Permission is a role, not a habit
Five roles, and a permission grid your workspace can override line by line. A permission introduced later arrives with a stated default rather than appearing unnoticed on someone's account.
Governance
An autonomous system acting under your name is a governance question before it is a technology question. This page is the answer: what it may do, who decided, what is written down, where the ceilings sit, and how it is stopped. Every claim below is a mechanism.
Today, on one account
Owner setThe run stops here. It does not borrow against tomorrow to finish what it started, and an account limit overrides the workspace default rather than the reverse.
Spacing
One write at a time, with a minimum gap and a jitter inside a ceiling you set. A restart does not release a queue in one burst.
Running unattended
Every judgement it makes is written down with its reason.
Autonomy is acceptable only when every decision is attributable to a named authority, a pinned version and a written reason — and the record cannot be edited afterwards.
What it looks like on the day
Every governance claim is a promise about a specific bad hour. These are the hours.
Without
The system skips someone you would have wanted. You are shown a score of 41 and a model name.
With dAiLink
The rejection carries the verdict, the confidence, the score against each criterion, the sentences that produced it, and the field each claim was drawn from. You can disagree with it in particular rather than in general.
Without
You say stop. The status field changes, and the messages already queued go out over the following hour.
With dAiLink
The stop is written before the machinery is asked to obey it. A failed halt cannot erase your decision, and a run belonging to a stopped workflow is refused at the next step it tries to take.
Without
Someone accepts your request while a follow-up is queued behind it. They receive a message written for a stranger.
With dAiLink
Acceptance cancels the queued follow-up, and the check runs once more in the instant before the attempt — so the race between accepting and sending is closed rather than tolerated.
Without
The provider times out mid-send. The system retries, and one person receives the same message twice — or it is marked failed and quietly never sent.
With dAiLink
The attempt is marked ambiguous and reconciled against what actually happened. The system will not assume it acted, and will not assume it didn't.
Without
You revise the instructions on Tuesday. Work already under way silently starts behaving differently, and last week's decisions can no longer be explained.
With dAiLink
Each run holds the version it started on. Each past judgement names the instruction version that produced it, and that version cannot be deleted while the decision still refers to it. The log itself accepts no edits at all.
01
Nothing acts on its own account. Every capability the system has was granted by a named person, and the grant is itself a record.

Five roles, and a permission grid your workspace can override line by line. A permission introduced later arrives with a stated default rather than appearing unnoticed on someone's account.
Where you require sign-off, it is a point the work must pass through. The first decision takes a lock and is written with the identity of the person who made it; every later attempt returns that same decision rather than creating a second one. An approval nobody answers expires on a stated schedule, and you decide in advance whether silence means proceed, decline or halt.
No client holds direct write permission on any table. Every change passes through a function that re-verifies who is asking and which workspace they belong to before it touches a row.
Every change to an account's ceiling is stored with the person who made it, where it came from — a preset, a manual override, a derating, a reset — the values before and after, and whether a high-risk change was acknowledged at the time.
Isolation is enforced at the row rather than in the application. The tenant travels inside the foreign keys, so a record belonging to two workspaces cannot be constructed even by privileged code. The table holding resume tokens has no read policy at all, for anyone.
02
What comes back is not a list of actions taken. It is an account of judgements made, each one legible enough to be argued with.

Each individual the system considered carries a verdict, a score, a confidence, a score against each criterion it was measured on, and the sentences that produced the decision. Rejections are kept in the same detail as acceptances, because the rejections are where you learn whether the profile is right.
Each claim in an evaluation is stored against the field it was drawn from, and what the system could not establish is recorded as missing rather than assumed. You are reading a case, not a number.
Every evaluation names the version of the profile and the instruction set in force when it was made, alongside a hash of the individual's profile as it then stood. An instruction version cannot be deleted while a decision still refers to it. Editing the instructions does not alter work already under way — a run keeps the version it started on.
Generated messages are stored with the model, the grounding facts the model was given, and a record of how many attempts were made and why the earlier ones were refused.
The audit table accepts inserts and nothing else. An update or a delete is rejected by the database itself, not by a convention someone can decide to skip on a difficult afternoon.
03
A ceiling is only a ceiling if it is checked in the instant of the act. These are.

An account's daily allowance is consumed atomically in the moment before the attempt is made — never when the work is planned, queued or drafted. A step that fails costs nothing, and a step that runs cannot have been over the line.
Where an account carries its own limit, it wins over the workspace default rather than being averaged against it. The order is fixed: your override, then your stored setting, then the preset.
Each account has a single serialised write clock, with a minimum spacing between actions and jitter inside a ceiling you set. Starts are staggered and the next due time is stored, so a restart does not release a queue in one burst.
Messages are generated only from facts about the individual being written to, held under a hard length limit, and screened for links and the language of discounts and guarantees. The model is instructed never to invent a fact about you. A draft that fails the screen is rejected with the reason recorded, then written again.
Every draft is normalised and compared against the last hundred of its kind sent from that account. A repeat is a rejection, not a send.
04
The measure of a stop is what happens to the work that had already begun.

A stop marks the run cancelled first and halts the machinery second. If the halt itself fails, your decision still stands, and a run belonging to a workflow that is no longer active is refused at the next step it attempts to take.
Disabling an account sets its daily starts to zero and causes its write clock to refuse a slot. Nothing further is planned, and nothing further is granted the right to act.
The moment someone accepts, the follow-ups already waiting for them are cancelled. The check runs before dispatch and again in the instant before the attempt, which closes the gap between the two.
A write has three outcomes, not two: succeeded, failed, and ambiguous. An attempt that may or may not have landed is marked ambiguous and reconciled against what actually happened before anything is decided on top of it.
A first approach is registered against the individual and the account before anything is drafted, under a constraint the database will not allow to be broken. A step that has already succeeded is replayed from its recorded result rather than run again, and a lease prevents two workers taking the same step at the same moment.
Every judgement made in your name is one you can open, trace to its version, and argue with.