An AI assistant that can only summarise is safe and not very useful. One that can send mail and change your calendar is useful and a little frightening. The question every team hits is where to put the line.
Our answer: it asks first
In AntFabric, anything the assistant cannot undo waits for your approval. Sending an email, cancelling a meeting, deleting a note: it prepares the action, shows you exactly what it is about to do, and stops.
The tools that write to your mail sit behind that approval and are switched off by default. There is no "approve" tool the assistant can call on its own. Approval is a button you press, not a sentence the model can produce. No amount of persuasive text gets an action through.
What that looks like
Asked to cancel a real calendar event, the assistant found it, named the meeting, its time and its video link, pointed out that nobody else was invited so nobody else would be notified, and then waited. That is the whole design in one exchange. It does the looking. You do the deciding.
Approvals also survive a restart. If the app or the server restarts while a request is waiting for you, it is still waiting when things come back. It does not quietly time out and it does not quietly go ahead.
Why not full autonomy
Because the assistant is not a domain expert yet, and neither is anyone else's. An assistant that sounds equally sure whether it knows or is guessing should not be able to act without a person in the loop. The limit is what makes it safe to give it real work.
See it on your own work. Book a demo.