These guides describe the full platform, which opens in a few days. Today you can try Instant Chat.
All documentationEvidence and control
Agentic AI Planning Safety: Human Control and Boundaries
- 1Define the boundary
- 2Review proposed changes
- 3Keep people accountable
Planning and security review support decisions; they do not certify compliance.
The app supports early discovery and planning. It makes uncertainty and control boundaries visible so a polished artifact is not mistaken for implementation approval.
Evidence before confidence
AI-generated wording can organize, summarize, and challenge evidence. It does not make an unsupported claim true. Public website research is useful for public company context but usually cannot confirm internal processes, data quality, decision boundaries, governance, costs, or implementation readiness.
Readiness and Agentic ROI retain unknown, unvalidated, estimated, and missing-baseline states rather than filling them with invented certainty.
Human control over changes
Chat mode keeps individual changes behind Apply actions. Guided always asks before applying: the Whole Canvas proposes an update for one saved gap at a time, and a section run produces a proposal that waits for Apply Action. Whole-Canvas Agent begins only after the user starts a bounded run, displays its steps, and provides Stop. Section Agent performs one explicitly started bounded orchestrator pass and then stops.
These modes can update the current Canvas within their defined scope. They do not authorize external communication, production deployment, unrestricted tool use, or indefinite background operation. Ordinary assessment and output chats explain the work without editing the Canvas. ROI chat can save explicit answers to the active baseline question and apply reviewed baseline proposals; it cannot edit authored Canvas sections. Optional Run the agents proof actions require their own explicit approval.
Peer benchmark data
When a saved Canvas has an AI Readiness assessment and sector, the service contributes a limited record to an anonymized cross-Canvas benchmark corpus. The record contains sector, optional project type, overall and dimension readiness scores, limited outcome metadata, and a timestamp. It does not contain the user id, company name, or free-text Canvas content.
Comparative statistics appear only after a minimum same-sector sample exists. Below that threshold, the product labels the benchmark as directional instead of presenting a cohort average or percentile as established fact.
Security and regulatory guidance
The Security Review is a high-level AI-generated planning aid. Regulations suggested from limited Canvas evidence may be incomplete or inapplicable. The review is not legal advice, certification, security testing, or authorization to process sensitive data.
Before implementation, the team should confirm data classification, access, retention, audit, human override, incident response, vendor, model, jurisdiction, and regulatory requirements with qualified owners.
Generated artifacts are decision aids
Summaries, Slides, Blueprint, Workflow, AI Readiness, Agentic ROI, and Security Review support different conversations. None proves that the underlying operation is correctly modeled or that an AI system is safe to deploy. Material assumptions should be reviewed at the Canvas and source level.
To write the limits down for one project, use the agentic AI implementation plan and check the team with the agentic AI readiness checklist. For how the Brain treats evidence, see using the Agentic Brain, and for the wider method, the planning framework.
Frequently asked questions
Who approves what an AI agent does?
In Canvas, a person does. Chat mode keeps changes behind Apply actions, Guided mode always asks before applying, and bounded agent runs show their steps and provide Stop. None of them authorize external communication or production deployment.
What permissions should an AI agent have?
Decide this per project, in three lists: what the agent may do alone, what it must ask a person to approve, and what it must never do. The implementation plan template has a row for each.
Does Canvas enforce permissions on an agent?
No. Canvas is for planning. It records the limits you set and keeps them visible. It is not a hosted production runtime, and an external workflow you deploy needs its own review.
What is human control in agentic AI?
A named person decides what the agent may change, reviews what it produces and can stop it. Planning is where those decisions are written down.
Current product boundary
The current Agentic Brain is a descriptive, updateable operating model. It is not a live digital twin synchronized with operational telemetry. Optional execution previews are disabled by default. Where enabled, in-app rehearsal is simulated and uses no live tools. Evaluation and deployment have separate prerequisites and explicit actions.
Deployment targets an n8n instance the user controls. Its actual integrations, credentials, permitted actions and operating controls require separate review; Canvas planning-mode boundaries are not a universal prohibition on what that external workflow can do. The app is not a hosted production runtime. Review the execution preview limits before using those paths.
For a worked planning example of approval gates and evidence, see the AI governance planning path.
Return to the documentation index.