bethatghost
Safeguards active

Built for
accountability.

This is not autonomous ghost mode. The boundaries are visible, the gates are real, and every sensitive step stays in your hands.

Four gates

Human approval, trusted-contact checks, full audit trail, and operator control.

Each safeguard exists because the failure mode it prevents is real. Together they keep the system from acting on your behalf in ways you didn't choose.
verified_user
Approval gateNothing schedules from raw AI output alone.

Every draft the AI produces starts in a pending state. It cannot be scheduled, queued, or delivered until you explicitly move it to approved. There is no setting that bypasses this. The gate exists because the gap between a good draft and the right delivery moment is a human judgment, not an algorithmic one.

  • Drafts start as pending — never auto-scheduled
  • Approval is an explicit action, not a default
  • You can revoke approval at any point before delivery
supervisor_account
Verification windowTrusted contacts can confirm or decline before sensitive deliveries move forward.

For moments where you want a second set of eyes, you can designate a trusted contact. When that rule triggers, the system pauses the scheduled delivery and requests a quiet verification check from the contact. They can confirm that the moment is right or decline, without seeing content they weren't meant to see. The delivery only moves forward on confirmation.

  • Trusted contacts are asked to verify, not recipients
  • Verification checks do not reveal message content
  • A declined verification cancels the delivery cleanly
history
Traceable historyEvery draft, rationale, and delivery event stays inspectable.

The audit log records what changed, when, and why. When you approve a draft you can attach a rationale note — a short explanation of why this version felt right. That note travels with the record. If something ever needs to be revisited, the full chain of decisions is there to read.

  • Draft changes are versioned with timestamps
  • Rationale notes attach to approval events
  • Delivery attempts and outcomes are logged
tune
Operator controlDeliveries can be rescheduled, retried, pulled forward, or cancelled instead of disappearing into automation.

The queue is always visible. Every scheduled delivery shows its status, pending verification, waiting for its delivery time, or in retry after a failed attempt. You can intervene at any stage. Rescheduling moves the delivery cleanly. Pulling it forward moves it up without losing the audit trail. Cancelling stops it before delivery. Nothing runs silently in the background.

  • All active deliveries are visible in the queue
  • Reschedule, retry, pull forward, or cancel from the operator view
  • Failed deliveries surface for your attention, not silent retries

What the safeguards protect

No auto-schedule from AI outputTrusted-contact confirmationFull audit trailOperator delivery controlExplicit approval states