Principles
Why we don't let the AI send anything
Most AI tools race to act. Taskpath's AI drafts and proposes, but a person approves anything that leaves the building. Here's why that's structural, not a setting, and how it still scales.
Most AI tools are in a race to act. Send the email, update the record, file the document, book the meeting. It looks impressive in a demo. It's a different feeling the first time it does the wrong thing to a real customer and you find out afterwards.
We built Taskpath on the opposite instinct. The AI drafts and proposes. A person approves anything that leaves the building. Nothing external goes out on its own.
That sounds like a policy. It isn't. It's how the code works.
It's structural, not a promise
Every action Taskpath can take, whether that's sending a reply, posting to a CRM, or moving a file, is a typed proposal with a risk class. Internal, reversible writes can run on their own. But anything that communicates with the outside world, or that can't be easily undone, is held for a person. The engine won't automate those. It raises an error rather than act. "The AI won't email a customer on its own" isn't a checkbox you're trusting us to have left on. It's a line the system can't cross.
So when a support email arrives, Taskpath reads it, drafts a grounded reply from your own documents, cites the source, and then stops. The draft sits there with the evidence next to it, waiting for you to send, edit, or reject. Nothing has left the building.
"But approving everything doesn't scale"
True. If a person has to click send on every routine reply forever, you've saved the drafting but not the deciding, and at volume the deciding is the work.
So Taskpath lets you hand over specific, narrow classes of work, but only ones it can earn. You can promote something like "known-policy answers" to send on their own, and only when machine-checkable conditions all hold: the reply is grounded in approved sources and cited, the recipient is known, there's no pricing, legal, or personnel exposure, and the model was confident. It's granted per procedure, it's off by default, and the sensitive topics, anything about money or legal, always stop for a human no matter how much autonomy you've handed over.
It works like onboarding a new hire. You don't give them the keys on day one. You hand over the easy tickets, watch how they do, and widen the lane as they earn it. Trust is granted in stages, it's visible, and you can take it straight back. What you don't do is let the AI decide, on its own, that it's ready.
Why a rule, and not a careful prompt
There's a deeper reason the gate is structural. You can't make an overconfident model safe by asking it to be careful. The model that would make the reckless call is the same one you'd be asking to check it.
There's a clean example of this. The New York Times ran a budget-cut task through an unguarded agent, and it marked employees on leave as "cuttable" without ever asking how long the leave was. Good data, fluent output, completely wrong judgment. The fix isn't a better prompt. It's a deterministic rule the model can't skip, unresolved leave, ask a person, sitting below the model with a human in the loop.
That's the pattern everywhere in Taskpath. The guard against a risky judgment is a rule and a person, not more of the same intelligence that made the judgment.
What it buys you
Because nothing acts on its own, a few things follow. Answers are grounded in your own documents and cited, or the system says it doesn't know instead of inventing one. Every consequential step is written to an audit trail you can read back. And you can put it on real work, because the worst case is a bad draft you catch, not a bad action you discover later.
Everyone's racing to make AI do more on its own. The harder, more useful problem is making it ask better, and making the moment it stops and waits for you part of the machine rather than a promise.
Want this on your own tools?
Taskpath runs over the email, folders and forms you already use, EU-hosted, and nothing goes out without a person's say-so.