Answers must be traceable
The agent explains data and drafts tasks. It should not bypass permissions or directly act on customer data.
- Answers show sources, data range, and important limitations.
- Cross-account and cross-site data access must be blocked by backend permissions and RLS.
- Plain PII is not part of default context.
High-risk actions
Exports, task creation, subscription changes, and sensitive-field access require confirmation and audit.
- Fixed questions and normal chat both obey daily quota limits.
- When context limits are reached, the UI prompts a new session or summarized compression.
- Agent-triggered scans, exports, and background work must enter the queue.