· Neos· Design
Why Neos always asks before it writes
An assistant that acts on your data should answer for it before, not after. The confirmation card is not a safety net bolted on: it is the contract.
By The Eos team4 min read
There are two ways to wire an assistant into a workspace. The first lets it act and shows you what it did; the second has it announce what it is about to do and wait. They look alike in a demo. They have nothing in common on the day the assistant gets it wrong.
Reading is free, writing is not
Neos looks around without asking: overdue tasks, the quote document, this week’s calendar. Reading breaks nothing, and demanding a confirmation for every question would make the assistant slower than the interface it is meant to shortcut.
Every creation, change or deletion, on the other hand, goes through a card: what is about to happen, to what, and two buttons. You accept, you correct the proposal, or you refuse — action by action, never in bulk.
It never has more rights than you
Confirmation alone would not be enough: people accept out of reflex. So Neos acts with **your** permissions, not its own. What your role does not let you do, it cannot do either; what you are not allowed to see, it does not read. Rights are enforced server-side, in the same place as for the interface and the API — there is no way around, because there is no second way.
What it costs, and why it is worth it
It costs one click. That is real, and it is the price of an assistant you can actually use on data that matters — a team’s data, not a sandbox. An assistant you dare not let write is useless; an assistant that writes without asking ends up never being opened at all.
Same logic as for context: Neos remembers the current thread, so “open it” is enough once you have talked about a task. Context shortens the request; the confirmation does not get shortened.