Skip to content

Systems · Commerce

Preview

Every customer answered. Nothing said that you did not approve.

Somebody on your team is answering these messages by hand, and not at eleven at night. The assistant answers in seconds using wording you approved, captures the order, and hands anything it cannot answer to a person — with the whole exchange on the record, including the questions it refused.

Five multiple-choice questions. A person replies within one business hour.

action ledger
  • 23:41:06T0order.status.readexecuted

    read only · scoped to this customer

  • 23:41:08T1answer.selectexecuted

    approved answer sent verbatim · source recorded

  • 23:41:22T2order.updateexecuted

    delivery address changed · before and after stored

  • 23:42:04T3answer.composerefused

    no approved answer for this question · handed to a person

  • 23:42:05T1handoff.queueexecuted

    conversation queued with full context

  • 08:12:30T3refund.issueheld for approval

    prepared overnight · waiting on a named person

Illustration of one night in a governed inbox. Every row is an event the system writes, including the two it refused or held.

The problem

The message that cost you the sale arrived at twenty to midnight.

Messaging is the shop floor now. The questions are the same twenty, over and over: is it in stock, where is my order, can I change the address, can I return this, is there a discount. Almost every one has an answer already — in a document, in a previous reply, in somebody’s head. What costs you is not the hard question. It is the easy one that waited until morning, by which time the customer bought elsewhere and told you nothing.

The obvious fix creates a worse problem. Point a general-purpose model at your website and it will answer the routine questions beautifully — and then answer an unusual one from its own imagination, in your name, on a channel where the customer keeps the receipt. That is not a hypothetical risk. A tribunal has already held a company responsible for what its chatbot told a customer, and the platforms themselves now draw the line: business-scoped assistants are permitted, general-purpose AI is not.

So the question is not whether an assistant can answer. It is what it is allowed to say, and what happens to everything else.

Source: Moffatt v. Air Canada, BC Civil Resolution Tribunal, February 2024; WhatsApp Business Terms of Service.

What it does

Five things, and none of them is writing the answer.

That is the difference between this and a chat window bolted to a knowledge base. What you get instead is a working front of house: the answer, the order, the handoff, the console your team lives in, and the loop that makes next month cover more than this one.

  1. 01

    It replies from answers you approved

    The assistant does not write the answer. It chooses one from a library you own and sends it as written. If nothing in the library fits the question, it does not improvise — it hands the conversation over.

  2. 02

    It takes the order and keeps the evidence

    Order capture, the evidence that payment was made, and an honest answer to “where is my order” read from the record rather than guessed. Moving money is never the assistant’s decision.

  3. 03

    It hands over with an attention queue

    Every conversation it cannot finish lands in a queue with the history, the customer, the order and the reason attached. Your team starts at the third message instead of the first.

  4. 04

    Your team works on your own domain

    A staff console under your brand, on your domain, with our governed backend behind it. Your people sign in to your business, not to a vendor’s product.

  5. 05

    It gets better only with your approval

    Questions nobody could answer become proposed answers. A person approves them and the library grows. What the system remembers advises the assistant and can never widen what it is allowed to say.

The governed hook

Four things it cannot do, whatever the customer types.

  • It cannot put words in your mouth

    Approved answers are sent as written. Fidelity is checked on the reply path, and a failed check is a refusal and a handoff, never a paraphrase that looks close enough.

  • It cannot move your money

    Refunds, captures and anything that changes a balance are prepared by the assistant and approved by a named person. No agent approves itself, and a spoken or typed yes from a customer is not a signature.

  • It cannot go live on optimism

    It runs in shadow against your real traffic first, answering nothing. You get a scorecard measured on your own history and a pass mark agreed before the test, then you decide go or no-go.

  • It cannot fail into silence

    If the model is unsure, the policy refuses or a provider is down, the conversation goes to a person and the customer is told a person is coming. The failure mode is a queue, not a dead thread.

The tier table, for a shop

Answering is not refunding.

This is the general tier table with the nouns of your business filled in. It is set before launch, in writing, with your team — not discovered afterwards.

  • Tier
    T0
    The action
    Read the order, the history and the answer library
    Who may run it
    The assistant
    What is recorded
    The request and what it returned
  • Tier
    T1
    The action
    Reply with an approved answer, prepare a draft, queue a handoff
    Who may run it
    The assistant, verbatim
    What is recorded
    Which answer, which version, and the match
  • Tier
    T2
    The action
    Change a delivery address, tag the conversation, set a reminder
    Who may run it
    The assistant, inside its ceiling
    What is recorded
    Before and after
  • Tier
    T3
    The action
    Say something outside the library, promise an exception, issue a refund
    Who may run it
    Prepared by the assistant · approved by a named person
    What is recorded
    Approver, evidence, policy version
  • Tier
    T4
    The action
    Capture or move money, delete a customer record
    Who may run it
    A person, with the assistant helping
    What is recorded
    Approver, second approver where set, full evidence
  • Tier
    T5
    The action
    Change what the assistant is allowed to say
    Who may run it
    Designated owners only
    What is recorded
    The change, the reviewer, what it affects

Honest status

Preview

Built, running, and not yet packaged.

You cannot sign up for this today and switch it on. Commerce runs on a specified delivery lane, configured for that engagement, with production cutover pending. No gallery, no self-serve switch. The packaging work is exactly what the badge is admitting to.

How we know it works before it speaks

Before an assistant answers a single customer, we measure it against the business’s own conversation history. A holdout test on past questions it has never seen. A replay of real past conversations to estimate how much of the traffic approved content can actually cover. A pass mark written down before the test, not after it.

On our first deployment, our own gate said not ready — so it did not go live. We publish that on purpose. A vendor whose gate has never failed has not built one.

We name no customer without a signed release. You get the method in full, and the measured results under an agreement — the same courtesy we would extend to your numbers.

What is not true yet

  • It is not a product you can sign up for and switch on yourself.
  • The X-Ray that reads a conversation history has been run once, with bespoke tooling.
  • Evidence export for auditors is designed and not built; the trail exists, the download does not.
  • The payment leg is configured per business rather than chosen from a list of connectors.

Straight answers

The five questions every shop asks.

Not by writing it. The reply path selects from your approved library and sends the wording as written; fidelity is checked on the way out, and a failure is recorded as a refusal rather than smoothed into a paraphrase. What it can still do is pick the wrong approved answer for a question, which is a relevance mistake, not a fabrication. That kind of mistake shows up in the scorecard before go-live, it is visible in the trail afterwards, and it is the reason handoff exists at all.

Start with the measurement, not the assistant.

You get the numbers out of your own conversations first: how long people wait, what never gets answered, what repeats, and the share an approved-answer assistant could actually take. If the answer is “not much”, you will hear that from us before you hear it from anyone else.

Five multiple-choice questions. A person replies within one business hour.


Other systems on the operating system: Kivara, Leadnix and Forge.