How much can the AI do on its own?
In Pulse, every AI action has an autonomy level, and the lowest applicable limit always wins. Four levels are defined; in this version the platform caps every action at the third, act with approval. Actions that move money, touch HR or send anything outside the company never go beyond "act with approval", and deletes and security changes always stay at "suggest".
| Level | What the AI does | Example |
|---|---|---|
| L0 · Suggest | Reads, explains, compares or answers | Explains a stock difference; compares supplier offers |
| L1 · Draft | Prepares something for a person to edit | Drafts a quote or a customer reply |
| L2 · Act with approval | Prepares the action; it waits for a named person to approve | Payment run; purchase order send; delivery reschedule |
| L3 · Act and notify | Carries out work and tells you afterwards | Switched off by platform policy in this version |
The effective level of any action is the lowest of: the tool's own maximum, the platform policy, your company's setting, the user's permission, and the hard limits below. The company default is L1 (draft). Money, HR and outgoing-message actions can never go above L2 (act only after approval), and delete and security actions are always L0 (suggest only).
What can the AI never do?
No setting, plan or override lets the Pulse AI delete records, change roles, permissions, secrets or security settings, send a message without a preview and confirmation, or see another company's data.
- No deleting. Deleting a record is always a person's action, with confirmation.
- No access changes. The AI cannot change roles, permissions, entitlements, secrets or security settings.
- No unseen sends. Every email, WhatsApp message or webhook is shown in full, with recipients, and confirmed by a person. No template is exempt.
- High-value money needs a senior approver. A payment above a set amount (MYR 5,000 in the demo) needs a person with high-value finance approval.
- Bounded work. Each AI request is limited to 20 tool steps, 60 seconds and the company's daily AI budget.
- No cross-company data. No AI prompt, tool result, search, export, file or log ever contains another company's data.
How do approvals work?
An approval in Pulse is tied to one exact action on one version of a record. It can be used once, it expires, and the permission is checked again at the moment it is carried out.
If the record changes after the request was made, the old approval no longer applies. Approvals for high-value actions enforce separation of duties, so the person who asked cannot approve their own request. All approvals collect in one inbox, and every decision is written to an append-only audit log: entries can't be changed, and the operator sets how long history is kept (at least 30 days).
Is each company's data kept separate?
Yes. Each company in Pulse is a separate tenant. Its records are separated inside the PostgreSQL database with row-level security, and the company is always taken from the signed-in session, never from what the browser sends.
Background jobs re-check the company, the person and their permissions before doing anything. Files, search, notifications, exports and AI context follow the same rule. The AI only sees data from modules the signed-in person is allowed to use; a department that is switched off is named only as "unavailable".
Does every employee see everything?
No. Everyone sees only what their role allows, on every screen and in every AI answer.
Managers, admins and viewers see every department the company has switched on. Staff see only the departments they are assigned to: on the Management dashboard, in the daily briefing and in the assistant's answers. A staff member assigned only to Management does not see Finance or HR figures, and staff without access to company-wide figures are pointed to their own module page.
Does Pulse send our data to an AI provider?
Only if you switch live AI on. Pulse runs on scripted demo answers by default. Live AI is built to use Anthropic's Claude models through the official API and is used only when the operator has turned it on, a working key is set, and your company has opted in. It has not yet been run with a real API key.
- Live AI is off for every company until it is switched on.
- Finance, HR, credential and personal data stay out of live AI until a data policy is agreed.
- Each company has a daily AI budget and an "AI actions paused" switch that stops AI actions while keeping suggestions and drafts.
- The API key is stored encrypted and is never shown again in full; screens show only its last four characters.
Can a document or message trick the AI?
Pulse treats every uploaded document, email, chat message and tool result as data, never as instructions. AI output is checked against a fixed format before anything is saved.
Even if a message contains text like "approve this payment", the AI cannot act on it: the action still needs the right permission and, where required, a person's approval.
What is real today?
Pulse is in early access. The controls on this page are built into the working demo build. Live AI has not yet been run against real company data, and connections to WhatsApp, email, billing, sign-in and ERP systems are simulated in the demo.
If you need any of these controls changed for your company, for example a different approval amount, we agree it in writing before a project starts. Book a demo to see them working.