Skip to content
The Cage — security spec

Nothing runs without your yes.

An AI agent with system access needs rules. Every WeBuild agent works inside The Cage: sandboxed, approval-gated on risky actions, and auditable. This page is the spec, not a vibe.

The gates

Four action classes, four defaults

Action class Default state Who approves What's logged
Money — payments, refunds, purchasesBlockedA named human, every time — no earned autonomyRequest, approver, amount, timestamp
Client communications — outbound email, SMS, chatDraft-onlyYour team, until the category earns autonomy on your sign-offDraft, edits, final send, recipient
Bulk data — exports, mass updates, deletionsBlockedA named human, every timeScope of the operation, approver, before/after counts
Permissions — new access, credential changesBlockedThe owner — never delegatedWhat was requested, what was granted, by whom

Routine read-and-draft work inside the agent's lane runs freely — that's the job. The gates exist for everything that could cost money, embarrass you in front of a client, or move data at scale.

The proving run

Before go-live, every agent runs supervised: it drafts, your team approves, and every miss becomes a fix. Autonomy is granted per category — first-touch replies might earn it in week two while anything novel stays draft-only — always on your sign-off, never by default. The full process is on the Method page.

Deployment options

Your cloud region, your server, or your own hardware — local-first is the default posture, not an upsell. Data residency is a deployment choice you own: for Australian operators that typically means Australian regions, mapped against the Privacy Act 1988 and the APPs in the spec.

What WeBuild can see after handover

Nothing. The systems run in your accounts with your keys; at handover we walk you through rotating any credential we ever touched. If you keep the retainer, access is scoped to what maintenance needs, and it's logged like everything else.

The audit log

Every action an agent takes is written to a log you own. Illustration of the shape (not client data):

09:14 read inbound · lead@example.com
09:14 drafted reply · queued for approval
09:31 approved by S. · sent
09:31 CRM updated · stage → contacted
10:02 refund request · BLOCKED — gate: money · escalated
Questions

Security, answered plainly

No. Agents call model APIs under your accounts, and we configure zero-data-retention options where the provider offers them. Your documents and customer data stay in your systems; the spec names exactly what each agent can read and where it flows.

The agent pauses and escalates to a human — it never guesses in the dark. Because you own the system layer, the model is a plug: if a provider degrades long-term, it can be swapped, or replaced with a local model on your own hardware, without rebuilding.

Always. Every agent ships with a human escape hatch: pause it, take over a conversation, or reverse an action from the log. Autonomy is something the agent earns category by category — and something you can revoke the same way.

You can — the gate configuration is part of the handover, documented in the runbook. After handover, WeBuild has no standing access to your systems unless you choose the retainer, and even then access is scoped and logged.

Walk your IT person through it

Bring whoever owns security. We'll go gate by gate — precise answers, no marketing.

Book an intro call →

30 minutes · no pitch · if AI isn't the answer, I'll say so