Systems · Commerce
PreviewEvery customer answered. Nothing said that you did not approve.
Somebody on your team is answering these messages by hand, and not at eleven at night. The assistant answers in seconds using wording you approved, captures the order, and hands anything it cannot answer to a person — with the whole exchange on the record, including the questions it refused.
Five multiple-choice questions. A person replies within one business hour.
- 23:41:06T0order.status.readexecuted
read only · scoped to this customer
- 23:41:08T1answer.selectexecuted
approved answer sent verbatim · source recorded
- 23:41:22T2order.updateexecuted
delivery address changed · before and after stored
- 23:42:04T3answer.composerefused
no approved answer for this question · handed to a person
- 23:42:05T1handoff.queueexecuted
conversation queued with full context
- 08:12:30T3refund.issueheld for approval
prepared overnight · waiting on a named person
The problem
The message that cost you the sale arrived at twenty to midnight.
Messaging is the shop floor now. The questions are the same twenty, over and over: is it in stock, where is my order, can I change the address, can I return this, is there a discount. Almost every one has an answer already — in a document, in a previous reply, in somebody’s head. What costs you is not the hard question. It is the easy one that waited until morning, by which time the customer bought elsewhere and told you nothing.
The obvious fix creates a worse problem. Point a general-purpose model at your website and it will answer the routine questions beautifully — and then answer an unusual one from its own imagination, in your name, on a channel where the customer keeps the receipt. That is not a hypothetical risk. A tribunal has already held a company responsible for what its chatbot told a customer, and the platforms themselves now draw the line: business-scoped assistants are permitted, general-purpose AI is not.
So the question is not whether an assistant can answer. It is what it is allowed to say, and what happens to everything else.
Source: Moffatt v. Air Canada, BC Civil Resolution Tribunal, February 2024; WhatsApp Business Terms of Service.
What it does
Five things, and none of them is writing the answer.
That is the difference between this and a chat window bolted to a knowledge base. What you get instead is a working front of house: the answer, the order, the handoff, the console your team lives in, and the loop that makes next month cover more than this one.
- 01
It replies from answers you approved
The assistant does not write the answer. It chooses one from a library you own and sends it as written. If nothing in the library fits the question, it does not improvise — it hands the conversation over.
- 02
It takes the order and keeps the evidence
Order capture, the evidence that payment was made, and an honest answer to “where is my order” read from the record rather than guessed. Moving money is never the assistant’s decision.
- 03
It hands over with an attention queue
Every conversation it cannot finish lands in a queue with the history, the customer, the order and the reason attached. Your team starts at the third message instead of the first.
- 04
Your team works on your own domain
A staff console under your brand, on your domain, with our governed backend behind it. Your people sign in to your business, not to a vendor’s product.
- 05
It gets better only with your approval
Questions nobody could answer become proposed answers. A person approves them and the library grows. What the system remembers advises the assistant and can never widen what it is allowed to say.
The governed hook
Four things it cannot do, whatever the customer types.
It cannot put words in your mouth
Approved answers are sent as written. Fidelity is checked on the reply path, and a failed check is a refusal and a handoff, never a paraphrase that looks close enough.
It cannot move your money
Refunds, captures and anything that changes a balance are prepared by the assistant and approved by a named person. No agent approves itself, and a spoken or typed yes from a customer is not a signature.
It cannot go live on optimism
It runs in shadow against your real traffic first, answering nothing. You get a scorecard measured on your own history and a pass mark agreed before the test, then you decide go or no-go.
It cannot fail into silence
If the model is unsure, the policy refuses or a provider is down, the conversation goes to a person and the customer is told a person is coming. The failure mode is a queue, not a dead thread.
The tier table, for a shop
Answering is not refunding.
This is the general tier table with the nouns of your business filled in. It is set before launch, in writing, with your team — not discovered afterwards.
| Tier | The action | Who may run it | What is recorded |
|---|---|---|---|
| T0 | Read the order, the history and the answer library | The assistant | The request and what it returned |
| T1 | Reply with an approved answer, prepare a draft, queue a handoff | The assistant, verbatim | Which answer, which version, and the match |
| T2 | Change a delivery address, tag the conversation, set a reminder | The assistant, inside its ceiling | Before and after |
| T3 | Say something outside the library, promise an exception, issue a refund | Prepared by the assistant · approved by a named person | Approver, evidence, policy version |
| T4 | Capture or move money, delete a customer record | A person, with the assistant helping | Approver, second approver where set, full evidence |
| T5 | Change what the assistant is allowed to say | Designated owners only | The change, the reviewer, what it affects |
- Tier
- T0
- The action
- Read the order, the history and the answer library
- Who may run it
- The assistant
- What is recorded
- The request and what it returned
- Tier
- T1
- The action
- Reply with an approved answer, prepare a draft, queue a handoff
- Who may run it
- The assistant, verbatim
- What is recorded
- Which answer, which version, and the match
- Tier
- T2
- The action
- Change a delivery address, tag the conversation, set a reminder
- Who may run it
- The assistant, inside its ceiling
- What is recorded
- Before and after
- Tier
- T3
- The action
- Say something outside the library, promise an exception, issue a refund
- Who may run it
- Prepared by the assistant · approved by a named person
- What is recorded
- Approver, evidence, policy version
- Tier
- T4
- The action
- Capture or move money, delete a customer record
- Who may run it
- A person, with the assistant helping
- What is recorded
- Approver, second approver where set, full evidence
- Tier
- T5
- The action
- Change what the assistant is allowed to say
- Who may run it
- Designated owners only
- What is recorded
- The change, the reviewer, what it affects
Honest status
PreviewBuilt, running, and not yet packaged.
You cannot sign up for this today and switch it on. Commerce runs on a specified delivery lane, configured for that engagement, with production cutover pending. No gallery, no self-serve switch. The packaging work is exactly what the badge is admitting to.
How we know it works before it speaks
Before an assistant answers a single customer, we measure it against the business’s own conversation history. A holdout test on past questions it has never seen. A replay of real past conversations to estimate how much of the traffic approved content can actually cover. A pass mark written down before the test, not after it.
On our first deployment, our own gate said not ready — so it did not go live. We publish that on purpose. A vendor whose gate has never failed has not built one.
What is not true yet
- It is not a product you can sign up for and switch on yourself.
- The X-Ray that reads a conversation history has been run once, with bespoke tooling.
- Evidence export for auditors is designed and not built; the trail exists, the download does not.
- The payment leg is configured per business rather than chosen from a list of connectors.
Straight answers
The five questions every shop asks.
Start with the measurement, not the assistant.
You get the numbers out of your own conversations first: how long people wait, what never gets answered, what repeats, and the share an approved-answer assistant could actually take. If the answer is “not much”, you will hear that from us before you hear it from anyone else.
Five multiple-choice questions. A person replies within one business hour.
Other systems on the operating system: Kivara, Leadnix and Forge.
