AI AGENTCONCIERGE

SERVICE BOUNDARIES & DISCLOSURES

Clear expectations.
A better working relationship.

A custom build needs a clear agreement about what it can do, what it can access and how it will be looked after.

Review draft · September 7, 2026 · This overview does not replace a client-specific agreement or a privacy notice.

01 / AGREED BEFORE ACTION

Useful access.
Clear limits.

Discovery identifies possibilities; it does not grant permission. Before a workflow goes live, its tools, accounts, allowed actions and approval requirements need to be recorded and accepted.

  1. PROPOSE

    A useful workflow or improvement

  2. AGREE

    Scope, access, cost and review rules

  3. TEST

    Expected results and denied actions

  4. ENABLE

    Only the accepted configuration

Some actions may have standing authorization; others require approval each time. A request to draft an email is not automatically approval to send it. Payments, publication and changes to live systems need explicit rules in the build.

Instructions to an agent and technical restrictions are different safeguards. What the agent is told not to do is not the same as what its credentials or environment make impossible. We describe the controls actually tested for the configuration.

02 / KNOW WHERE INFORMATION GOES

Privacy is part of the build.
Not one blanket setting.

Each client supplies their own provider subscription and authorizes their own connected accounts. A separate workspace is only one part of the design: model providers, connectors, backups, logs and maintenance access also matter.

YOUR APPROVED SOURCESBusiness informationOnly the systems and data in scope
YOUR AGENT WORKSPACEWork & useful contextConfigured storage and permissions
SELECTED PROVIDERSModels & connectorsInformation needed for approved processing
Illustrative data path—not a claim that every build uses these services or that all processing stays on the server. The actual destinations and access are documented for the client.
What should my data and access record cover?
  • Which information is stored in the workspace or memory and which information is sent to each selected provider or connector.
  • Who can access operational records, backups, conversations or secrets, including any approved support or emergency access.
  • Retention periods, memory correction, export and offboarding arrangements—including what deletion can and cannot remove from third-party systems.
  • Additional restrictions or specialist review needed for sensitive information.

These details must be settled for your configuration; this page does not claim zero retention or operator-inaccessible conversations.

Does a business subscription settle privacy?

A suitable business plan can improve the provider-side privacy terms. For example, OpenAI says its business products are not used for model training by default. That commitment has a defined scope; it is not a guarantee about every connected service, retained record or support process.

We review the selected plan, authentication method and current provider terms for the proposed build. Read OpenAI’s business data policy.

03 / A BUILD AND AN ONGOING SERVICE

Know what is included.
Know what needs a new decision.

Initial build

Discovery, design, configuration, agreed connections, testing and onboarding. The deliverables and acceptance criteria belong in the proposal.

Ongoing care

The agreed patching, security maintenance, connector upkeep and upgrades. Support channels, hours, response targets and exclusions need to be stated—not assumed.

Your subscriptions

Provider plans and other third-party charges are identified separately. Usage limits, service availability and authentication changes can affect the workflow.

We handle setup and the agreed technical care. You are not expected to build the agent yourself. Some account verification, consent or reauthorization may still need you as the account owner.

A suggestion is not a charge or permission to expand the build. New integrations, substantial development or changed service needs are reviewed together, with any scope or price change agreed before work proceeds.

Always available as a design aim does not mean guaranteed uninterrupted operation. Recovery, monitoring and backup commitments depend on the agreed service; this page makes no uptime or response-time guarantee.

04 / EVIDENCE WITHOUT OVERREACH

Review the result.
Keep the claims grounded.

AI can make mistakes, omit details or misinterpret a request. Review important outputs and use qualified professional judgment where the work requires it. Examples on this site are illustrative unless explicitly identified otherwise; they are not guaranteed outcomes.

Time saved is an estimate unless measured against a defined baseline. We distinguish recurring work, one-time setup and new capability, and account for the owner’s review and correction time.

Container tests describe the tested container configuration. They do not establish the isolation of a future VPS or VM deployment. Production readiness requires checks against the environment and access paths actually delivered.

See the current evidence and its limits

Before we start

The client-specific packet needs an accepted scope, access and data record, commercial terms, support and recovery arrangements, and ownership, export and offboarding provisions. Unresolved choices remain open for agreement; the website does not settle them by implication.

Discuss a scoped pilot