Flo can read and act across company work. What it can see, which tools it can use, when it needs confirmation and what stays human are enforced outside the model.
Access, tools, actions and authority - each enforced outside the model, not as a prompt.
Flo's available tools are filtered by role and capability, and data access remains scoped to the authenticated user's organization and permissions.
Tools can be disabled at the organization level. If a tool isn't available to the user or has been disabled for the company, Flo cannot use it. The dispatch gate enforces this even if a call is forced directly.
26 of Flo's 28 current write tools ask for confirmation before acting. Confirmation is a property of the tool - not an instruction we hope the model remembers.
Flo can gather context, prepare work and surface evidence. It does not become the authority for decisions such as compensation, termination or final performance outcomes.
Customer data is not used to train our models or our model providers' models. Managed model calls use zero-retention API access. Data is encrypted in transit and at rest.
Groups below the anonymity floor are withheld before Flo or a manager can use them. Free-text that reaches Flo arrives without employee identifiers.
Below the 3-response floor · result withheld
Flo receives anonymous text without employee, response or department identifiers.
Every request passes through identity, permission, org tool settings, data scope and confirmation before an action can land.
Flo's conversations persist under the user's access. Tool calls are stored with the interaction, and proposed actions link back to the conversation that created them.
We record observable actions and outputs - not a claim to expose hidden model reasoning.
Flo handles the watching, preparation and follow-through. You stay in control of what gets decided and what gets done. Meet Flo →