Security & control

Powerful because it's disciplined.

An AI that can publish a price or a listing to every marketplace is only as good as its guardrails. Ours weren't theorized. They were forged operating real brands, where a bad write shows up on the storefront the same hour. Discipline isn't a feature here. It's the foundation.

The guardrails

Five things that are always true.

01

Before-state on every change

Before a price or a listing is modified, the prior value is captured. Every action is reversible in one step. No "we can't undo that."

02

Hard limits in the system

Price bands, stock-change caps, and publish steps live in the platform itself, not in a prompt. The AI cannot cross them, even if asked.

03

Approval queues

You decide what applies instantly and what waits for your click. A listing publish can always require a human yes.

04

Full audit trail

Every action records who, which marketplace, when, and a written reason. The change history is queryable, like everything else.

05

Measured, not assumed

Price and listing changes are tracked with a captured baseline and a result scored days later, so the system corrects course on evidence. Bad writes get caught. Good ones get repeated.

Data ownership

Your data stays yours.

The unified record of your catalog is yours, not a silo we rent back to you. We're the operator and the plumbing. You keep the asset.

Exportable any time: it's a real database, not a locked dashboard.
Scoped access: each marketplace connection grants only what's needed, and you can see exactly what.
Revocable: pull a marketplace, or the whole thing, whenever you choose.
Not training fodder: your orders and catalog are used to run your brand, full stop.
access · per marketplace
Shopify · read orders, write listings + prices
Amazon · read orders, write listings + prices
Walmart · read orders, write listings
Faire · read orders, write products + prices
you control every line · revoke anytime
The control model

You set the leash. The system respects it.

Action typeDefault behaviorYou can change it to
Read / answer a questionAlways allowed, instant·
Inventory sync within the capAuto-applied within limitsRequire approval
Price change within the bandValidated, then appliedRequire approval
Listing publishValidated, then queued for approvalAuto-apply for trusted fields
Price or stock move outside the bandBlocked, needs an explicit overrideWiden the band (logged)
Teams & roles

Ten people, one system, zero oversharing.

Each seat gets a role. Each role is a precise slice of the catalog and the levers, enforced in the database itself. What a role can't see never reaches the AI, so it can't be talked out of it.

RoleSeesCan doNever sees
Owner / AdminEverythingEverything·
FinanceRevenue, margins, payouts, feesReconcile, export, bandsListing controls
MerchandisingSales by marketplace, catalog, coverListings and price drafts, queued over the bandMargins, payout accounts
OpsOrders, inventory, shippingReorders, stock sync within the capMargins, pricing bands
AnalystTrends across marketplaces, PII-strippedRead onlyCosts, identities, credentials

Roles are set with you during onboarding and reviewed as the team changes. Marketplace credentials live in a sealed vault, never in the database, so a question can't leak account access.

Held on Faire

What a held change looks like.

The film on this page types one instruction: raise Aurora 18% on Faire. That raise sits outside the band, so Faire is held. The before-state is kept, and the change waits.

The instruction

Raise Aurora 18% on Faire. One product, one marketplace, one move, in the same words the guard film uses.

Outside the band

Price bands live in the platform, and the AI cannot cross them. This raise sits outside the one you set, so Faire shows held.

Before-state, then the wait

The price already on Faire is captured first. That before-state stays. The change waits for the explicit override, and the override is logged.

The audit

What the audit keeps.

Every action already records who, which marketplace, when, and a written reason. The approval queue is where you decide what applies instantly and what waits for your click. A listing publish can always require a human yes. The audit keeps the before-state with that decision, and whether the change published, waited, or was blocked.

01

Who asked

The person who sent the instruction. When the approval queue holds a listing for a human yes, that line still names who asked.

02

The before-state

The value captured before the write. On the Aurora raise, that is the price Faire already showed, kept so the change can be reversed in one step.

03

Which marketplace

Faire on the held raise. Each line names its own channel, the same way a listing publish names the marketplace waiting on your click.

04

Published, waited, or blocked

The approval queue leaves one of those three on the line. Raise Aurora 18% on Faire is blocked and held: outside the band, before-state kept, still waiting.

Built the hard way

We learned this operating our own brands.

The day a bad price published across every marketplace was the day these guardrails became non-negotiable. You get the discipline without the tuition.

Schedule a call