Teach it in sentences. Watch it run the same way every time.

You write how a refund, a delivery question or a cancellation should be handled, in the words you would use training a new person. Aqvitus turns that into steps it executes exactly — and the AI does not get to change them mid-conversation.

Refund request version 15 · active
  1. Check the email is verified
  2. Get the order number
  3. Look the order uporders.get
  4. Outside the refund window?branch
  5. Refund itpayments.refund
  6. Confirm, and say when the money lands
Compiled from your sentences. The AI fills the blanks; it does not choose the path.

The AI writes the words. It does not write the rules.

This is the whole difference between an assistant that sometimes does the right thing and a worker you can put in front of customers.

Refund request · what you wrote version 15

“If someone asks for a refund, check their email is verified, find the order, and refund it if it is inside 30 days. Tell them when the money lands.”

Compiled 4 steps · 2 tools
  1. Check the email is verified
  2. Find the order orders.get
  3. Inside the 30-day window? branch
  4. Refund it, and say when the money lands payments.refund
The reply it wrote

“That’s refunded — $48.00 back to your card, and it will be with you tomorrow morning.”

  • Every fact traces to a source
  • Sounds like you, and nothing banned in it
  • Promises a timeline your policy does not allow
Draft Held for a person. The blocked wording goes with it, and the run stopped there.

Example data. A blocked reply stops the run where it is — no later step executes, and the text travels with it so whoever picks it up can see what the AI wanted to say.

  1. You write the procedure in the words you would use training a new person.
  2. Aqvitus compiles it into steps it executes exactly, and names the tool each one calls.
  3. On a real conversation the AI fills the blanks and writes the reply.
  4. Before that reply can leave, a separate check reads it.
  5. One check says no, so the conversation steps down to Draft. Nothing was sent.

What the AI is allowed to decide

  • Pulling the order number out of what the customer typed
  • Choosing which help article actually answers the question
  • Writing the reply, inside the tone and the constraints you set

What is decided before the conversation starts

  • Which step comes next, and what the branches are
  • Which tool is called, and with which values
  • Whether an action is allowed, and who has to approve it

Versions are frozen once written. A procedure moves from draft to a simulation, then shadows live traffic without sending anything, then runs for a small percentage of conversations before it runs for all of them — and a conversation that started on version 14 finishes on version 14. How many procedures a workspace can hold depends on your plan — see pricing.

Every reply is read by something other than the AI that wrote it

Before an outbound message leaves — whether the lane would send it automatically or a person is about to approve it — a separate check reads it. Six questions, and what happens when the answer is no.

  1. Is every fact in it from somewhere?

    Each claim has to trace to a source, a tool result, a learned answer or a template. An invented delivery date fails here.

  2. Does it promise anything off-policy?

    Amounts, timelines, discounts, legal, medical or tax advice. Two strikes and the conversation goes to a person.

  3. Does it sound like you?

    Your tone, your brand voice, your banned phrases. It gets one attempt to rewrite itself, then it steps down.

  4. Is anything in it that should not be?

    Unmasked personal data, another customer’s details, internal-only content. This one blocks the send outright and raises an alert.

  5. Is it confident enough?

    A composite score against the floor you set, not the AI’s own opinion of itself alone.

  6. Did it do what the supervisor said?

    If somebody whispered an instruction into this turn, the reply has to follow it, or the supervisor is asked to step in.

A failed check moves the conversation one step toward a person rather than swallowing the problem. When a reply is blocked the run stops right there — no later step executes and no action is proposed — and the blocked text travels with it, so whoever picks it up can see exactly what the AI wanted to say and why it was not allowed to.

Try a change on last quarter before a customer meets it

Editing a procedure, a rule or your knowledge is a change to how customers are treated. You should be able to see what it would have done.

Replay

Run real past conversations through the whole pipeline with the change in place. Tool calls are dry runs against recorded results, so nothing is refunded and nobody is emailed. How far back you can replay depends on your plan.

Shadow

Let the change run alongside live traffic, computing what it would have said and sent — without saying or sending any of it.

Canary

On Business and Enterprise, give the change a small percentage of real conversations and let it stop itself the moment a gate slips.

Six gates, and all six are checked on every change

A procedure, a prompt, a rule set, the autonomy matrix, the model routing table or a knowledge snapshot — the same gates apply to all of them, and the results are kept as events you can look at later. There is a command-line entry point too, so this can sit in the same pipeline as the rest of your engineering.

  • No policy violations at all
  • No personal data leaking in any reply
  • Resolution correctness within 2 points of where it was
  • Tool calls right at least 98% of the time
  • Cost per resolved turn within 15%, unless you override it
  • Every new failure looked at by a person

Replay depth and canary rollout depend on your plan — see pricing.

Your model, your keys, or your own hardware

Nothing in Aqvitus is built around one AI vendor. Every job the platform does — classifying, pulling values out of text, answering, judging an answer, embedding, transcribing a call, speaking — is a task class, and a table you control says which model does which.

Cloud

We hold the model keys and the routing table ships configured. Nothing to set up.

Bring your own key

Your provider accounts, your rates. Model spend passes through at cost and stays attributable per task.

Sovereign

Self-hosted, with classifying, extracting and embedding on local open-weight models. Where nothing may leave, that is verifiable rather than promised.

Change a model for one task class and it is a change like any other: it runs the six gates first. Every call records what it cost, how long it took and which provider served it, so the bill is attributable rather than a single line at the end of the month.

And a place to sit and work on it

Agent Studio is where the procedures, the training material, the sandbox, the persona and the autonomy matrix all live.

Playground

A sandbox chat against recorded results. Pick a persona, a verification level and the procedure you are testing; every reply shows its lane, its confidence and what the checker said. Save a good case as a test.

Persona

Tone and length sliders that rewrite a sample reply as you move them, banned phrases as chips, and an AI disclosure on the first message that cannot be switched off.

Training

Which sources are connected and how fresh they are, how well your intents are covered, and the learned answers waiting for review.

Autonomy

The matrix itself: intent by intent, which lane, and what confidence it takes to get there. Route cannot be loosened by a slider.

Aqvitus

AI First. Human Always.

Put the AI in front of every conversation, and keep your team in charge of everything that matters.