Six hard limits always apply: they are not a card you can click away, they are a refusal. Everything else ends up in the log without a gap, which can be searched and exported as CSV. One click on “stop everything” halts every automatic action instantly, without losing anything.
Contents
Docs overviewApprovals · Hard limits, log & emergency stop
What no level can lift
Six limits stand before every autonomy level and before every “without asking” switch. They do not ask — they say no, precisely at the point where asking itself would become the trap: when an instruction comes from someone else’s message.
The six hard limits
- G1 Emergency stop pressed
- While it is engaged, absolutely nothing happens — there is nothing to weigh here.
- G2 Suspected loop
- A job ran unusually often — Otto stops itself so nothing runs out of control.
- G3 Admin rights from outside content
- A command needing admin rights whose task comes from someone else’s message is refused outright — not even presented for approval. This cannot be unlocked.
- G4 Irreversible deletion from outside content
- If the trigger for a permanent deletion comes from someone else’s message, Otto refuses — even with “delete without asking” switched on. The trash is unaffected by this; that still runs without a card.
- G5 Money from outside content
- A payment whose trigger stems from someone else’s message is refused — this is exactly what fraudulent payment requests look like.
- G6 Deleting memory when the run touched outside content
- Otto never deletes a memory because of an email or a web page — that is also where the rules you gave it live. ADDING a new memory is unaffected by this.
Quiet hours — with one exception
At the “always ask” and “balanced” levels, Otto holds outgoing mail back until your working hours begin — nothing is lost, it waits. In autopilot, as of 19 Sept 2026, no clock applies anymore by explicit design: whoever chooses this level does not want quiet hours, by their own account, and Otto also sends at night and on weekends. The six hard limits above remain in force regardless.
The log
- What it records
- Timestamp, trigger, action, result and reason for every action — the full wording once expanded.
- Four results, not one bucket
- Successful, waiting, refused or failed look distinct — a deliberate refusal only carries the warning colour, only a genuine failure gets the sharper danger colour.
- Searchable and exportable
- Filter tabs by result type, a CSV export for job and run histories.
- Cannot be deleted
- No entry can be removed from the log — it is the one place where nothing disappears after the fact.
The emergency stop
“Instantly halts every automation: no jobs, no mail, no reading along. Nothing is lost, everything waits.” One click on “start again” lifts it — any approval that was pending in the meantime is still there, still waiting for your yes.
Known gaps in this documentation build (as of 26 Sept 2026)
- Confirming or declining an approval in the “Approvals” window is only tested at the core logic level, not via a click in the window itself; the same applies to permanently allowing a tool call or a third-party tool server.
- Live-reloading the list when a new event arrives has no automated test — only checkable live.
Next: Memory, quota & account Back to the three autonomy levels