Control

Confidence is not permission.

Nothing important should change in Clover because an AI felt sure. Emma makes every supported action understandable before it runs and accountable after it runs.

Six operating principles

Trust is designed into the workflow.

Safety is not one confirmation modal at the end. It begins with the permission model and continues through preview, execution, verification and recovery.

01 · Least privilege

Only the access required

Emma requests the Clover permissions needed for its enabled workflows and treats missing permission as a boundary—not something to work around.

02 · Preview first

See before and after

Current values, proposed values, evidence, expected outcome and the complete affected-record list are shown for review.

03 · Explicit boundaries

Rules travel with the task

Margin floors, stock policies, business periods, product groups and approval limits remain attached to the mandate.

04 · Deterministic tools

Language plans. Tools act.

Emma uses narrow validated Clover actions instead of allowing a model to create arbitrary API mutations.

05 · Full traceability

Every action leaves evidence

Who approved, what changed, when it ran, which objects were affected and what failed remain visible.

06 · Verified outcome

Read after every write

Emma checks the final Clover value, isolates errors and never marks a proposal as completed without a confirmed result.

Control by workflow

Autonomy is not a switch. It is a ladder.

A merchant can let Emma read and explain automatically while keeping every supported Clover write behind an explicit approval.

Level 01Observe

Explain

Read authorised Clover data and surface opportunities without creating a mutation.

Zero writes
Level 02Prepare

Draft

Create evidence-backed analyses and action payloads that remain outside live Clover data.

Nothing changed
Level 04Monitor

Run checks

Repeat specified read-only controls within explicit data, time and alert limits.

Revocable per workflow
Level 05Guarded

Pursue goals

Prepare work toward agreed objectives while protected actions and strategic decisions remain human.

Approval remains enforced
Always protected

Some actions should never happen quietly.

These operations require an explicit decision even when Emma eventually supports the underlying workflow.

01

Product deletion

Archiving is preferred where possible; permanent deletion requires a clear, item-level decision.

02

Material price changes

Price thresholds and margin floors are validated before any change can enter approval.

03

Inventory modification

Stock signals can trigger alerts and plans, but quantities remain protected by default.

04

Refunds, voids or cancellations

Order-level financial actions are not executed by Emma’s current tools and are never inferred from a chat request.

05

Customer communication

Nothing is sent to a customer without the merchant enabling a purpose-built communication workflow.

06

Employee and financial decisions

Emma can explain operational records but never accuses an employee or makes payroll, disciplinary or financial decisions.

A decision packet, not a pop-up

Approval should be informed.

A confirmation is only useful when the merchant understands the change. Emma packages the evidence needed to make a fast, confident decision.

  • The requested outcome and merchant constraints
  • Emma’s justification and confidence
  • Current and proposed Clover values
  • Every Clover record the action will affect
  • Risk label, dependencies and verification method
Approval packet · Inventory receiptMedium risk
Scope11 products
✓8 standard stock increasesReceiving quantities match the reviewed sheetReady
✓2 low-value correctionsCurrent and proposed quantities shownReview
!1 high-value item separatedIndividual approval required by merchant ruleApprove
Final quantities verified in CloverReview 11 items
Prepared by Emma · Today, 9:18 AMApprove selected
The operational record

A clean history of every decision.

Emma’s memory should never become a black box. Merchants can inspect rules, permissions, prior approvals and the evidence behind a recommendation.

01

Mandate

The requested outcome, constraints, deadline, scope and approval level are captured before preparation begins.

02

Proposal

Emma records the plan, confidence, inputs used, affected objects and why each action belongs.

03

Decision

Approvals, rejections and merchant edits become visible events—not hidden chat context.

04

Execution

Each write has a timestamp, job state, retry history and precise success or error result.

05

Outcome

Emma verifies the final Clover state and, where measurable, follows the operational result over time.

Safety questions

Know the boundary before you delegate.

Can Emma undo a change?

Emma shows the previous value and whether a reliable reversal is available. Some Clover actions are not perfectly reversible; those stay labelled before approval.

Can one approval cover many products?

Yes. A merchant can approve a safe batch after reviewing its rule, sample previews and full affected-item list. Higher-risk or inconsistent items can be separated for individual review.

What happens when a long job fails?

The operation is divided into idempotent jobs. Completed items stay recorded, failed items are isolated, duplicate writes are avoided and the merchant receives a precise retry option.

Does Emma train a shared model on merchant data?

No. Merchant content is processed to provide and secure Emma, not used to build a shared Emma model. Data handling, processors and retention are explained in the Privacy Policy.

Can permissions be revoked?

Yes. The merchant can uninstall Emma or change authorised access through Clover. Emma treats a revoked or missing permission as a hard boundary.

Careful by default

Start with observation. Approve every next step.

See what Emma finds before deciding what she may prepare—or ever change.

Start the 7-day trial →