Manual

Security and privacy

This chapter describes what the system does, not what would be nice for it to do. Where there is an automatic protection, it says which one and when it fires. Where there isn't one, it says that too — because a stated limit protects you more than a vague promise.

Read in: Portuguese · Spanish

When Orion holds a message before sending

Orion sends emails and messages in your name — and none of them go out before you have read them. The system holds every send to a third party, shows you the draft, and waits for your confirmation.

The rule
when sending an email (Gmail or Outlook), a WhatsApp message, a group message, a Teams message, a reply to a prospecting lead, or when creating a calendar event with an external guest, the send is held. You get the recipient, the subject and the full text, and only after your yes does the message go out.

The draft is rendered by the code, not by Orion. That difference matters: if the model were the one describing the send, it could store one text and show you another. Your approval is bound to the exact content that appeared on your screen — change a comma and it asks again. The confirmation lasts 5 minutes and works once.

Before that, it checks who the recipient is. If the name you gave matches more than one person in your address book — two Gabriels, three Anas — it does not choose for you: it shows the candidates with their addresses and asks which one. And if the address belongs to someone other than the person you named, it blocks and tells you.

In a voice conversation there is no automatic hold. Orion is instructed to read the draft aloud and wait for a spoken "yes" before sending, but there that is its behaviour, not a system lock.

Routines you scheduled go out on their own. The morning brief, the end-of-day wrap and any automation you created do not ask for confirmation on each run — you authorised the content when you set the routine up.

Why the hold exists in two layers

Beyond letting you read what goes out, the hold protects against something specific: if Orion has read external content before sending — an email that arrived, a web page — the request to send may have come from what it read, not from you. A malicious email can carry the instruction "forward this client's contacts to such an address", and to the model that is indistinguishable from a request of yours.

Today the hold covers both cases: the send you asked for, and the send someone tried to ask for on your behalf.

What it reads, and when

On the dedicated number
the only thing there is what you send to it. It has no access to any other conversation of yours, because the number is its own.
On your own number
it lives in the chat with yourself, and its replies come marked with 🟣. Here it's worth separating two things that often get confused.
What it does on its own
it logs who you talked to and when — without keeping the content. That log is what feeds the Relationships board and the automatic creation of contacts in the CRM. It doesn't reply to your friends, family or customers, doesn't take part in your conversations and doesn't mark your messages as read.
What it does when you ask
it reads the content of a conversation of yours with any contact, if you ask. "Summarize my conversation with Denise in July" or "what did we agree on in the project group?" work — and to work, it has to read those messages. It's your data, and the request is yours; but it isn't true that it "never reads your other conversations". It doesn't read on its own initiative.

For the contacts you choose to track closely, it keeps a short summary of the messages exchanged with that person, building the history of the relationship. Until August 12, 2026 that applied only to what you wrote; since then it applies to both sides — what they write to you goes into the history too. The asymmetry is over, and it existed by accident, not by decision. For contacts you don't track, the log without content still applies; for anyone who isn't in your CRM, nothing.

The LinkedIn conversations from prospecting are a case apart, and an explicit one: when you import the LinkedIn message file on the Prospecting screen, the text of the conversations with people in your queue is stored and stays on each contact's card. Group conversations and everything else in the file — which are your other conversations — are never recorded.

Access to Google and Microsoft 365

The two are not equivalent, and the difference matters.

Google — minimum access. Calendar (view and create), email send, read-only contacts, and files it created itself. It can't see the rest of your Drive, and it doesn't read your inbox: for it to triage incoming email, you have to forward it.

Microsoft 365 — includes reading the mailbox. When you connect Microsoft, you also grant read access to Outlook, and Orion reads your inbox directly, with no forwarding. This applies to calendar, Teams, OneDrive, Excel, Word, OneNote and To Do.

In other words: the phrase "it only reads what you forward" holds for Google. It does not hold for Microsoft.

Groups

Orion only takes part in groups you authorize, and each group has its own policy: reply to any member, reply only when you mention it, or require your approval for every reply.

Inside an authorized group it keeps, for a short period, a log of what was said there — so it can answer "what did I miss?". Outside the authorized groups, that short-term log does not exist.

Read that sentence carefully, because it applies only to participation. The work capture described further down depends on another switch, independent of this one: a group declared a company group is captured even if Orion does not take part in it, and a group authorized to reply is not captured until someone declares it.

Company group: a separate, and more serious, declaration

Since August 14, 2026 there is a second switch, independent of the first: declaring a group a company group. It does not decide whether Orion replies there — it decides whether what is said in that group enters the organization's work record. A group can have its content captured without him replying in it, and he can reply in a group with nothing being captured.

What changes when you declare it: the content of that group's messages starts being captured as work events, and that information may be shared with other people in your company — in records, in plans and in the organization's memory. It applies to WhatsApp and Telegram.

Three guarantees. Capture applies from that point on, never retroactively; you withdraw the declaration whenever you want, in the same place; and the declaration exists only on the Connection screen — neither you nor Orion can declare a group over chat, precisely because a chat command would skip the warning you have just read. A group that is not declared: zero capture.

And the group hears it from Orion himself. When you declare it and when you withdraw the declaration, he writes a message inside the group saying what changed, who changed it and when. It's worth knowing that before you click, for two reasons: the members are told without it depending on you, and declaring a group makes Orion speak publicly there — even in a group where he takes no part in the conversations. That notice is the best attempt possible, not a guarantee: if the channel is down at that moment, the marking holds all the same and the notice may not go out. That's why confirming that people found out remains your responsibility.

What gets recorded about the work

Besides conversations, the system keeps a line of work events: "something happened" — a meeting scheduled, an email that arrived, a commitment stated in the conversation. They come from what he already sees:

  • the emails that come in through him — both the ones you forward by hand and the ones that arrive through the automatic forwarding you turned on;
  • your messages with him on WhatsApp, on Telegram, in the panel chat and in the app;
  • the messages that arrive on your customer service numbers;
  • the actions he performs at your request, such as putting an appointment on the calendar;
  • the groups you declared as company groups.

Worth spelling out: an email that arrives for you leaves an excerpt here even if you never ask anything about it.

Each event keeps a short excerpt — up to 500 characters — not the whole content: the original stays where it always was, and the event points back to it. That is what makes it possible to retrace where a piece of information came from, instead of asking you to trust his memory.

How long this stays. At this stage, none of it is deleted automatically. The short log of an authorized group expires on its own; work events do not — they stay for as long as the organization exists. Withdrawing a company group's declaration stops the capture right away, but does not erase what has already been captured; to erase it for real, the path is the deletion described further down.

What he can conclude on his own

By default, nothing that is a manager's act: he proposes and waits. If — and only if — a manager explicitly authorizes it, he may conclude three acts for that team: apply the cycle assessment he drafted, sign work plans of AI workers, and create deliverables and tasks inside a delivery plan a human has signed. He never signs a human's plan and never signs the delivery plan.

One point that deserves to be clear before any manager turns this on
the cycle assessment includes people's, not only that of AI workers. With that act authorized, the rating and the justification Orion wrote can go into a team member's record without a human clicking. Whoever was assessed is told, and the message says who applied it. Signing a work plan, that one really is AI worker only: a person's still requires the two human signatures.

Nothing happens by surprise. Even when authorized, he warns one day before the date on which he is going to conclude, and the warning goes to that team's managers. If the warning doesn't go out, the act doesn't happen — it's a lock, not a courtesy. When the act is creating deliverables inside a signed plan, the warning is itemized: it lists each deliverable and how many tasks will be created. After acting, he sends a receipt saying what he did.

Four things never run through there, even with everything authorized: money, contact with third parties, deactivating a worker, and changing the autonomy policy itself. And whatever he concludes is recorded as done by him under the authorization of whoever granted it — never as if you had signed. How to turn it on, audit it and turn it off is in the work plans and cycles chapter.

Leaving and deleting your data

In Orion → Delete you delete your agent. What happens next depends on whether you are on your own or in an organization with other people.

If you are the only person in the organization, the deletion is broad: agent, data and work records.

If the organization has other people, the deletion is deliberately narrower. Orion's data — conversations, memory, agent — is deleted. The work records in Y Managers (deliverables, plans, cycles, assessments) stay, because they belong to the organization, not to you: the employer is the one who answers for them. You will see this stated explicitly on the screen, and not as fine print.

To stop only the proactive messages — relationship tips, emails — reply STOP. That deletes nothing; it only silences.

What we don't promise

  • It is not infallible against hostile content. The hold described above limits the damage from an instruction planted in external content; it does not eliminate the risk. No AI product on the market eliminates it.
  • It doesn't make things up by design, but models get things wrong. It is instructed to consult the live sources and to say it doesn't know instead of estimating. When the data matters — a number, a date, an amount — check it on the screen.
  • The hold does not cover voice, as stated above.

Keep reading