Autonomy is opt-in, feature by feature
Typed thresholds, not blanket permission
Autonomy is opt-in, feature by feature
Nothing runs on its own until you say so. Under Settings → Agent, the master autonomy switch sets the default posture: with it off, the agent only proposes actions and you approve each one; with it on, routine work inside your limits runs by itself. There is no vague "suggest mode" in between — each capability is either something you approve or something the agent is cleared to handle within a limit you set.
The same screen lists the individual capabilities you can enable: auto-replying to tenant messages, triaging and dispatching maintenance, waiving small late fees, drafting renewals, and running rent collection. Turn on only the ones you are comfortable with and leave the rest as propose-and-approve. Autopilot is a one-click preset that flips the switch and the dials to a conservative starting point you can adjust anytime.
Typed thresholds, not blanket permission
Enabling a feature does not hand the agent a blank check. Each one carries a typed limit. Settings → Agent → Per-task spend limits lets you cap autonomous spend by category — repairs and dispatch, approvals, late fees, late-fee waivers, lease renewals, and rent collection — with a per-action cap plus optional daily and monthly ceilings. Leave a field blank for no limit of that kind; set a cap to 0 to always require your approval for that action.
Under a cap, the agent acts. Over it, the action routes to your review queue instead. Daily and monthly ceilings also count actions still sitting in their safety window, so a fast burst can never slip past the limit a piece at a time. Repairs can be restricted to your preferred vendors, and renewal drafts are bounded by a maximum rent-increase percentage.
Some decisions are never automated, no matter how you set the dials. This is a compliance and liability floor, and no threshold or custom rule can lift an action past it.
The agent never denies an applicant (FCRA requires a human decision plus an adverse-action notice), never files an eviction, and never terminates a lease. It also will not move an unusually large sum in a single transfer or issue a refund above a set amount without you. For these, the agent can gather information, draft the paperwork, and tee the decision up — but the decision itself stays with you.
Actions that cannot be taken back — moving money, posting to the ledger, sending an outbound notice — do not fire the instant the agent decides. They are held for a short soft-commit window (about 15 minutes) during which you can stop them. During the hold the action appears in your queue with a live countdown and a Stop control, and the same cancel link travels in the push and SMS alerts, so you can intercept from your phone without opening the app.
Lower-risk, easily reversible actions skip the hold and simply run, because undoing them afterward is trivial. And if anything ever looks wrong, the emergency stop on the Agent screen pauses all autonomy at once and voids whatever is still inside its window — your settings are preserved and everything routes back to your review queue until you resume.