The fear is reasonable. You hand real work to an AI and one afternoon it sends a customer the wrong price, or an email you would never have written, or it changes a record and nobody knows until the accountant asks.
Safe AI for business is not about a smarter model. Every model makes mistakes. Safety comes from how the work is structured around it: what it can draft, who approves, what gets recorded, what it can see, and how your business is kept separate from everyone else’s. Here is how the approval-first way works at TAO.
The one rule
Andy drafts. A person approves. Then it goes out.
That is the whole rule, and everything else follows from it. Andy does the doing: the reply, the quote, the invoice, the booking, the reminder. But every message it sends and every change it makes passes through a person on your team before it leaves. Andy does not have a way around this. It is not a setting that can be forgotten.
In practice that means your team’s day is mostly reading drafts and tapping approve, changing a line where it matters. The work happens fast. The judgement stays human.
It also means the approval is real. A draft is not a notification you can swipe away. It sits in the queue until someone on your team reads it, and Andy does not move on to sending until they do.
What approval actually covers
People sometimes assume approval means emails only. It means anything that leaves the business or changes it.
- Emails, replies and reminders to customers and suppliers.
- Quotes, including revisions.
- Invoices raised in your accounting software, and the reminders that chase them.
- Bookings and calendar invites that go to people outside the team.
- Changes to records in the systems TAO connects to.
Answers to your own team inside TAO can flow without an approval step, because nothing has left the business. You decide where the line sits, and it is set during Discovery, not discovered later.
The audit trail
Every action Andy takes is recorded: what it drafted, what it drew on, who approved it, what changed, and when. Every answer shows its source, so if Andy says the balance is due seven days before the event, you can see the document or thread it learned that from.
This matters for two reasons. When something is wrong, you can find out why in a minute instead of an afternoon. And when something is right, the whole team can see how the decision was made, which is how trust in the system is built. Nobody is asked to trust a black box.
The trail also covers what Andy chose not to do. If a step was skipped because a rule said so, that is recorded too.
Who sees what
Permissions
A business has people who should see everything and people who should see their own jobs. TAO’s permissions work the way you would expect from a serious system: roles decide what each person can see and do, and Andy works within the permissions of the person it is working for.
So when a member of the crew asks Andy about a client’s deposit, Andy answers within what that person is allowed to see. When the owner asks, the answer can be fuller. The same assistant, bounded by the same rules you set for your people. Permissions are set during Discovery, alongside the approval rules, so the people who should see everything do, and the people who should see their own jobs see exactly that. The detail is on Data and permissions.
Isolation
Your company brain is yours. It is built from your documents, your history and your decisions, and it is kept separate from every other business on TAO. Nothing learned from your business is used to answer another business’s questions.
The systems TAO connects to are connected through their official access, with the specific permissions the connection needs, and you can revoke that access from inside the system at any time. There are no shared passwords and no screen scraping. What Andy can touch is explicit. The full list of what connects is on Integrations.
SOC 2, honestly
SOC 2 is in progress. We say it that way because that is what is true, and because a business making decisions about its data deserves plain language. The controls that matter day to day, approval before anything leaves, a full audit trail, role-based permissions and isolation between customers, are already how TAO works. The formal attestation follows the process. Security has the current detail.
What good looks like day to day
Take an illustrative events hire company. The morning starts with a list of drafts: three quotes from overnight enquiries, a deposit invoice from a quote accepted yesterday, two reminders due today, and one notice that a run sheet has no confirmed delivery time.
The office manager reads each one, changes a delivery window, approves the rest, and is done in fifteen minutes. Andy sends what was approved, raises what was approved, and books what was approved. The audit trail records all of it. Nothing left the building without a person saying so, and the whole team can see what went out.
Two of the quotes go out as drafted. The third gets a line changed, because the manager knows that venue charges for after-hours access, and that correction becomes part of the company brain for next time.
Questions to ask any AI vendor
If you are comparing options, these are the questions that separate safe from not.
- Can it send anything without a person approving it? If yes, how do you turn that off, and can it be turned back on by mistake?
- Does every answer show its source?
- Is there an audit trail of every action, including who approved it?
- Do permissions follow the person, or does the AI see everything?
- Is my data isolated from other customers, and is that a promise or a setting?
- How does it connect to my systems, and can I revoke that access myself?
The honest answers to those questions matter more than any demo.
Approval-first is not a brake on the work. It is what makes it possible to hand the work over at all. A business that can see everything its assistant does, and has the last word on everything that leaves, can let the assistant do a great deal. That is the difference between AI you have to watch and AI you can rely on.
If you want to see the approval flow on a real job, book a discovery call. Bring the thing you would least want an AI to get wrong, and we will show you where the person sits in the loop.
Questions people ask
Can Andy send an email or an invoice without approval?
No. Andy drafts, a person approves, then it goes out. That applies to everything that leaves the business or changes a record.
Can I see what Andy did and why?
Yes. Every action is recorded with what was drafted, the source it drew on, who approved it and what changed.
Is TAO SOC 2 certified?
SOC 2 is in progress. The day-to-day controls, approvals, audit trail, permissions and isolation, are already in place.
Is my company brain shared with other TAO customers?
No. Your company brain is built from your business and kept separate from every other customer.



