AI

AI Agents & approvals

Agents are AI workers that operate your back office, Work, Accounting, People, CRM, HR and Support, under human control. An agent never acts on its own: it proposes a typed action, a person approves it with one click, and every action is audited and reversible.

  • Scoped, never a bypassAn agent can only do what the approving person could do, every action runs through the same permissions and tenant isolation a human is subject to.
  • Voice & tone per agentGive each agent a voice, Professional, Friendly, Concise, Formal or Casual, in the agent editor on the Agents page. Every summary and drafted text the agent proposes follows its tone; leave it on Default for neutral output.
  • Approve-first by defaultAgents propose; a person with the Approve agent actions permission approves or rejects. Money, payroll and legal actions always stay approve-first.
  • Audited & reversibleEvery proposal, approval, execution and rollback is recorded in an append-only trail, and executed actions can be rolled back in one click.
  • Cost ceilings & the Free tasteSet per-day or per-month run and dollar limits (org-wide or per agent). Agent runs are refused once a ceiling is reached.AI agents are available on every plan: the Free plan includes a metered taste of 25 agent actions per month; Pro and above are unlimited. Set your own org-wide monthly cap any time and it overrides the default.On the Free plan the Agents page shows a usage meter (runs used this month) and surfaces an Upgrade to Pro prompt as you approach the limit, upgrade for unlimited runs; your agents, tools, approvals and ceilings stay exactly as configured.
  1. 1

    1. Create an agent

    Open Agents ▸ New agent. Give it a name, pick a domain (Work, Accounting, People, CRM, HR, Support) and an autonomy level, Approve-first is recommended.

  2. 2

    2. Grant tools

    Re-open the agent and tick the tools it may use. Each tool shows its risk level and whether it is reversible.

  3. 3

    3. Set a cost ceiling

    On the Agents page set an org-wide day/month limit on runs or dollars so an agent can never run away.

  4. 4

    4. Review the queue

    Proposed actions appear under Agent approvals. Open one to see the exact change and audit trail, then Approve, Reject, or (after execution) Roll back.

  5. 5

    5. Track the ROI

    Open Agents ▸ Activity & ROI to see the time and money your agents have saved, actions executed, hours saved, value created net of agent cost, and how many actions were rolled back, over the last 7, 30 or 90 days.

  6. 6

    6. Turn on autonomous sensing (optional)

    Open an Accounting, Tasks, CRM or People agent and switch on “Autonomous sensing”, choosing a cadence (daily or hourly) and a max proposals per run. The agent then watches your data on a schedule and files proposals to the approval queue on its own, no clicking. It stays approve-first (nothing executes itself), is capped per run, de-duplicates (and won’t re-raise something you rejected for a week), and still obeys your cost ceilings. Use “Pause all agents” on the Agents page to stop all sensing across the workspace instantly.

Ask your agent in plain language: on the Agents page pick an agent and type what you want, e.g. "draft follow-ups for my stalled deals". It reasons over your data and proposes concrete, approve-first actions (with the dry-run preview); nothing runs until you approve. Powered by the AI provider you connect under Console ▸ AI assistant.

Chief is INSTANT for clear commands: "create a portfolio called Growth", "rename project Apollo to Apollo 2", "set task Onboarding due tomorrow", "mark task Design review as done", these execute immediately within your permissions (no AI round-trip, typically well under a second). If a required detail is missing, like which company a new portfolio belongs to, Chief asks one short question and finishes on your answer. And asking "tell me about NAME / project X / client Y" returns the complete picture in one reply, open, overdue and completed work, leave, deals, invoices and last activity, with empty cases stated plainly instead of a bare "no tasks". Risky changes (deletes, money, approvals) still go through the approval queue.

Connected workspace: every record lives in a web, and Chief can walk it. Ask “what’s connected to Helio Systems” or “which company does this portfolio sit under” and it maps one hop in both directions, what a record belongs to and what hangs off it, with counts. When Chief opens, creates or edits a record it automatically sees that record’s connections too, so answers come with context (“that task belongs to the v2 API launch under Helio Systems”) instead of a lone row. If a name exists as both a client and a company, Chief follows the one with live connections and says so.

Business Architect (rolling out): answer five questions about your business, industry, team size, what you sell, how you get paid, where clients come from, and Chief drafts your whole workspace setup: which modules to enable, a starter AI-agent team, a lead-intake form, a booking page, optionally sample data. The blueprint only ever uses a fixed whitelist of safe operations, NOTHING runs when it is drafted, every step files into Agent approvals, and each approved step executes as the admin who approved it, through the same permission-checked paths a human click uses. Find it under Administration ▸ Business Architect.

Total recall (rolling out): tell Chief to “watch overdue invoices”, “track this deal” or “tell me if anything changes on the Acme project” and it checks every 15 minutes (or daily), capped at 20 active watches each. A watch is handled by an agent rather than announced at you: it opens one accountable item that counts occurrences and closes itself when the condition clears, an agent is picked from the area being watched and proposes concrete actions into your normal approval queue, and a person is told only when the agent could not deal with it. The person it escalates to and your owners and admins can see it as well as you. Ask “what changed today / this week” for an instant pulse of everything that happened, “show the timeline of X” for one record’s history, and “remind me to…” files a real reminder. When Chief promises a follow-up it files its own reminder too, so its promises don’t slip.

Morning briefing: while agents are sensing, the Agents page shows a daily briefing, what they watched, what awaits your approval, and what they handled automatically (reversible), and the people who can approve get a once-a-day notification so nothing slips. Everything stays approve-first and auditable.

Pre-drafted autonomously: when an agent senses a stale deal it does not just flag it. A background job writes the actual follow-up message for you (via the AI provider you connect under Console > AI assistant), so the proposal lands in the approval queue already drafted, ready to review and send. It stays approve-first (nothing sends itself), is rate-limited and cost-capped with a hard daily limit, and reuses a cached draft for the same deal so it never re-bills for the same work. The same engine attaches a one-line rationale to expense, task, and capacity proposals too, so every autonomous suggestion arrives with its reasoning.

Learns your preferences (policy memory): every time you approve or reject a proposal your agents remember, per workspace, per action type. The Agent approvals queue is then ranked by how often you approve each kind, so the proposals you usually accept rise to the top and the ones you usually dismiss sink. Each row shows a Signal (Usually approved / Often rejected / Learning / New), and opening a proposal shows exactly what was learned (for example, you approved 9 of 10 of these). It only ranks and explains, it never changes the approve-first rule, auto-approvals never train it, and an admin can Reset learning for any action type to start it neutral again.

Built-in agents: your workspace comes with a default team of agents: a Chief plus assistants for Work, CRM, Finance and People (the ones your plan includes). These are marked System and are always available: you can pause or archive them, but they cannot be deleted, so the core team is never lost by accident. You can still add your own agents alongside them. Archive one to hide it from the list and stop it working; restore it any time from Show archived.

Chief writes in your brand voice: set your workspace Brand Voice once (tone, audience, guidelines, preferred call-to-action and words to avoid) under Marketing > Social & Content > Brand Voice, and Chief plus every content agent draft in that voice automatically - chat replies, generated posts, reports and reminders all sound on-brand and steer clear of your banned words. No key or per-page setting needed; it applies everywhere the AI writes.

Chief (your AI personal assistant): a movable floating assistant that knows the whole platform AND your live workspace, your team, your numbers, everything your role can see. Ask it anything in plain English (“how many staff do we have and what do they do?”, “what needs my attention?”, “how do I set up X?”) and it answers from your live data + the product docs, so answers stay current as the product grows. Tell it what you need done (“onboard Acme Corp”, “create a support agent”) and it sets it up and drafts the work for your approval. It acts with YOUR permissions only, delegates to the right domain agent, keeps your conversation history, and every action it proposes goes through the approve-first, preflighted queue, nothing runs until you approve. Drag its button anywhere; open it from the bottom-left. Answers use your connected AI key; workflows and agent-creation work with no key at all.

Chief, it reads your live data before answering: when you ask about your guests, invoices, deals, leads, tasks, projects, clients or files, it pulls a fresh, permission-scoped snapshot of exactly those records (only what your role can see) and answers from it, e.g. “any guests in any project?” returns the real guest list and their projects, not a guess. It only claims something is empty when it actually holds that list; if a detail is outside what it can see it tells you plainly and points you to the right page rather than inventing an answer, and it never claims to have “checked” a screen it cannot open.

Chief, proactive suggestions: open the assistant and it shows a short “Suggested for you” list, the highest-impact things waiting on you right now, drawn from your live workspace (agent approvals to review, overdue invoices to chase, tasks past due, leave requests to approve, new leads to follow up, storage running low, or starting an NPS survey). Each is one click: it either takes you straight to the right page or drafts the action for your approval. Suggestions are personalised to your role and plan, you only ever see actions you can actually take, and they cost nothing extra: they are computed from the same live figures the dashboard already loads, with no AI usage.

Per-agent reports (Agents ▸ Activity & ROI): every agent has a complete individual record, just like a human teammate, work done (net of rollbacks), per-skill breakdown, reliability, estimated time saved and net value at your blended rate, runs, tokens and metered cost, and first/last activity. Click an agent to open its full profile page (/agents/<id>): what it suggested by category, its complete action history with every detail (the exact payload it proposed, result, what rollback restores, decision notes) and the per-action audit trail, plus CSV export of the whole team or one agent’s history. Visible to agent managers and approvers.

Chief, it keeps learning (org-wide): teach it anything with “remember that …” or “from now on …” and the note is learned for the WHOLE workspace, every manager’s assistant applies it from then on, and learned notes win over generic docs. Rate any answer 👍/👎; on a 👎 it asks what it should have said and learns the correction for everyone. Say “forget …” to remove a note. It also learns your project automatically (grounds on the live docs as features ship) and your action taste (approve/reject history tunes what agents propose). Learning is capped and secure: manager-only, per-org limits, no personal data collected beyond your workspace.

Chief, invite teammates & train agents: ask it to “invite dana@acme.com as an admin” and it collects anything missing (email, role, it suggests admin / member / viewer from the duties you describe), then queues ONE approve-first invitation; the invite email only goes out when you approve, and rollback revokes it. Ask it to “train the CRM Assistant” and it shows what that agent already knows, offers the skills it could learn, and queues an approve-first training action, granting or revoking tools, changing autonomy (draft-only / approve-first / auto low-risk) or toggling proactive sensing. Fully reversible: rolling back restores the previous skills and settings. Sending invites requires an owner/admin approver; training requires the manage-agents permission.

Chief, it now fetches its own live data (the brain): instead of a fixed set of pre-loaded snapshots, Chief can look up whatever your question needs, still only within YOUR permissions, with row-level security enforced on every lookup, so it never sees more than you could see yourself on the matching page. It also has permanent memory: facts, preferences and corrections it learns are saved automatically (not just when you say “remember that”) as either private (visible only to you) or workspace notes (visible to every teammate’s Chief), manage everything it knows from the brain icon in the panel header (“What Chief knows”), where you can review and forget (archive) any note; admins can also forget shared workspace notes. It never stores secrets, passwords or payment details. And it remembers the conversation itself: close the panel, reload the page, or come back on another device, and Chief picks the thread back up, use the eraser icon any time to start a brand-new conversation. CORRECTED: this paragraph used to say the brain was enabled workspace by workspace from the platform rollout console. It is not any more - the chief_brain rollout flag reached stage ga, which means every workspace has it, and nobody updated the sentence. It is still a rollout flag rather than a sellable feature, so it does not appear in the plan matrix, and there has never been a control for it under Administration ▸ Plans whatever an older version of this page told you. Nothing to ask for and nothing to switch on: it is on.

Chief: learned skills: when Chief works out a reusable way to do something (for example a report it can run the same way each time), it proposes the skill in chat; an admin approves or rejects it either right there or from the panel’s Skills tab (open “What Chief knows” and switch tabs), and only approved skills are reused going forward. Chief also ships with built-in operating playbooks across finance, HR, projects, sales, marketing, social, communication, support and operations. Admins can extend these with their own workspace-specific entries alongside the built-ins.

Chief (Playbooks (open “What Chief knows” ▸ Playbooks): browse every operating playbook Chief draws on) built-ins across finance, HR, projects, sales, marketing, social, communication, support and operations (marked Built-in, read-only) plus your workspace’s own, grouped by domain. Admins (Manage agents) can add a playbook there (pick a domain, a title and the guidance text) edit or deactivate it, and delete their own; built-ins can’t be changed or removed from the client. Your own playbooks override the matching built-in when Chief gives advice, so this is where to encode exactly how your workspace wants things done. Chief now recalls the built-ins by meaning (semantic search), not just exact wording, so the right operating guidance surfaces even when you word a request differently.

Chief: take your brain with you (Export / Import): from “What Chief knows” ▸ Memories, owners and admins can Export brain to download a portable JSON bundle of the workspace’s shared memories and operating playbooks, and Import one into another workspace. It is your data, not ours. The export never includes anyone’s private notes, identifiers, secrets, passwords or payment details, and import is content-checked on the server (it refuses anything that looks like a secret or card number, caps length and count, and de-duplicates) so a bundle can only add safe workspace knowledge to the workspace you run the import in. Ideal for standing up a new client workspace with a fleet you have already trained, or moving between workspaces without starting Chief from scratch. The same Import button also understands ChatGPT and Claude data exports: drop the conversations.json from either and Chief extracts fact-looking statements about you and your business into a review list. You tick exactly what it should remember, and nothing else is read or saved. Prefer a guided start? Teach Chief (next to Import) walks you through a few short questions about your business, customers, delivery process and writing preferences and saves the answers as shared memories (plus an operating playbook for your delivery process).

Noise control (opt-in): if your agents keep proposing a kind of action you almost always reject, turn on Noise control at the top of Agent approvals (admins / people with Manage agents). Once an action type has enough of your decisions and a low enough acceptance rate, your agents quietly stop autonomously proposing it, so the queue stays signal, not noise. It is fully reversible: turn it off and the suggestions come straight back, and any items already waiting stay in the queue for your review. It only affects the agents’ own background scanning, asking an agent directly (or Find work) still surfaces everything, and nothing is ever auto-approved or auto-executed.

Run a workflow: on the Agents page, managers can pick a ready-made workflow (Onboard a new client, Onboard an employee, Kick off a project), fill a couple of fields, and the agent proposes the whole thing as an ordered, approve-first plan, for example a client onboarding becomes a CRM contact, an onboarding project with starter tasks, and the sales opportunity, all queued together. Every step is dry-run + preflighted in Agent approvals, and nothing runs until you approve it. It is the fastest way to turn a repeatable back-office process into one reviewed click, and every action stays reversible. You can also just type it in plain English in the “Ask your agent” box (for example “onboard Acme Corp” or “kick off project Apollo”) and your agent turns the request straight into the same preflighted, approve-first plan (add the name in the form if it needs one).

Build an agent from a description: on the Agents page, managers can describe the AI teammate they want in plain English (for example “chase overdue invoices and draft polite reminders, flag anything over 60 days late”) and AI drafts the whole agent: a name, the right domain, a safe default autonomy (approve-first unless you clearly want hands-off low-risk automation), whether it should proactively look for work, and an operating playbook. It opens in the normal agent editor so you review and adjust everything before saving, and the new agent still acts approve-first under your permissions. It is rate-limited and runs on your workspace AI budget.

Preflight (will this actually run?): when you open a proposed action that creates records (for example onboard a client, or scaffold a project + tasks), the queue runs a real transactional preflight as you, it attempts the exact writes under your own permissions and every data rule, then rolls them back so nothing is saved. You get a clear green “Verified” or a red “Would fail if approved” with the reason (for example a permission or validation rule), and the Approve button is blocked when it would certainly fail. This catches the frustrating case where an action is approved and only then errors out. It is read-only, nothing is ever written by the preflight itself.

Unattended server execution (Agents page, admins, experimental, OFF by default): a step beyond auto-approve. When you turn it on and pick an accountable owner/admin to run as, the safe reversible subset (task triage, expense categorization, deal-stage moves) is not just auto-approved overnight but actually carried out with no one online. Every action runs under that person’s real permissions (row-level security is still enforced on each write), stays within an hourly cap, honours the global “Pause all agents” kill-switch, is re-checked by preflight first, and remains one-click reversible from Agent activity. Money, payroll, legal, deletes, record creation and anything higher-risk are never executed this way. They keep waiting for a human. It does nothing until an admin explicitly enables it and names the run-as principal.

You always know when Chief acts on its own: whenever unattended execution carries out low-risk work with no one online, the people who can approve get a rolled-up notification -- "Chief automatically handled N items" with the breakdown (task triage, expense categorization, deal updates) and a link straight to Agent activity to review or undo. It is deduplicated (each action is announced once), admins-only, and respects your notification preferences (toggle "Autonomous actions" under Notifications). Nothing ever happens silently.

Preflight the whole queue: the Agent approvals list has a Preflight column and a summary (for example “5 ready · 1 would fail”) so you can see at a glance which pending actions will run and which would fail, without opening each one. It runs automatically for small queues and there is a Check all pending button for larger ones. It now covers the record updates too (re-prioritise a task, categorise an expense, move a deal), catching cases where the target was changed or removed since the agent proposed it. Everything is read-only and rolled back.

New here? On the Agents page click "Add starter agents" to provision a ready-made back-office team, Task Assistant, Expense Categorizer, Support Triage, Pipeline Mover, Lead Nurturer, People Coordinator, Content Assistant, HR Coordinator and more, pre-wired with the right tools. Nothing runs until you trigger it.

Autonomy without an LLM key: switch on “Autonomous sensing” on an Accounting, Tasks, CRM or People agent and it watches your real records on a schedule (daily or hourly), uncategorized expenses, overdue tasks, stale deals, capacity risks, filing concrete proposals to the approval queue by itself, always approve-first, capped and de-duplicated. You can also click “Find work in my data” to scan on demand. An LLM key later adds free-form natural-language requests on top.

No LLM key yet? Open an agent and click "Generate sample proposal" to see the approve → roll back flow on sample data. Connect a provider key under Console ▸ AI assistant to let agents propose real actions.

Graduated autonomy: set an agent to "Auto low-risk" and its low-risk, reversible actions run automatically with no approval click, money, payroll and any medium or high-risk action still wait for a person. Every auto action is audited and one-click reversible, and cost ceilings still apply. Switch the agent back to Approve-first (or disable it) to stop auto-execution.

Unattended auto-approve (opt-in, off by default): under “Unattended autonomy” on the Agents page, admins can let an Auto low-risk agent’s low-risk + reversible proposals be auto-approved by a capped sweep. A preflight confirms each would actually succeed first. It runs on a schedule (about every ten minutes) once enabled, you set a hard per-hour cap, and “Pause all agents” is the instant global kill-switch. Money, payroll, legal, deletes and anything medium/high-risk always stay approve-first, and every auto-approval is audited and one-click reversible.

Agents live in your modules: Work, Accounting, People, CRM, HR and Support each show their own agent panel right on the module page - the agent for that module, how many proposals await approval, and a one-click "Try it". It only ever proposes; you approve, and every action stays audited and one-click reversible.

Dry run before you approve: open any proposed action and the "What will happen" panel shows the exact before→after change, anything it will create, the blast radius (records touched, whether money moves) and whether it is one-click reversible, so you approve with full sight, never a black box.

Agents take real actions, not just drafts: create and assign tasks, draft onboarding checklists, post journal entries, categorize expenses, triage tickets and support replies, move deal stages, send approved SMS, create CRM contacts and deals, scaffold a whole project with its starter tasks, onboard a new client end-to-end (contact + project + tasks), log CRM activities (calls / emails / notes), convert a qualified lead into a client, post status comments on tasks and projects, set reminders, and draft job descriptions, each one proposed, approved with a click, audited, and one-click reversible.

Permissions: "Manage agents" lets a person create and configure agents; "Approve agent actions" lets them approve, reject and roll back. Owners and admins have both. Grant them on Roles.

Activity & ROI: the Agents ▸ Activity & ROI page measures what your agents are worth, actions executed, estimated hands-on time saved, the dollar value created (at a blended hourly rate you set) net of metered agent cost, and a reliability score (how few executed actions were rolled back), broken down by domain over a 7/30/90-day window. Read-only; visible to agent managers and approvers.

Chat commands: type #task, #onboard or #expense (or your own) in any chat channel and an agent acts on it. Manage them on the Agents page (Chat commands). Add a custom #keyword mapped to an action, set who can use it (any member vs agent-managers), enable/disable. Commands are approval-gated by default. They propose an action that appears in Agent Approvals. Admins can also add custom natural-language commands (which run the AI proposer) and can mark a low-risk, reversible command as auto-run, which skips the approval click while staying audited and one-click reversible. Money and higher-risk actions can never be auto-run. Members can use member-commands (always queued for approval); only managers configure them.

Chief: live streaming, more it can create, and an access explainer: replies now stream in as Chief thinks (with visible step-by-step progress when it runs several tools for one request); it can create a company, client, lead, contact, deal, task, project, idea, risk or job posting directly from chat (asking one short question first if a required field is missing); and it can explain exactly why you can or cannot do something on a page. Ask “why can’t Dana edit invoices?” and it walks through the role, page access and any per-user override behind the answer. See Access & permissions above for the full layer-by-layer model.

Was this page useful?