· Neos· Design

Why Neos always asks before it writes

An assistant that acts on your data should answer for it before, not after. The confirmation card is not a safety net bolted on: it is the contract.

By The Eos team4 min read

There are two ways to wire an assistant into a workspace. The first lets it act and shows you what it did; the second has it announce what it is about to do and wait. They look alike in a demo. They have nothing in common on the day the assistant gets it wrong.

Reading is free, writing is not

Neos looks around without asking: overdue tasks, the quote document, this week’s calendar. Reading breaks nothing, and demanding a confirmation for every question would make the assistant slower than the interface it is meant to shortcut.

Every creation, change or deletion, on the other hand, goes through a card: what is about to happen, to what, and two buttons. You accept, you correct the proposal, or you refuse — action by action, never in bulk.

The confirmation card: nothing runs without your say-so.MP4GIF

It never has more rights than you

Confirmation alone would not be enough: people accept out of reflex. So Neos acts with **your** permissions, not its own. What your role does not let you do, it cannot do either; what you are not allowed to see, it does not read. Rights are enforced server-side, in the same place as for the interface and the API — there is no way around, because there is no second way.

What it costs, and why it is worth it

It costs one click. That is real, and it is the price of an assistant you can actually use on data that matters — a team’s data, not a sandbox. An assistant you dare not let write is useless; an assistant that writes without asking ends up never being opened at all.

Same logic as for context: Neos remembers the current thread, so “open it” is enough once you have talked about a task. Context shortens the request; the confirmation does not get shortened.

Read next