// AI trust & safety

The agent should know when to stop.

A dependable AI system is explicit about what it is, acts only inside approved boundaries, and leaves important decisions with authorised people.

// Design principles

Controls before convenience.

The exact controls depend on the organisation, workflow, country, and information involved. They are agreed before launch.

01 · Disclosure

People should know they are speaking with AI.

The opening and channel profile identify the assistant clearly. The system does not pretend to be a clinician, employee, or specific real person.

02 · Boundaries

Approved tasks are written down.

Allowed information, prohibited advice, escalation triggers, and tool permissions are defined for the workflow instead of left to improvisation.

03 · Human control

Uncertainty produces a handoff.

When a request is sensitive, urgent, unclear, or outside scope, the agent stops, captures context, and follows an approved transfer or callback path.

04 · Data restraint

Collect only what the task needs.

Access, retention, deletion, exports, and staff visibility are scoped before launch. Sensitive data is not collected merely because the system can ask for it.

05 · Recording

Recording is optional and disclosed.

If calls are recorded or transcribed, the organisation must approve the purpose, notice, access rules, retention period, and deletion process.

06 · Auditability

Important actions leave evidence.

Calls, messages, handoffs, tool actions, failures, and approvals can be logged so staff can review what happened and correct the system.

// Healthcare boundary

Administrative support is not clinical judgment.

A clinic agent can share approved administrative information, manage appointments, and route requests. It should not diagnose symptoms, recommend treatment, or delay urgent human help.

Agent handlesHours, location, services, and booking
Agent handlesApproved preparation information
Human handoffSymptoms, diagnosis, and treatment
Human handoffUrgent, distressed, or uncertain callers

Define the safe boundary before the first live call.

Bring one routine workflow. We will map what the agent may do, what it must never do, and when a person takes over.

Review a workflow