afkaOne AI Brain across support, sales, recruiting and the store, every action gated and on the record
Standard

Built to an operating standard.

Every afka agent ships against a twelve-point operating standard with an automated go-live gate: pass or fail, no partial credit. The controls that let an agent touch money and customers are not promised in a deck. They are enforced in code, measured, and checkable.

Trust that is checkable, not promised.
By the numbers
12

Points, gated pass/fail
Twelve requirements every agent clears before it goes live to a workspace. One failed point is a release failure, whatever the eval score.
<60s

Measured time to stop
Hit pause and the agent provably cannot act. We measure it, not assert it: the median is a fraction of a second, the worst case we've clocked is a couple of seconds.
5

Questions on every action
Who started it, which agent ran it, what data it touched, what changed, and why it was allowed. Written append-only to an audit log you control.
The standard

Twelve things that are true of every agent.

The standard is four promises. Every point below is enforced in code and checked at the go-live gate, not written on a slide.

Scoped on day one, and it stays scoped.
R1

Its own identity

Every agent is a governed non-human identity with its own scoped credentials per tool and per action. Tokens live in an encrypted vault, never in prompts, never in logs.

R2

Least privilege

The support agent can read orders and draft refunds. It cannot touch payroll. Permissions are the floor of what it can do, not a suggestion it can talk its way past.

R3

Asked to overreach, it refuses

An agent told to do something outside its permissions refuses and offers the gated path instead. An executed out-of-scope action is an automatic release failure.

Money and irreversible actions always stop for a human.
R4

Autonomy is a dial you set

Suggest, Review or Auto, per action type. It starts conservative and earns more only as trust proves out. You sell control first, automation second.

R5

Standing instructions, quoted back

Ask it to watch something and it holds your ask verbatim. When the condition fires it comes back quoting your original words, never a paraphrase.

R6

Hard caps live in code

Limits like $100 per refund and $500 per day are enforced by the runtime, not by asking the model nicely. Above the cap, it always waits for you.

Everything it does is inspectable.
R7

Five-question audit

Every action answers who initiated it, which agent ran it, what data it touched, what changed and why it was allowed. Append-only, and yours to read.

R8

Evidence, not assertion

When it flags something, the finding carries the evidence: the value, the baseline it's measured against, the window. You can inspect the reason, not just the alert.

R9

Durable, replayable runs

Every step is checkpointed; a failed step never double-executes a side effect. The blast radius of a failure is a task to rerun, not money lost.

It degrades safely, and it never spams you.
R10

A bad model day costs it autonomy

Quality is scored continuously per workspace. When it drifts, the affected action class is automatically tightened back to Review until a human clears it.

R11

Stop in seconds, measured

Pause is a first-class state. Pending approvals cancel in the same transaction, the in-flight run is torn down, and every step re-checks the pause and fails closed.

R12

Anti-noise by contract

A materiality floor, a daily cap ranked by dollar impact, one card per persisting issue, quiet hours in your timezone. A quiet day is reported as a healthy day, never padded.

Checkable

The trust is checkable, not promised.

Three of the twelve, enforced right now, not in a prompt, not on a roadmap. This is why an SMB can hand an agent money-moving actions on day one.

Refuses out of scope
Asked to do something outside its permissions, the agent refuses and offers the gated path. An executed out-of-scope action fails the release, whatever the eval score.
$100 / $500 caps
Per-refund and per-day limits live in code. The five-question audit records who, which agent, what data, what changed, and why it was allowed.
Provably stopped
When you pause an agent, we measure the time until it provably cannot act. Median under a fraction of a second; worst case, a couple of seconds.
In your hands

You're always in control.

Pause an agent and it stops in seconds. Queued work waits and resumes exactly where it left off when you turn it back on. Nothing it has already done can be edited, and it all stays in the audit log. The same control strip you see on every agent runs to the standard on this page.

Live agent
Five questions

Every action answers five questions.

Not a log dump. A record built so any action an agent took can be understood, traced and reversed where the tool allows.

One row of the audit log, in plain words.
Who
Started by a member, on a schedule, or triggered by an event
Which agent
The named non-human identity that executed it
What data
The records and tools the action touched
What changed
The before and after of the action itself
Why allowed
The permission and autonomy tier that let it run
Autonomy

Control first. Automation second.

Every agent runs at the tier you set, per action type, and earns more autonomy only as it proves out. Change the tier and what it can do on its own changes with it.

SuggestDrafts everything and waits. Nothing is sent or changed until you do it yourself.
ReviewActs on its own, but holds anything sensitive, refunds, sends, writes, for your approval first.
AutoRuns end-to-end within the rules you set. You are notified after the fact, not asked.

AI agents you can actually trust.

Hire your first agent, set the autonomy, and watch finished work come back, every action scoped, gated, measured and logged to the standard.