Every action passes through a single checkpoint: six hard limits always apply, regardless of level and switches. After that, the chosen autonomy level decides whether Otto asks or acts. Every action ends up in the log without a gap, and an emergency stop halts everything instantly.
Contents
Docs overviewApprovals & security
Otto stops, before it gets serious
This page describes the tool-level view: which individual action sits on which level, when a card appears, and when no level in the world makes it disappear. The concept explanation with the full five-row table lives on “How it works”.
The four building blocks
- One card, the same everywhere
- Whether in the conversation or in the “Approvals” window — a waiting action always looks the same, grouped by risk, the most dangerous on top.
- Three autonomy levels
- One lever in the settings decides how much Otto does without your yes — from “always ask” to “autopilot”.
- Six hard limits
- Apply at every level and with every switch on — they are not a card, they are a refusal.
- A log without gaps
- Every action with trigger, reason and result — searchable, exportable as CSV, cannot be deleted.