trust you can inspect
Easy to do the right thing.Hard to do the wrong one.
The same system that makes an action easy has to make a wrong one hard. These are the limits you'll set, and the checks we'll enforce either way.
the problem today
All or nothing.That's how refund access usually works.
Giving a team or an AI the power to refund usually means giving them all of it.
Limits that live in someone's head fail on the busiest day.
And a single dollar figure can't govern shops that sell in different currencies.
what you'll set
Four kinds of limit.
- 1A switch per actionEleven actions, each with its own switch. The three riskiest start off.
- 2Ceilings per actorDifferent ceilings for Fin, agents, workflows and API keys, set per shop and in that shop's currency.
- 3Above a ceiling, the action isn't offeredThe case is handed over in Intercom to someone whose ceiling covers it. There is no separate approval queue.
- 4Two stop controlsOne halts all writes. One halts reaching out to buyers. Neither disconnects your shop.
- Agentceiling $200action not offered
- Team leadceiling $500handed over in Intercom
No separate approval queue: the case moves to someone whose ceiling covers it.
not settings, rules
What we check, every time.
These run on every action from every caller: an agent in the panel, Fin, a workflow, a macro, or your own system through the API. One implementation, not five.
- 1This buyer really owns this order
- 2TikTok still allows this action, checked at the moment of acting
- 3You have switched this action on
- 4The value is within the ceiling
- 5Any required reason or evidence is present
- 6Any required confirmation was actually given
- 7The same action has not already been done
- 8Everything is recorded
fair is fair
If something goes wrong.
- If you need to stop everything, use the stop control. Writes halt, reading carries on, and the shop stays connected.
- If a limit is set too high, the audit trail shows it, by person and by shop.
- If someone worries a rule might be skipped: the checks run in one place, for every caller, and can't be switched off.
boundaries, on purpose
What this does not do.
No named-approver workflow
Above a ceiling the action is absent, and the case moves to someone whose ceiling covers it.
No unsupervised AI
Fin acts only within limits you set, after explicit buyer confirmation.
No bulk approval
One decision, one person, one record.
short answers
Questions about limits.
The three riskiest actions start off until you switch them on. Every action has its own switch, so you can turn off any of the others too.
Yes. Ceilings are set per shop, in that shop's currency.
No. It halts writes, or halts outreach to buyers. The shop stays connected and reading carries on.
goes well with
Related.
Automation you canswitch off in one place.
Messages work today. Per-action switches come with refunds; ceilings and the stop controls come later. The shops that join now get a say in what ships first.