What the AI is allowed to decide
- Pulling the order number out of what the customer typed
- Choosing which help article actually answers the question
- Writing the reply, inside the tone and the constraints you set
You write how a refund, a delivery question or a cancellation should be handled, in the words you would use training a new person. Aqvitus turns that into steps it executes exactly — and the AI does not get to change them mid-conversation.
This is the whole difference between an assistant that sometimes does the right thing and a worker you can put in front of customers.
“If someone asks for a refund, check their email is verified, find the order, and refund it if it is inside 30 days. Tell them when the money lands.”
“That’s refunded — $48.00 back to your card, and it will be with you tomorrow morning.”
Example data. A blocked reply stops the run where it is — no later step executes, and the text travels with it so whoever picks it up can see what the AI wanted to say.
Versions are frozen once written. A procedure moves from draft to a simulation, then shadows live traffic without sending anything, then runs for a small percentage of conversations before it runs for all of them — and a conversation that started on version 14 finishes on version 14. How many procedures a workspace can hold depends on your plan — see pricing.
Before an outbound message leaves — whether the lane would send it automatically or a person is about to approve it — a separate check reads it. Six questions, and what happens when the answer is no.
Each claim has to trace to a source, a tool result, a learned answer or a template. An invented delivery date fails here.
Amounts, timelines, discounts, legal, medical or tax advice. Two strikes and the conversation goes to a person.
Your tone, your brand voice, your banned phrases. It gets one attempt to rewrite itself, then it steps down.
Unmasked personal data, another customer’s details, internal-only content. This one blocks the send outright and raises an alert.
A composite score against the floor you set, not the AI’s own opinion of itself alone.
If somebody whispered an instruction into this turn, the reply has to follow it, or the supervisor is asked to step in.
A failed check moves the conversation one step toward a person rather than swallowing the problem. When a reply is blocked the run stops right there — no later step executes and no action is proposed — and the blocked text travels with it, so whoever picks it up can see exactly what the AI wanted to say and why it was not allowed to.
Editing a procedure, a rule or your knowledge is a change to how customers are treated. You should be able to see what it would have done.
Run real past conversations through the whole pipeline with the change in place. Tool calls are dry runs against recorded results, so nothing is refunded and nobody is emailed. How far back you can replay depends on your plan.
Let the change run alongside live traffic, computing what it would have said and sent — without saying or sending any of it.
On Business and Enterprise, give the change a small percentage of real conversations and let it stop itself the moment a gate slips.
A procedure, a prompt, a rule set, the autonomy matrix, the model routing table or a knowledge snapshot — the same gates apply to all of them, and the results are kept as events you can look at later. There is a command-line entry point too, so this can sit in the same pipeline as the rest of your engineering.
Replay depth and canary rollout depend on your plan — see pricing.
Nothing in Aqvitus is built around one AI vendor. Every job the platform does — classifying, pulling values out of text, answering, judging an answer, embedding, transcribing a call, speaking — is a task class, and a table you control says which model does which.
We hold the model keys and the routing table ships configured. Nothing to set up.
Your provider accounts, your rates. Model spend passes through at cost and stays attributable per task.
Self-hosted, with classifying, extracting and embedding on local open-weight models. Where nothing may leave, that is verifiable rather than promised.
Change a model for one task class and it is a change like any other: it runs the six gates first. Every call records what it cost, how long it took and which provider served it, so the bill is attributable rather than a single line at the end of the month.
Agent Studio is where the procedures, the training material, the sandbox, the persona and the autonomy matrix all live.
A sandbox chat against recorded results. Pick a persona, a verification level and the procedure you are testing; every reply shows its lane, its confidence and what the checker said. Save a good case as a test.
Tone and length sliders that rewrite a sample reply as you move them, banned phrases as chips, and an AI disclosure on the first message that cannot be switched off.
Which sources are connected and how fresh they are, how well your intents are covered, and the learned answers waiting for review.
The matrix itself: intent by intent, which lane, and what confidence it takes to get there. Route cannot be loosened by a slider.
What the AI answers from, and how the gaps get filled.
KnowledgeThe rules that decide which of its actions need a person.
ApprovalsTriggers and SLAs around the conversation the AI is having.
WorkflowsWhat it actually resolved, and how well it was written.
Analytics
Put the AI in front of every conversation, and keep your team in charge of everything that matters.