Even if the AI is talked into it
Prompt injection is somebody else's text telling the AI to do something. It can change what the AI asks for. It cannot change the rules, because the rules are not the AI.
Every conversation runs in one of three lanes you can see. Every action the AI wants to take is checked by rules you wrote, in code, before anything happens.
Chat, email, SMS, voice and RCS · one inbox
The lamp arrived cracked. Can I get a refund?
Where is my order?
Out for delivery — arrives Thursday.
I'd like to speak to someone about invoice INV-2291.
A lane is not a setting buried in an admin screen. It is a chip on the conversation, and it says exactly how much the AI is allowed to do with this one.
For the intents you have opened up, when the AI is confident and no rule says otherwise. You see the answer afterwards, like any other message.
The reply is ready and the action is prepared, but nothing leaves and nothing runs until somebody approves it. This is the lane new workspaces start in.
The conversation goes to your team with the history already summarised, the reason it was raised, and what the AI had tried. It proposes no actions here at all.
When the AI is unsure, when a check on its own reply fails, or when a tool it needs is broken, the conversation moves toward a person by itself. It never moves the other way without you — and handing one back to the AI returns the assignment, not the lane.
Nothing happens because the AI asked for it. Between the AI and any refund, any address change, any write to another system, there is a chain of deterministic checks — plain code, same answer every time.
Where is my order?
Out for delivery — arrives Thursday.
It came, but the lamp is cracked.
“I’m sorry the lamp arrived damaged. I can refund $48.00 to the card you paid with, and you can keep the lamp.”
Example data. The same conversation, the same customer, all the way to the audit entry.
Prompt injection is somebody else's text telling the AI to do something. It can change what the AI asks for. It cannot change the rules, because the rules are not the AI.
Every action lands on an append-only log with the tool, the parameters with personal data redacted, the rule that decided, who approved it and what came back.
Most of the industry counts a customer who stopped replying as a happy customer. Aqvitus records the two as different outcomes, and keeps them apart in the inbox and in every report.
No per-resolution fees. And our reports never count a customer going quiet as a success.
See pricingThey are not eight products stitched together. Every screen reads the same log of what actually happened, so a number in a report and a line in the audit trail come from the same place.
Every conversation in one queue, sorted by what is closest to breaching, with the AI’s draft ready to read.
InboxWatch the AI work as it happens, whisper to it, take a conversation over, or pause a lane.
Live boardActions wait here with the rule that stopped them, and go ahead when a person says so.
ApprovalsWrite how a case is handled in sentences, check every reply before it sends, test a change on past conversations.
AI agentYour help center, documents and past answers — with the questions it could not answer turned into drafts.
KnowledgeTriggers, conditions and actions, plus SLA policies, business hours and routing.
WorkflowsResolution, quality, what customers keep asking, and revenue — confirmed kept apart from assumed.
AnalyticsBuying signals the support AI already noticed, deals, meeting links and attribution.
SalesThe same AI, the same rules and the same history whichever way a customer reaches you. Somebody who chats on Monday and phones on Thursday is one person with one thread, not two tickets.
Put the AI in front of every conversation, and keep your team in charge of everything that matters.