AI Policy
How the AI agents in Dispatch work, what data they see, the human-review and approval safeguards, and our commitment never to train models on your data.
Dispatch exists to let you delegate work to AI agents safely and visibly. This page explains how the AI features work and the commitments we make. It complements our Terms of Service, Privacy Policy and Acceptable Use & User Content Policy.
1. How a run works
- You create a card with a task type (for example “Research brief” or “Data extraction”) and its inputs.
- When you move the card to Running, an agent loads the task type’s instructions, your inputs, the text extracted from your attachments and your workspace settings.
- The agent writes a short plan, then calls the tools allowed for that task type — searching the web, fetching a page, reading a file, building a table.
- Every step is recorded in the trace you can watch live: a summarised progress narrative, each tool call with its inputs, each result, messages, costs and errors.
- The agent produces an artifact (a document, table, JSON, email draft or file) with citations to its sources, and the card moves to Review.
- You review, edit, export, comment “send to agent” for a revision, approve or reject.
2. Human in the loop
- Approval gates. Any tool with effects outside Dispatch — sending an email, posting to Slack, creating a Notion page, uploading to a drive, calling a webhook — is side-effecting. The run pauses and shows you the exact action as it will execute. Nothing happens until an authorised person approves it, optionally after editing it. Rejecting sends your reason back to the agent.
- Configurable only by admins. On Pro, an admin may set a task type to “Never ask”. The product shows a warning, and the change is recorded in the audit log.
- You decide. Agents draft, research and extract. People make decisions. Do not use AI output as the sole basis for decisions with legal or similarly significant effects on individuals.
3. Models and providers
- By default, Dispatch uses large language models from Anthropic through its commercial API. The provider may change; the current list is on our subprocessors page.
- Where no AI provider is configured (for example in some demo or development environments), a deterministic built-in engine simulates agent runs. Output from that engine is clearly illustrative.
- Workspaces choose between a Standard tier (default) and an Advanced tier (Pro) for higher-quality reasoning at a higher cost.
4. Your data and model training
- We do not train or fine-tune AI models on your data, and our model providers are contractually prohibited from doing so.
- We send the provider only what a run needs: the task instructions, your inputs, relevant attachment text, tool results and, when you re-run from a comment, your feedback and the previous artifact.
- We use providers’ zero-data-retention options where available; otherwise inputs and outputs may be retained by the provider for a short period (typically up to 30 days) solely for abuse monitoring.
- Traces, artifacts and tool logs are stored in your workspace under your plan’s retention period, so you can audit them.
5. Safety measures
- Untrusted content. Web pages and files are treated as data, never as instructions. Instructions found inside fetched content are ignored, and side effects always require approval.
- Network protections. The fetch and HTTP tools block private networks and local addresses, respect robots rules and cap response sizes.
- Budgets. Each run has limits on tokens, wall-clock time and tool calls, and stops gracefully with a partial artifact when a limit is reached.
- Refusals. Requests that violate our policies are refused with a clear explanation rather than retried.
- Audit. Every tool invocation, approval decision and administrative change is logged.
6. Limitations
AI output can be inaccurate, incomplete, outdated or biased, and a citation may not fully support a statement. The “thinking” shown in a trace is a summary of progress, not the model’s raw reasoning. Always review output — especially facts, figures, legal or medical content and anything you will send to others.
7. Transparency obligations
If you publish AI-generated content or deploy it in interactions with people, you are responsible for complying with applicable transparency rules (for example disclosing that content is AI-generated where the law requires it). Dispatch labels agent-produced artifacts and records whether an artifact was edited by a person.
8. Reporting issues
Report harmful output, suspected prompt injection or misuse to abuse@asrar.example, and security issues to security@asrar.example. We review every report.
9. Changes
We will update this page as the product evolves and publish every version on its version history page.