Skip to content

Trust & controls

Agents can prepare the work. People decide what leaves.

Workspace roles and product access decide what people and agents can use. Agents prepare drafts. Teammates approve each email or Slack message.

Outbound approval

Waiting for approval

Prepared email

To
Maya Chen · maya@northstar.example
Subject
Confirm the revised renewal plan.
Body
Hi Maya — the revised renewal dates and support terms are ready. Please confirm that the plan matches our conversation.
Channel
Email
Delivery
Not sent
Workspace access
Workspace member
Product scope
Northstar only
Agent version
Company research v2 · reviewed
Message approval
Exact recipient, subject, and body

Approval applies only to the recipient, subject, and body shown here.

Representative product flow. This example does not contact a provider, change a CRM record, or send a message.

Four separate boundaries

Workspace access, product access, agent permissions, and outbound approval stay separate.

Each check answers a different question. Passing one does not pass the next.

Workspace

People need workspace membership to access the CRM.

picrm checks workspace membership on every CRM request. Background work stays with the workspace and product where it started, and connected services cannot switch to another customer workspace.

Product

Customer identity stays shared. Product work stays scoped.

Companies and contacts keep one workspace identity. Deals, lists, reports, agents, jobs, and drafts stay with the product that owns them.

Agent

Agents can use only what their reviewed setup allows.

Each run uses one product, one reviewed version, approved records or an explicit workspace scope, and only the allowed tools. Recovering that run does not expand its access.

Outbound

Messages wait for exact approval.

Agent-generated email remains a draft. Approval covers only the displayed recipient, subject, and body or the pinned Slack destination and text.

After a run

Run records show retained evidence, not hidden reasoning or raw provider data.

Teammates with access can inspect what started the run, which reviewed version acted, what it recorded, and the evidence behind the result.

Retained for review

The run record shows what happened.

  • Trigger and initiating person or source
  • Product and agent version used
  • Recorded actions and outcome
  • Cited research sources, when used

Not exposed in the run record

The run inspector does not show these details.

  • Raw provider content
  • Private model reasoning
  • Every internal step
  • Exact tool-call chronology

A recovered run keeps its original product, reviewed version, records, accounts, and tools. Starting again with the current version creates a separate run with its own access checks.

picrm Founding

Start with access you can review. €49 per workspace, each month.

Create a workspace, choose product access, and review each agent version before deployment.