoured immediately, recorded, and never overridden.

Stop
Opt-out · honoured instantly

No purchased lists

Records come from the ad, Places, the licence board and the site. Nothing bought.

Paused until you say go

Created paused, budget set by rule, a loser paused and a winner duplicated from a text.

12 adsuploaded, paused

Replies inside your rules

Until they answer, never after

Day 2, 5 and 10. The follow-ups stop the moment they reply.

First messageDay 2Day 5Day 10
2:30 worksthe follow-ups stop

Says it is AI

It tells people it is an AI assistant when they ask, and passes the conversation to you when they ask for you.

Customers and leads are told it is an assistant when they ask, and it hands to a person the moment the conversation goes somewhere it shouldn't.

When they ask, yes, and it hands to you the moment it should. Pretending otherwise gets found out on the first visit and costs you the job.

Whom it may reply to

Does it talk to my leads as me?

It replies from your number, in your voice, within the permissions you set, and says it is an assistant when someone asks. It books showings; it does not negotiate, quote commission or give legal advice. Those hand to you.

What about my brokerage's rules?

Send them. The assistant's rules are yours to set, and the transcript of every message is on the ledger for your broker to read.

Text me.

Text the permissions you would switch on. I will reply with what the assistant would do with them, and what its Ledger entries would show.