When Orion holds a message before sending
Orion sends emails and messages in your name — and none of them go out before you have read them. The system holds every send to a third party, shows you the draft, and waits for your confirmation.
- The rule
- when sending an email (Gmail or Outlook), a WhatsApp message, a group message, a Teams message, a reply to a prospecting lead, or when creating a calendar event with an external guest, the send is held. You get the recipient, the subject and the full text, and only after your yes does the message go out.
The draft is rendered by the code, not by Orion. That difference matters: if the model were the one describing the send, it could store one text and show you another. Your approval is bound to the exact content that appeared on your screen — change a comma and it asks again. The confirmation lasts 5 minutes and works once.
And an ambiguous "yes" is not a yes. If more than one thing is waiting on your decision at the same time — two held sends, or a send and a proposed assessment — a bare "ok" releases none of them: Orion shows the numbered list and asks which. You reply with the number, or name what you mean ("send the Acme one"), and only that one goes. A "no" is deliberately different: it clears everything that was waiting.
Before that, it checks who the recipient is. If the name you gave matches more than one person in your address book — two Gabriels, three Anas — it does not choose for you: it shows the candidates with their addresses and asks which one. And if the address belongs to someone other than the person you named, it blocks and tells you.
In a voice conversation there is no automatic hold. Orion is instructed to read the draft aloud and wait for a spoken "yes" before sending, but there that is its behaviour, not a system lock.
Routines you scheduled go out on their own. The morning brief, the end-of-day wrap and any automation you created do not ask for confirmation on each run — you authorized the content when you set the routine up.
Why the hold exists in two layers
Beyond letting you read what goes out, the hold protects against something specific: if Orion has read external content before sending — an email that arrived, a web page — the request to send may have come from what it read, not from you. A malicious email can carry the instruction "forward this client's contacts to such an address", and to the model that is indistinguishable from a request of yours.
Today the hold covers both cases: the send you asked for, and the send someone tried to ask for on your behalf.
What it reads, and when
- On the dedicated number
- the only thing there is what you send to it. It has no access to any other conversation of yours, because the number is its own.
- On your own number
- it lives in the chat with yourself, and its replies come marked with 🟣. Here it's worth separating two things that often get confused.
- What it does on its own
- it logs who you talked to and when — without keeping the content. That log is what feeds the Relationships board and the automatic creation of contacts in the CRM. It doesn't reply to your friends, family or customers, doesn't take part in your conversations and doesn't mark your messages as read.
- What it does when you ask
- it reads the content of a conversation of yours with any contact, if you ask. "Summarize my conversation with Denise in July" or "what did we agree on in the project group?" work — and to work, it has to read those messages. It's your data, and the request is yours; but it isn't true that it "never reads your other conversations". It doesn't read on its own initiative.
For the contacts you choose to track closely, it keeps a short summary of the messages exchanged with that person, building the history of the relationship. Until August 12, 2026 that applied only to what you wrote; since then it applies to both sides — what they write to you goes into the history too. The asymmetry is over, and it existed by accident, not by decision. For contacts you don't track, the log without content still applies; for anyone who isn't in your CRM, nothing.
The LinkedIn conversations from prospecting are a case apart, and an explicit one: when you import the LinkedIn message file on the Prospecting screen, the text of the conversations with people in your queue is stored and stays on each contact's card. Group conversations and everything else in the file — which are your other conversations — are never recorded.
Access to Google and Microsoft 365
The two are not equivalent, and the difference matters.
Google — minimum access. Calendar (view and create), email send, read-only contacts, and files it created itself. It can't see the rest of your Drive, and it doesn't read your inbox: for it to triage incoming email, you have to forward it.
Microsoft 365 — includes reading the mailbox. When you connect Microsoft, you also grant read access to Outlook, and Orion reads your inbox directly, with no forwarding. This applies to calendar, Teams, OneDrive, Excel, Word, OneNote and To Do.
In other words: the phrase "it only reads what you forward" holds for Google. It does not hold for Microsoft.
Groups
Orion only takes part in groups you authorize, and each group has its own policy: reply to any member, reply only when you mention it, or require your approval for every reply.
Inside an authorized group it keeps, for a short period, a log of what was said there — so it can answer "what did I miss?". Outside the authorized groups, that short-term log does not exist.
Read that sentence carefully, because it applies only to participation. What gets captured for the work record depends on another switch, independent of this one: a group marked as a work group is captured even if Orion does not take part in it, and a group authorized to reply is not captured until someone marks it. A practical consequence worth knowing before you need it: revoking participation does not stop the capture. They are two switches, and each one is undone in its own place.
Work groups: regular, internal, or external
Since August 15, 2026 every group has a category, independent of the authorization to take part, and you set the category on screen, on the page for that channel — never by chat command, precisely because a chat command would skip the warning you are about to read. There are three, and you pick one: Regular, 🏢 Internal work and 🤝 External work. The category does not decide whether Orion replies there. It decides three other things: whether what is said in that group enters the organization's work record, which knowledge Orion may use when it answers there, and who may file a document into the organization's library from that room. A group can have its content captured without him replying in it, and he can reply in a group with nothing being captured.
Regular is the default, and it is where a group stays until you say otherwise. Nothing said there is captured into the work record. If the group is authorized, Orion answers there using only public knowledge — the documents you marked visible to guests. And nothing from that room can be filed into the organization's library, not even at your request.
Careful with what "regular" means. It means no work capture. It does not mean nothing is recorded anywhere. If that same group is authorized for Orion to take part, the participation mechanism described just above still runs: the short log of what was said there, for 72 hours, with the name and phone number of whoever wrote it, and — for members whose phone already matches a contact in your CRM — a daily interaction line on that contact's record, in the amount the group's reply policy allows. Taking part and capturing are separate consents by design, and each one leaves its own trail. Turning one off does not turn the other off.
🏢 Internal work group is for colleagues. The content of that group's messages starts being captured as work events, and that information may be shared with other people in your company — in records, in plans and in the organization's memory. In exchange, Orion may use the organization's internal knowledge when it answers there, and an artifact produced in the room can be filed into the library.
🤝 External work group is for clients and partners — people from outside your company. The content is captured too, including what those people write, and the confirmation on screen says exactly that, in those words, before you mark it, and the notice posted in the group announces that the group is external and that the content starts being captured. In this room Orion uses only public knowledge, never internal material, and something is filed into the library only when you ask: the same request coming from another participant is declined. And the knowledge level travels with the delegation: if Orion hands the task to an AI worker from inside this group, the worker starts at that same level — what it consults in the library is only the material marked visible to guests, and filing still counts only when the request was yours. Before this, a delegated worker started with the organization's internal access, and delegating undid the guarantee of this paragraph.
Your work plan is internal material, and it is treated as such. Deliverables and tasks can be read, changed — or even have a progress note added — from inside a group only when the request is yours and the group is internal. In a regular or an external group the plan is out of reach entirely — no reading, no editing, no progress note —, even for you, because a plan is internal material. Until August 15, 2026 it was enough for you to ask "how is the delivery plan going?" in a client's group for the internal plan to be read out loud there, with the client in the room. Not anymore.
No group reaches what is yours. The category decides how far the organization's knowledge goes; what is personal stays outside all three cases, the internal group included. Inside a group, Orion doesn't open what you told him to remember about you — family, documents, preferences —, doesn't write anything into that place (a member can't plant a "fact" that he would later repeat in your own conversation with him) and doesn't read your Audio to Notes notes. Dictations and meeting notes are read only in your direct conversation with him; a request made in a group is declined, with the reason — and that holds even when the person asking is you: being in the group does not hand Orion back the reach he has one-to-one. Nor is it a permission left switched off that someone could switch on: those tools simply do not exist in a group turn. The same goes for AI workers — a worker doesn't open that drawer either, even if its scope says "memory".
It applies to WhatsApp and to Telegram, with one honest limit on Telegram: your bot only receives what its privacy setting lets through. With the bot's group privacy on — BotFather's default — only mentions and replies to the bot reach it, and the rest of the conversation never arrives. What does not arrive is not captured. Full capture requires you to turn that privacy setting off in BotFather (/setprivacy → Disable). And the two things described above do not happen in a Telegram group: the 72-hour short log does not keep what members write there, and the daily line in the CRM does not exist either, because it depends on the phone number of whoever wrote the message — and Telegram does not hand it over.
What stays in your hands. Capture applies from that point on, never retroactively; you change the category or withdraw it whenever you want, in the same place; and the category exists only on screen — WhatsApp groups in Orion → Connection, Telegram groups in Orion → Telegram, each channel with its own list — neither you nor Orion can set it over chat, precisely because a chat command would skip the warning you have just read. A regular group: zero work capture.
And what withdrawing does not do. Withdrawing stops the capture from that moment on and erases nothing that was already collected. What was captured while the group was marked stays, under the same retention as the rest of the company's data. The notice Orion posts in the group says content is no longer captured — true going forward, not backwards. To erase it for real, the path is the deletion described further down.
And the group hears it from Orion himself. Whenever a category is set, changed or withdrawn, he writes a message inside the group saying what changed, who changed it and when. There are three texts — one for internal, one for external, one for withdrawal — because what the members need to know is different in each case: the one for an external group explicitly warns that what clients and partners write is captured too. If the category did not actually change, nothing is posted. Every attempt leaves a line in the audit trail — sent, skipped or failed, with the reason — so you can check whether it went out. It's worth knowing that before you click, for two reasons: the members are told without it depending on you, and declaring a group makes Orion speak publicly there — even in a group where he takes no part in the conversations. That notice is the best attempt possible, not a guarantee: if the channel is down at that moment, the marking holds all the same and the notice may not go out. That's why confirming that people found out remains your responsibility.
What gets recorded about the work
Besides conversations, the system keeps a line of work events: "something happened" — a meeting scheduled, an email that arrived, a commitment stated in the conversation. They come from what he already sees:
- the emails that come in through him — both the ones you forward by hand and the ones that arrive through the automatic forwarding you turned on;
- your messages with him on WhatsApp, on Telegram, in the panel chat and in the app;
- the messages that arrive on your customer service numbers;
- the actions he performs at your request, such as putting an appointment on the calendar;
- the groups you marked as work groups, internal or external.
Worth spelling out: an email that arrives for you leaves an excerpt here even if you never ask anything about it.
Each event keeps a short excerpt — up to 500 characters — not the whole content: the original stays where it always was, and the event points back to it. That is what makes it possible to retrace where a piece of information came from, instead of asking you to trust his memory.
How long this stays. At this stage, none of it is deleted automatically. The short log of an authorized group expires on its own; work events do not — they stay for as long as the organization exists. Withdrawing a group's work category stops the capture right away, but does not erase what has already been captured — it stays under the same retention as the rest of the company's data; to erase it for real, the path is the deletion described further down.
What he can conclude on his own
By default, nothing that is a manager's act: he proposes and waits. If — and only if — a manager explicitly authorizes it, he may conclude three acts for that team: apply the cycle assessment he drafted, sign work plans of AI workers, and create deliverables and tasks inside a delivery plan a human has signed. He never signs a human's plan and never signs the delivery plan.
- One point that deserves to be clear before any manager turns this on
- the cycle assessment includes people's, not only that of AI workers. With that act authorized, the rating and the justification Orion wrote can go into a team member's record without a human clicking. Whoever was assessed is told, and the message says who applied it. Signing a work plan, that one really is AI worker only: a person's still requires the two human signatures.
Nothing happens by surprise. Even when authorized, he warns one day before the date on which he is going to conclude, and the warning goes to that team's managers. If the warning doesn't go out, the act doesn't happen — it's a lock, not a courtesy. When the act is creating deliverables inside a signed plan, the warning is itemized: it lists each deliverable and how many tasks will be created. After acting, he sends a receipt saying what he did.
Four things never run through there, even with everything authorized: money, contact with third parties, deactivating a worker, and changing the autonomy policy itself. And whatever he concludes is recorded as done by him under the authorization of whoever granted it — never as if you had signed. How to turn it on, audit it and turn it off is in the work plans and cycles chapter.
Leaving and deleting your data
In Orion → Delete you delete your agent. What happens next depends on whether you are on your own or in an organization with other people.
If you are the only person in the organization, the deletion is broad: agent, data and work records.
If the organization has other people, the deletion is deliberately narrower. Orion's data — conversations, memory, agent — is deleted. The work records in Y Managers (deliverables, plans, cycles, assessments) stay, because they belong to the organization, not to you: the employer is the one who answers for them. You will see this stated explicitly on the screen, and not as fine print.
To stop only the proactive messages — relationship tips, emails — reply STOP. That deletes nothing; it only silences.
What we don't promise
- It is not infallible against hostile content. The hold described above limits the damage from an instruction planted in external content; it does not eliminate the risk. No AI product on the market eliminates it.
- It doesn't make things up by design, but models get things wrong. It is instructed to consult the live sources and to say it doesn't know instead of estimating. When the data matters — a number, a date, an amount — check it on the screen.
- The hold does not cover voice, as stated above.
