Controls by design
Each of these is built into how the system works, rather than a setting we switch on for you.
"What if it sends something wrong to a client?"
Wrong pricing, wrong tone, confidential info in the wrong thread. One bad email to a key client and years of trust are gone.
Client-facing sends wait for your approval.
Lilla drafts. It lands in your queue. You read it and you send it. That is how every account starts, and nothing widens it unless you ask us to.
"What if it makes a financial mistake?"
Pays the wrong invoice, applies the wrong discount. For an SME, a $5K error isn't a rounding error.
Lilla doesn't process payments or execute transactions.
It prepares and routes for approval. You authorise. Money never moves without a human.
"What if it does irreversible damage?"
Deleted files, overwritten data, sent replies you can't take back. Irreversible actions with no safety net.
Lilla cannot delete. Ever.
Archive only. Every action logged, so you can see what happened and when.
Two kinds of control.
A policy decides what an agent may do at all. An approval decides whether this one goes out. Client emails and invoices start behind an approval.
Thanks for the order. Invoice 1042 is attached, due 30 days from today. Shipping confirmation follows once the container is booked.
Permission is set per action.
Connecting Gmail gives Lilla the same access it would give any tool. Nothing runs on that access until a policy says it can.
| Job | System | Capability | Policy |
|---|---|---|---|
Read your inbox | Gmail | read | allow |
Share a file with someone | Google Drive | write | approval required |
Email a client | send | approval required | |
Delete an email | Gmail | delete | blocked |