Dry-run first: why we never let an AI agent act on day one
The unsettling version of business AI is the one that starts doing things the moment you switch it on — messaging your customers, moving your data, acting on a judgement you haven't seen it make yet. That fear is reasonable. It is also the specific thing we designed out. Every Sustainable Agent begins in dry-run: it does all the thinking and drafts every action, but sends nothing.
What dry-run actually means
In dry-run the agent runs its full workflow, start to finish, on your real work. It reads the inbox, updates its view of the world, and prepares exactly the messages, updates, and actions it would take. Then it holds every outbound one. You get to read a whole week of what the agent would have done — the actual drafts, in context — before a single thing leaves the building. You are hiring on a work sample, not a promise.
Who flips the switch
You do. Not the agent, not us. Dry-run is turned off by the owner and only the owner. And "off" is not a blank cheque: even once an agent is live, the actions that carry real weight — spending money, sending a commitment or contract, contacting someone for the first time — stay individually gated behind your one-tap approval, forever. Those can't be batched away.
Why this order matters
Trust in software should be earned the same way you'd earn it in a new hire: by watching the work, not by reading the brochure. Dry-run makes that possible. By the time you flip the switch, you are not taking our word for anything — you have already seen the agent do the job.
A constraint, not a hope
The important part: this isn't a setting we trust the model to respect. Dry-run and the approval gates live in the control plane that sits between the agent and the outside world. If the agent tries to send while it is held, the system refuses and logs the attempt. The safe version isn't the well-behaved version — it is the only version available.
More on how the supervision works lives on our Trust & supervision page.