When Orion holds a message before sending
Orion sends emails and messages in your name — and none of them go out before you have read them. The system holds every send to a third party, shows you the draft, and waits for your confirmation.
- The rule
- when sending an email (Gmail or Outlook), a WhatsApp message, a group message, a Teams message, a reply to a prospecting lead, or when creating a calendar event with an external guest, the send is held. You get the recipient, the subject and the full text, and only after your yes does the message go out.
The draft is rendered by the code, not by Orion. That difference matters: if the model were the one describing the send, it could store one text and show you another. Your approval is bound to the exact content that appeared on your screen — change a comma and it asks again. The confirmation lasts 5 minutes and works once.
Before that, it checks who the recipient is. If the name you gave matches more than one person in your address book — two Gabriels, three Anas — it does not choose for you: it shows the candidates with their addresses and asks which one. And if the address belongs to someone other than the person you named, it blocks and tells you.
In a voice conversation there is no automatic hold. Orion is instructed to read the draft aloud and wait for a spoken "yes" before sending, but there that is its behaviour, not a system lock.
Routines you scheduled go out on their own. The morning brief, the end-of-day wrap and any automation you created do not ask for confirmation on each run — you authorised the content when you set the routine up.
Why the hold exists in two layers
Beyond letting you read what goes out, the hold protects against something specific: if Orion has read external content before sending — an email that arrived, a web page — the request to send may have come from what it read, not from you. A malicious email can carry the instruction "forward this client's contacts to such an address", and to the model that is indistinguishable from a request of yours.
Today the hold covers both cases: the send you asked for, and the send someone tried to ask for on your behalf.
What it reads, and when
- On the dedicated number
- the only thing there is what you send to it. It has no access to any other conversation of yours, because the number is its own.
- On your own number
- it lives in the chat with yourself, and its replies come marked with 🟣. Here it's worth separating two things that often get confused.
- What it does on its own
- it logs who you talked to and when — without keeping the content. That log is what feeds the Relationships board and the automatic creation of contacts in the CRM. It doesn't reply to your friends, family or customers, doesn't take part in your conversations and doesn't mark your messages as read.
- What it does when you ask
- it reads the content of a conversation of yours with any contact, if you ask. "Summarize my conversation with Denise in July" or "what did we agree on in the project group?" work — and to work, it has to read those messages. It's your data, and the request is yours; but it isn't true that it "never reads your other conversations". It doesn't read on its own initiative.
For the contacts you choose to track closely, it keeps a short summary of what you send to that person, building the history of the relationship.
Access to Google and Microsoft 365
The two are not equivalent, and the difference matters.
Google — minimum access. Calendar (view and create), email send, read-only contacts, and files it created itself. It can't see the rest of your Drive, and it doesn't read your inbox: for it to triage incoming email, you have to forward it.
Microsoft 365 — includes reading the mailbox. When you connect Microsoft, you also grant read access to Outlook, and Orion reads your inbox directly, with no forwarding. This applies to calendar, Teams, OneDrive, Excel, Word, OneNote and To Do.
In other words: the phrase "it only reads what you forward" holds for Google. It does not hold for Microsoft.
Groups
Orion only takes part in groups you authorize, and each group has its own policy: reply to any member, reply only when you mention it, or require your approval for every reply.
Inside an authorized group it keeps, for a short period, a log of what was said there — so it can answer "what did I miss?". Outside the authorized groups, nothing is logged.
Leaving and deleting your data
In Orion → Delete you delete your agent. What happens next depends on whether you are on your own or in an organization with other people.
If you are the only person in the organization, the deletion is broad: agent, data and work records.
If the organization has other people, the deletion is deliberately narrower. Orion's data — conversations, memory, agent — is deleted. The work records in Y Managers (deliverables, plans, cycles, assessments) stay, because they belong to the organization, not to you: the employer is the one who answers for them. You will see this stated explicitly on the screen, and not as fine print.
To stop only the proactive messages — relationship tips, emails — reply STOP. That deletes nothing; it only silences.
What we don't promise
- It is not infallible against hostile content. The hold described above limits the damage from an instruction planted in external content; it does not eliminate the risk. No AI product on the market eliminates it.
- It doesn't make things up by design, but models get things wrong. It is instructed to consult the live sources and to say it doesn't know instead of estimating. When the data matters — a number, a date, an amount — check it on the screen.
- The hold does not cover voice, as stated above.
