Security & Approval Design — Rules Enforced in Code
The AI is capable, but it operates inside guardrails it cannot cross: tiered approval gates, hard ad-spend caps, KMS-encrypted credentials, and a full audit trail — all enforced in code, not AI judgment.
- Approval gates: negative-review replies, ad budget changes, and pricing moves always require owner approval in Telegram
- Spend caps: ad spend limits are enforced by the system; the AI has no code path to exceed them
- Content hard rules: review replies can never admit legal liability, promise compensation, name staff, or argue — these cannot be configured off
- Audit trail: every action, approval, and failure is logged; failures alert with screenshots, never silently