Skip to main content
OCTOVO

Six hard limits always apply: they are not a card you can click away, they are a refusal. Everything else ends up in the log without a gap, which can be searched and exported as CSV. One click on “stop everything” halts every automatic action instantly, without losing anything.

Contents Docs overview

Approvals · Hard limits, log & emergency stop

What no level can lift

Six limits stand before every autonomy level and before every “without asking” switch. They do not ask — they say no, precisely at the point where asking itself would become the trap: when an instruction comes from someone else’s message.

The six hard limits

G1 Emergency stop pressed
While it is engaged, absolutely nothing happens — there is nothing to weigh here.
G2 Suspected loop
A job ran unusually often — Otto stops itself so nothing runs out of control.
G3 Admin rights from outside content
A command needing admin rights whose task comes from someone else’s message is refused outright — not even presented for approval. This cannot be unlocked.
G4 Irreversible deletion from outside content
If the trigger for a permanent deletion comes from someone else’s message, Otto refuses — even with “delete without asking” switched on. The trash is unaffected by this; that still runs without a card.
G5 Money from outside content
A payment whose trigger stems from someone else’s message is refused — this is exactly what fraudulent payment requests look like.
G6 Deleting memory when the run touched outside content
Otto never deletes a memory because of an email or a web page — that is also where the rules you gave it live. ADDING a new memory is unaffected by this.

Quiet hours — with one exception

At the “always ask” and “balanced” levels, Otto holds outgoing mail back until your working hours begin — nothing is lost, it waits. In autopilot, as of 19 Sept 2026, no clock applies anymore by explicit design: whoever chooses this level does not want quiet hours, by their own account, and Otto also sends at night and on weekends. The six hard limits above remain in force regardless.

The log

What it records
Timestamp, trigger, action, result and reason for every action — the full wording once expanded.
Four results, not one bucket
Successful, waiting, refused or failed look distinct — a deliberate refusal only carries the warning colour, only a genuine failure gets the sharper danger colour.
Searchable and exportable
Filter tabs by result type, a CSV export for job and run histories.
Cannot be deleted
No entry can be removed from the log — it is the one place where nothing disappears after the fact.
An excerpt from the log re-enacted Re-enacted log excerpt with three rows: an ad email was filed, a draft to Möbelwerk Reinhardt is waiting for approval, and the approved reply was sent — each row with a time, result and reason.

The emergency stop

“Instantly halts every automation: no jobs, no mail, no reading along. Nothing is lost, everything waits.” One click on “start again” lifts it — any approval that was pending in the meantime is still there, still waiting for your yes.

Known gaps in this documentation build (as of 26 Sept 2026)

  • Confirming or declining an approval in the “Approvals” window is only tested at the core logic level, not via a click in the window itself; the same applies to permanently allowing a tool call or a third-party tool server.
  • Live-reloading the list when a new event arrives has no automated test — only checkable live.

Next: Memory, quota & account Back to the three autonomy levels