Every action Flo takes is a narrowly-scoped tool call — logged, gated to the asking user, and (for writes) confirmed by default. Here's the catalogue.
Tools always run as the asking user. The audit log records you, not Flo. If you can't see a record, Flo can't see it either. The boundary is the database, not the prompt.
See the full tool catalogue in action — start a 14-day trial.