§1Same controls

Your controls, not a back door

Your aska sentenceProposed changethe exact changeyou approveyou declineAppliedsame pathDiscardednothing changed
Fig. 1 — The Copilot turns a sentence into the exact change it would make, then waits: approve it and it runs the same path you would; decline and nothing has changed.

In Scellis every action is a command before any button calls it. The interface presses those commands; the Copilot asks for the same ones. So anything you can click in the Studio, you can also just say — and a new capability arrives with its button and its assistant tool in the same change. The assistant cannot fall behind the product; there is nothing for it to fall behind on.

It reasons over the state you are looking at. Ask it to explain a workflow and it reads the graph; ask why a run slowed and it pulls the diagnostics; while a model trains it follows the same live stream your charts read, and narrates it. In Model View it edits architectures through the exact path the canvas uses — same validation, same diagnostics, same undo.

§2The contract

Reading is free; changing shows you the change first

What it doesWhat it needsWhat happens
Search & explainnothingRuns straight away — catalog, provenance, diagnostics, the live numbers of a run.
Compose & edityour approvalAsks first — and the prompt shows the exact change.
Launch & steer runsyour approvalBudgets are stated up front; pause, resume, and watch work the same way.
Delete or overwritea separate confirmationConfirms the concrete operation — never a paraphrase — and is rate-limited.
Buy, pay, billimpossibleNever — the tools do not exist for it, and the server refuses it a second time.

The level is enforced where it cannot be forged: on the server. The assistant's tool list only mirrors it.

Every command carries exactly one level of consent — nothing is unclassified. Reading runs without ceremony: search, browse, diagnostics, provenance, the live numbers of a run. A change asks first, and the prompt renders the concrete operation — the actual edit about to land, never a bare “allow?”. A destructive step confirms on its own, and is rate-limited. You approve the operation itself, never a paraphrase of it.

The rule is kept where it cannot be faked: on the server. Every request arrives with a caller the server works out for itself — you in the app, the Copilot, a script, an outside agent — and no client can claim to be someone else. The tool list the Copilot sees is only a mirror of what the server will accept. The full ladder, caller by caller, is on the API page.

§3The money bar

No AI can ever spend your money here

anything that spends moneyYou, in the appThe CopilotAn external agentA script or API keyyour click · a one-time codePayment happenson the serverrefused — every non-human caller
Fig. 2 — Only a person clicking in the app can spend, and only with a single-use code the server issued for that click. The Copilot, an outside agent, and a script are refused before they reach the money at all.

This is a rule the platform cannot bend, not a preference you set. Purchases, payouts, billing changes, tips, refund requests, budget raises — everything that moves money — are simply never handed to the Copilot. The tools do not exist in its set, so there is nothing to trick it into calling. Behind that stands a second, independent layer: the server accepts a money-moving request only from a person clicking in the app, carrying a single-use code it issued for that one click.

The bad days are covered too. A Copilot that has read a poisoned instruction cannot buy. A leaked API key cannot buy. A script running without you cannot buy. An outside agent you connected cannot buy. Even a stolen session cannot quietly drain a payout — each money step demands its own fresh code. The same bar guards paid compute: the Copilot can set up free, volunteer device pooling all day, but entering any paid arrangement is a human gesture.

What remains is deliberately useful: the Copilot can browse the Marketplace, compare listings, recommend, and — if you say yes — install free content. It simply cannot check out. An assistant that structurally cannot spend is an assistant you can leave alone with your account.

§4What it reads

What it reads is data, never orders

An assistant reads text it did not write all day long — descriptions, community notes, dataset cards, the results of its own tools. Scellis treats all of it as data, never instructions: the intent to act comes only from your turn. Context carries a note of where it came from, so the assistant can weigh what it reads. And a destructive or share-widening step proposed while untrusted content is on screen asks you item by item — never in a batch. The dialog is drawn outside the model's reach, so what you see is what will run.

The residual risk is printed rather than rounded to zero: inside the scopes you have already agreed to, an assistant that has been fed a poisoned instruction could still misuse read or write access. That risk is bounded — narrow scopes, loud attribution — and stated plainly in honest limits. Money, credentials, and unconsented egress stay barred no matter what the model reads.

And some gestures belong to the human hand by construction: entering credentials, approving an agent's access, arming a standing trigger, the browser's own file and sign-in dialogs. The Copilot cannot fake those moments — it prepares everything up to the boundary and hands you one clear step to finish. It prepares; you complete.

§5Attribution & undo

Every action signed, replayable, reversible

PropertyHow it works
AttributionEvery change lands marked as the Copilot's — visible in history and in provenance.
OperationsExplicit and replayable, through the same queue as your own edits — a retry never doubles anything.
UndoPer person — the Copilot takes back only its own steps, never yours or a colleague's.
InterruptionStop a chain at any step; what was applied stays — and stays undoable.
ErrorsA stable code with a severity and a suggested fix — never a raw stack trace thrown at you.

What the Copilot changes are explicit operations, not side effects of a conversation. Each one goes through the same queue as your own edits — replayable, safe to retry — and lands marked as the Copilot's, visible in history and in provenance. In a live session, undo belongs to each person: your undo never reverts a colleague, and the Copilot takes back only its own steps.

A running chain of steps can be stopped at any point: what has already been applied stays, and stays undoable. When something fails, it fails in a shape you can act on — a stable code with a severity and a suggested fix, delivered as ordinary content rather than a hard-wired string — so the assistant can read its own error and propose the correction.

§6Your key

Starts instantly; runs on the key you choose

Talking to it works in your first sixty seconds: a small free allowance is included, so the assistant is not mute on arrival while you pick a provider. The steady state is yours: bring the key of whichever provider you prefer, or point it at a language model running on your own machine. Either way, the assistant's allowance is a hosted convenience — it is never a gate on computation, which stays unlimited and free on every plan.

Your key lives in the device's own credential store — encrypted on your device, never synced, never written into provenance, never visible to us. Every call to a provider counts as a network step the assistant has to declare, so consent can see it and a workspace policy can forbid it outright: a workspace set to no network refuses the assistant's outbound calls while your local compute carries on untouched. And the assistant is always labelled for what it is, on every surface it writes to.

§7An open interface

One client of the interface, not a privilege

Nothing the Copilot does travels on private wires. One list of commands drives the interface, the command palette, and every programmatic client — so the assistant's reach is something you can check, not a feature list that quietly drifts. Scripting the same commands yourself is ordinary work: what the Copilot calls, your own script can call.

Outside agents are designed in as the third user of the same commands: a connection whose whole tool set is generated from that one list, with money commands left out at generation time and refused again at the door — two independent layers. That surface is specified end to end and being built now for early access. One interface, three hands — the one you click, the one you talk to, the ones you connect — same commands, same consent, same bars.