Default-deny grants
Coworkers act only through scopes and tools that are granted for the current context.
Evidence: 008 grant permission model
Security and trust
Personal privacy and regulated workflows are enforced by application permission checks, default-deny grants, approval packets, and receipts; database-level controls protect direct API paths where implemented, but Cuadrila does not claim autonomous regulated decision-making.
Regulated decisions
Cuadrila is software that prepares, organizes, and routes work. Its AI coworkers draft communications, assemble documents, and propose actions with sources attached — but they do not make legal, medical, financial, HR, or compliance decisions, and they do not provide professional advice. Every regulated or externally consequential action is approval-gated and fails closed: a named human reviews the proposed action, its sources, and its receipt before it executes. You remain responsible for deciding whether an output is appropriate for your business, your industry, and your legal obligations.
Backed guardrails
Coworkers act only through scopes and tools that are granted for the current context.
Evidence: 008 grant permission model
Externally consequential actions are parked with a named packet until an authorized human decides.
Evidence: 015 approvals everywhere
Actions leave receipts with source, scope, and decision posture so teams can inspect what happened.
Evidence: 009 artifact receipt entity
Will not do
Make legal, medical, financial, HR, or compliance decisions
003 regulated-decision disclaimer plus 015 approval gates
Send, file, publish, or share externally without the required approval state
015 approval packets and 008 verb-tier grants
Treat marketing-only characters as shipped product agents
003 two-rosters hygiene and 007 active product roster
Claim generated media, public apps, local execution, help center, or backup as active without launch evidence
028 hardening evidence and 029 go/no-go review
Trust destinations
Support destination is configured from the platform brand record.
Open destinationOperational update host is configured from the platform brand record.
Open destinationSubprocessor posture is summarized in the privacy policy until a standalone backed table is accepted.
Open destination