Nothing runs without your yes.
An AI agent with system access needs rules. Every WeBuild agent works inside The Cage: sandboxed, approval-gated on risky actions, and auditable. This page is the spec, not a vibe.
Four action classes, four defaults
| Action class | Default state | Who approves | What's logged |
|---|---|---|---|
| Money — payments, refunds, purchases | Blocked | A named human, every time — no earned autonomy | Request, approver, amount, timestamp |
| Client communications — outbound email, SMS, chat | Draft-only | Your team, until the category earns autonomy on your sign-off | Draft, edits, final send, recipient |
| Bulk data — exports, mass updates, deletions | Blocked | A named human, every time | Scope of the operation, approver, before/after counts |
| Permissions — new access, credential changes | Blocked | The owner — never delegated | What was requested, what was granted, by whom |
Routine read-and-draft work inside the agent's lane runs freely — that's the job. The gates exist for everything that could cost money, embarrass you in front of a client, or move data at scale.
The proving run
Before go-live, every agent runs supervised: it drafts, your team approves, and every miss becomes a fix. Autonomy is granted per category — first-touch replies might earn it in week two while anything novel stays draft-only — always on your sign-off, never by default. The full process is on the Method page.
Deployment options
Your cloud region, your server, or your own hardware — local-first is the default posture, not an upsell. Data residency is a deployment choice you own: for Australian operators that typically means Australian regions, mapped against the Privacy Act 1988 and the APPs in the spec.
What WeBuild can see after handover
Nothing. The systems run in your accounts with your keys; at handover we walk you through rotating any credential we ever touched. If you keep the retainer, access is scoped to what maintenance needs, and it's logged like everything else.
The audit log
Every action an agent takes is written to a log you own. Illustration of the shape (not client data):
Security, answered plainly
No. Agents call model APIs under your accounts, and we configure zero-data-retention options where the provider offers them. Your documents and customer data stay in your systems; the spec names exactly what each agent can read and where it flows.
The agent pauses and escalates to a human — it never guesses in the dark. Because you own the system layer, the model is a plug: if a provider degrades long-term, it can be swapped, or replaced with a local model on your own hardware, without rebuilding.
Always. Every agent ships with a human escape hatch: pause it, take over a conversation, or reverse an action from the log. Autonomy is something the agent earns category by category — and something you can revoke the same way.
You can — the gate configuration is part of the handover, documented in the runbook. After handover, WeBuild has no standing access to your systems unless you choose the retainer, and even then access is scoped and logged.
Walk your IT person through it
Bring whoever owns security. We'll go gate by gate — precise answers, no marketing.
Book an intro call →30 minutes · no pitch · if AI isn't the answer, I'll say so