Human approval comes first
For outreach and other high-trust workflows, Tilth agents prepare drafts for human review. The agent's role is to research, draft, organize, and surface the work. A person decides what gets sent.
For client-specific pilots, sending can be configured off entirely for the relevant workflow. In those cases, the agent produces reviewed deliverables inside the portal rather than transmitting messages itself.
Client data is separated
Each client agent runs with its own working space, long-term memory, email identity, and portal scope. Tilth does not use one shared client brain. Portal data is scoped per client, and database access rules enforce that separation on every query.
Least-privilege access
When an agent needs access to a client system, Tilth treats it like onboarding a new employee: named account, limited role, revocable access. We ask for the minimum access required for the work and keep the scope tied to the job the agent is doing.
Outside content is information, not instructions
Tilth agents are trained to treat emails, web pages, attachments, and other outside content as information, not instructions. A page on the internet or a line in an email cannot override the agent's operating rules.
Audit history and oversight
Tilth is a managed service, not unattended software. Client work is visible through the portal, including tasks, delivered files, chat history, and usage activity. For high-stakes work, a named human approver reviews outputs before they are used externally.
Retention, export, and deletion
Client data lives in the client's portal and agent workspace for as long as the work requires it. If a client offboards, Tilth exports the relevant work product and removes active client data from the system. Backup copies age out on the normal backup cycle.
Exact deletion timing and export procedure are confirmed in each client agreement before work begins.
What we do not claim
Tilth does not claim to be unhackable, does not claim the AI is incapable of mistakes, and does not claim compliance certifications we have not earned. If your organization requires SOC 2, ISO 27001, HIPAA, or another formal framework, we will discuss that requirement directly before starting work.