The AI you can show an auditor.
Every AI call runs through the same actions your team calls. Inherits your permissions. Every step in the same audit log. Never bypasses dangerous: true.
Every call in the audit log
AI tool calls land in the same audit log the UI writes to. Actor + input + result + latency, retained per your plan. Attributed to the delegating operator, not a bot user.
Inherits your permissions
AI tokens can only be further restricted, never expanded. The AI sees exactly what its delegating user sees — and no more. No shadow admin, no bypass path.
Confirms dangerous actions
Any action flagged `dangerous: true` requires human confirmation. The AI runtime enforces the gate — the agent cannot bypass it, no matter what a prompt asks.
Same buttons. Same rules. Same record.
The AI does not get a private back door into your data. It uses the product, exactly as a member of your team would — which is also why every new feature works with it on day one.
- Someone clicks a buttonA person, in the app
- Or the AI does itThe same button
- Same rules applyPermissions checked either way
- Same record keptWho did it, when, and what changed
Three autonomy levels. You pick which.
The product ships the Cursor pattern — Ask, Propose, Execute. Per organization, per role, per use-case.
ASK
“Show me the contracts I need to sign this week.” Read-only. No state change. Always allowed.
PROPOSE
“Draft a reply to this lead and advance the deal stage.” Drafts shown. You approve. No state change yet.
EXECUTE
“Send the offer to Maria with the standard joining pack.” Dangerous? Preview + approve. Audit-logged.
The AI inherits your permissions. It cannot escalate.
If you can't delete a deal, the AI can't either. If your role loses access to compensation data tomorrow, the AI loses it automatically. The AI cannot create an API key, cannot grant itself a new permission, cannot impersonate.
AI tokens are separate from browser sessions: 24-hour expiry by default, rate-limited independently, revocable per session. Every AI call records the token ID + session ID for traceability.
Dangerous actions require explicit approval.
Sending email. Deleting records. Charging cards. Posting to public channels. Running payroll. Mass-updating. The AI proposes, the user approves. Every approval is logged with the actor, the timestamp, the input, and the output.
You decide what's dangerous in your org. Out of the box, Odexy ships sensible defaults — see /security#dangerous-actions .
Nothing the AI does is off the record.
Every action is written down and cannot be edited afterwards: what was done, who asked for it, which conversation it came from, and exactly what changed as a result. You can walk back through an entire session and see how it reached each decision.
This is the difference between trusting an AI and being able to prove what it did.
The right model for the right job. Picked by you, not us.
Different jobs deserve different models. Summarising a thread does not need the same horsepower as screening a candidate or drafting a contract clause. You decide which model handles which job — a cheap fast one where that is enough, a stronger one where it matters — and change your mind whenever you like.
Bring Anthropic, OpenAI or Google. Use your own account and your own rates if you prefer. Nothing here locks you to one provider.
What it does today.
Concrete examples, all shipped. None of these are demos.
- Draft + send branded emails from any module's templates.
- Plan a Projects sprint from a natural-language brief.
- Advance a CRM deal through its pipeline with required notes.
- Schedule an interview, attach an ICS, send the candidate the invite.
- Generate an offer letter PDF, attach to email, send the public accept link.
- Approve a leave request after checking team coverage.
- Run a payroll cycle and produce the payslips — asking you to confirm first.
- Triage a support ticket: classify, route to group, set SLA, reply with the right macro.
- Summarize a long chat thread or a project's recent activity.
- Answer "what actually changed in this project last week?" — and show its working.
What we don't pretend.
The AI can't do these things — not because of policy, but because of architecture:
- Reach your database directly.
- Call out to the internet on its own.
- Touch your files or your passwords.
- Give itself more access than the person who asked.
- Do anything irreversible without you confirming it.
- See a conversation, file or record that person cannot see.
These aren't policies. They're the architecture.
Change provider without changing how you work. Swap the model behind any job and everything your team built keeps running exactly as it did.
The AI you can show an auditor.
Free for 5 seats. No credit card. The AI is included — never a paid add-on.
