Manual

The AI team

Up to here Orion has worked alone for you. Here it stops being only your manager and gains a team: AI workers you hire, each with a name, a role description, a set of released tools, a work plan and a cycle assessment — supervised by Orion and governed by rules you define. And it goes beyond your chat: the WhatsApp and Telegram groups you authorize (since August 15, 2026 both channels follow the same rule) are the other room where your Orion talks to people who are not you — and therefore the one that requires you to say, clearly, how far it can go.

Read in: Portuguese · Spanish

Your Orion and AI workers are not the same thing

Before you hire the first one, it is worth separating two things that look alike and are not:

Your Orion is yours. Each person has their own. It is the instance that talks to you on WhatsApp or Telegram, holds your memory, knows how you work and follows your plan. If someone on your team never chats with Orion, that person simply does not have one — and goes on using Y Managers through the panel as usual.

An AI worker belongs to the organization. It is not owned by a person: the administrator hires it, the team sees it, it is assigned to teams and it answers for deliverables inside the company's work plans. Several different Orions can delegate to the same worker.

The difference shows up on the bill: your Orion follows your plan — that is what decides your channels and limits — while an AI worker is hired by the organization, with its own monthly price. Having one does not give you the other.

Hiring and directing AI workers

An AI worker is a team member who is not human. It has a name that appears on the screens, a role description written by you, a closed set of tools, a work plan with deliverables it answers for, cycles, and an assessment at the end of each cycle. You hire it, give it work through chat, decide how much it can do on its own, and see everything it did in an audit trail.

The place for all of this is Orion → AI Workers Team (the page is titled "AI Team Governance").

Hiring your first worker

Open the page and you find the Hire a worker gallery: ready-made samples, each with what it does, the tools it uses, the integrations it needs and the monthly amount — all on the card, before you click. One click hires. In organizations already enabled for autonomous execution, the AI Manager then proposes its first work plan as an editable draft, and you sign it whenever you want; everywhere else, you are the one who creates the worker's work plan.

If an integration the sample requires is not yet connected on your account, the card warns you with a ⚠️ before the click. The worker is hired anyway, without it, and the screen says what was left out — never silently.

Prefer to build one from scratch? Add AI worker opens the same form you use later to edit:

Name
how it appears on the screens and how you call it in chat — "Marketing (Content)", "Sales (SDR)".
Instructions
the role description. Responsibilities, tone, boundaries. Orion reads this text every time it delegates work to the worker. It is where you write things like "always propose 3 options" or "never publish anything — deliver drafts".
Skills
the tools it may use (Internet, Google, Microsoft 365, Email, WhatsApp, CRM, Relationships, Booking, Routines, Memory, Deep research…). Only what is ticked is available; everything else is blocked at call time. Leaving everything unticked does not release everything — since August 13, 2026 it is the opposite: the worker gets a basic set, enough to work and account for itself. The basics include researching and reading (the internet, pages, this manual, the organization's library), thinking (its own scratchpad, data analysis), delivering (recording an artifact, creating and reading a document, recording progress), accounting for the work (cycle report, declaring a capability gap) and asking a colleague for help. Deliberately left out: CRM, prospecting, email, calendar and delegating to another worker — anything with an external recipient or a contractual consequence only comes in if you tick it.

Your personal memory does not come in — not for any worker. Since August 15, 2026, the tools that read and write what you told Orion to remember (family, documents, preferences) and your Audio to Notes notes are stripped out of every worker run, including the run of a worker with "Memory" ticked under Skills: ticking that skill gives it its own scratchpad and the reading of this manual, never your drawer. An AI worker is a colleague at work, and a colleague does not open the boss's drawer — nor write inside it. It thinks on its own scratchpad, consults the organization's library when it needs to know something about the work, and that is where it files what it produces.

Integrations
the third-party accounts you connected in Orion → Integrations, released worker by worker. Being connected is not enough — each worker only uses the ones you ticked for it.
Posture
the default leash. That is the subject of the next section.

Hiring a worker is a monthly line item on your subscription, and that is why it requires an active subscription: without one, hiring is refused on the spot, saying the subscription is missing. There is no free path — the team panel's free period gives seats, not workers (free workers that already existed before were not canceled). The amount is on the gallery card and on the pricing page.

Hired is not the same as working. A worker that has not yet been assigned to a team refuses any delegation, saying exactly that — and it keeps counting on your invoice. There are two steps, and the second one is yours: assign the worker to a team and sign its work plan. Until that happens, it exists, it shows up on the screens, it is billed, and it does nothing.

Two separate things: the work and the identity

Every worker you hire automatically gets a person identity in the organization — with an AI tag. That is why it shows up on the team screens, can be added to a team and gets a work plan like anyone else. The work record (price, autonomy, runs) is one thing; the organizational identity is another. You manage the worker the same way you manage people, with no parallel screen.

Two practical consequences: this identity does not consume a human user seat, and it cannot be removed directly on the Users page. To shut the worker down, you remove it in Governance — you don't delete the puppet, you dismiss the worker.

And the one current plan per period rule applies: an AI worker serves one team, like a person. If you want the same function on two teams, hire two workers. Trying to create a second, overlapping plan for the same worker is refused, with the explanation on screen.

Giving it work

Through chat, talking to Orion:

  • "Ask Marketing to review this post." (and paste the post)
  • "Have Research & Analysis pull the 5 biggest players in this market."
  • "What did Sales do this week?"

Orion delegates by passing the worker's exact name. If you use a fragment that matches more than one — three workers with "Marketing" in the name, on different teams — it refuses and asks for the full name instead of guessing. If no worker on the team covers the request, it says so and does the work itself, or tells you there is nobody to do it.

The delegation carries the full content (the worker does not see your chat) and the files you just sent. The worker comes back with a report of what it did — and with the list of what is sitting still, waiting on you.

When the request matches a deliverable on the worker's current plan, Orion ties the delegation to that deliverable. That is how the work shows up on the plan, where the humans on the team see it. If it matches nothing, it delivers and tells you: "that fell outside Marketing's plan — want me to add it?"

The autonomy matrix

Every action a worker tries to execute is classified by code, before it happens, and sent down one of three routes:

🟢 Runs alone
the action happens. It is still recorded in the audit trail.
🟡 Orion approves
Orion runs a separate review, with a manager's head and explicit criteria (does the action serve the task? is the recipient right? is the content professional and free of invention? what is the risk if it is wrong?), and approves or rejects. If the review fails for any reason, the action is rejected — never let through by default.
🔴 Ask me
the action is held, complete, in the "Awaiting your approval" queue. Nothing happens until you decide.

The worker's posture sets the default route for each action class. There are six classes and three postures:

Action classShadowGatedAuto
Internal / reversible (CRM, records, drafts)🟡🟢🟢
External — known contact🔴🟡🟢
External — new recipient🔴🔴🟡
WhatsApp group reply🔴🔴🟢
Financial / billing🔴🔴🔴
VIP contacts🔴🔴🔴

In each worker's table you can pin an exception: clicking a route on that class overrides the posture default. "Clear rule" returns it to the default. The Autonomy section stays collapsed when everything is on the default and opens by itself when that worker has exceptions — a rule you can't see is worse than the noise it saves you.

How the classification is done, in code and without guessing:

Known or new recipient
known is someone already in the organization's CRM (or in your personal CRM). Anyone who is not is new. If the CRM lookup fails, "new" wins — the more cautious side.
A message to you
the worker sending a message or email to the boss is a report, not an external action. It counts as internal.
A calendar event
it is only external when it has guests. With no guests, it is internal.
An unknown tool
any tool with no declared classification is treated as "new recipient". The default is to close, not to open.

Two honest notes about the table. Financial and VIP contacts exist as rows and your rules for them are respected — but today no tool is automatically classified into those two classes, because the platform does not yet have a deterministic signal for "this is money" or "this one is a VIP". The two rows are ready for when there is one.

And the exception worth understanding: a signed plan is authorization. When the action is tied to a task or deliverable on that worker's work plan signed by both parties, it runs straight through, even if the class route would have asked for review — because signing the plan is approving that work, and supervision becomes progress and the cycle assessment. Financial and VIP are never released through this path.

The "Awaiting your approval" queue

When an action lands on the 🔴 route, it is stored whole — tool, recipient, text — and you get this on WhatsApp:

> 🔴 Pending approval — AI team > Marketing prepared send_gmail (a3f91c22). > … > Reply approve or reject — or decide on the Governance page.

You decide in two ways:

  • In chat: "approve", "reject". With more than one pending, it shows the numbered list and you reply "approve number 1".
  • On the Governance page: the "Awaiting your approval" block shows recipient, subject and the beginning of the text, with the Approve & run and Reject buttons.

Approving runs the action exactly as the worker prepared it — your decision is the gate, there is no second check. Rejecting discards the prepared action.

When the escalation is the only thing waiting on you, a bare "approve" is read as a decision about that queue, and not as approval of some other topic in the conversation.

With more than one decision open, he asks instead of guessing. If two escalations are pending at once, or an escalation and a held send, or a proposed assessment and an email waiting for your yes, a bare "ok" decides none of them: Orion shows the numbered list and asks which one, and nothing happens until you answer. You settle it in two ways — reply with the number, or name what you mean ("send the Acme one"), which decides only that one. A "no" is deliberately different: it applies to everything open, because letting out what you told him not to send has no undo.

The audit trail

At the bottom of the page, each classified action from each worker becomes a line: who, which tool, which route, which outcome. You can filter by worker, route, class, text and date range.

What lands there is not only what happened. A reply Orion decided not to give in a group (because the policy was "boss-only") also becomes a line — explained silence is better than mysterious silence. A send that failed is recorded as a failure, not as "sent".

The worker inside the team's cycle

This is the point that separates an AI worker from a loose automation: it goes through the same ritual as a human.

Work plan
the plan belongs to the worker and must be tied to a team. It is what says which deliverables the worker answers for. A worker with no current plan can still work when you ask through chat, but its work belongs to no deliverable — and the worker itself is instructed to declare that in its report.

An overdue renewal = a worker that is stopped, paid for and silent. Daily execution — the part where it works on its own — only reaches a worker whose plan is signed by both parties and inside its period. Once the renewal falls due with no signature, it stops waking up, and it stays hired and billed. So that this does not go unnoticed, once the normal reminders are exhausted the worker starts speaking for itself, once a week: "I'm Iris. My renewal fell due on August 20 and I'm stopped, waiting for your signature" — with the proposed period, the deliverables and a personal authorization link for each manager on the team.

Cycle report
the worker writes and submits its own report, starting on the last day of the cycle, like any team member — what it delivered, with links, results, open items and next steps. Once submitted, it freezes and goes to the manager.
Assessment
the worker never assesses its own cycle. The system refuses the attempt. The manager is the one who assesses: Orion drafts the proposed assessment (stars + justification), files it as a pending proposal in your "Waiting on you" box and waits for your decision. Once applied, it freezes a performance record — with mandatory justification, as in a human's cycle.

Two things can happen without you, and it is better to know about both. If the assessment deadline passes with nobody deciding, the cycle closes on its own with a neutral 3★, and the justification says, in so many words, that the manager gave no feedback in time — the cycle is stamped as automatic. And if the team manager has turned on the "Assess cycles for me" autonomy, Orion applies on the date the assessment it drafted itself, with a heads-up the day before and a receipt afterwards. In both cases the screen shows where that rating came from.

Continuous progress
the worker is instructed to record progress at the moment it happens, not at the end of the cycle. Whoever reads "What was done" sees the mark of who did it: a worker's notes are filed under its name with the AI tag.
The CLEAR canon, and where it is asymmetric
to enter a work plan, a deliverable has to come from a signed, current team deliverables plan. There is no exception here for anyone — the platform refuses to add it, for a human exactly as for an AI worker, with the explanation. The rule holds until the work plan is signed by both parties; after that the agreement stands, and a deliverables plan that expires does not undo what was agreed. The asymmetry sits in a different rule: when the deliverable is broken into tasks and the plan points at none, the human is warned and carries on, and the AI worker is blocked — the human exception is usually legitimate; the AI one is not.

Cost, removal, and the honest limit

Each worker shows a measured-cost badge: how much it consumed in the current month and over the last 7 days, with the number of runs. Until there is a measured run, the screen says "no measured activity yet" instead of showing zero — no measurement is not the same as no work. Orion (the manager) appears in the list as a line of its own: management costs something, and its cost is spread across the workers' prices.

Each worker has a usage allowance of its own. Since August 13, 2026, what a worker spends does not come out of your personal allowance for talking to Orion, nor out of the organization's management allowance: each worker has an account of its own, with one cap per day and another per month. That is what makes the cost badge comparable between them. If the day's allowance runs out, the delegation is refused saying the worker's name and the cause, the work is not lost (it picks up again when the day turns) and the Admins are notified — a worker going silent with no explanation would be the worst possible outcome.

Remove deactivates the worker immediately: it stops acting, its pending approvals are canceled and the audit history is kept.

And the limit: daily autonomous execution — the worker waking up every day, pulling the next task from the plan and working without anyone asking — is in gradual rollout, enabled organization by organization. Outside of it, the worker works when Orion delegates (at your request or through a routine you created). Hiring, scope, the autonomy matrix, escalations, the work plan and the audit trail all hold from day one; the automatic cycle report and the manager's proposed assessment arrive with that same enablement.

WhatsApp and Telegram groups

In a group, Orion talks to people who are not you. Taking part and capturing are two separate switches, and neither turns itself on.

When Orion is on your own number, it records the groups where traffic passes — only the name and the date of the last activity. None of the content. You see that list in Orion → Connection, in the "WhatsApp groups" block, and you can also ask in chat: "which groups are you seeing?".

Authorizing a group is what changes the game. The screen asks for confirmation and says what will now happen, because the decision affects other people: an AI starts taking part in a room where nobody signed anything.

There is a second switch, and it is independent of this one. Every group has a category, and it does not make Orion reply there. There are three, and you pick one on the group's own row:

CategoryWhat is capturedKnowledge it uses thereWho can file into the libraryWork plan
Regular (the default)None of the contentPublic only — documents marked visible to guestsNobodyOut of reach, including for you
🏢 Internal work (colleagues)All the content, for the organization's work recordThe organization's internal knowledgeAnyone in the group can askYou read it and change it from there
🤝 External work (clients, partners)All the content, including what the outside people writePublic onlyOnly you — a request from another participant is refusedOut of reach, including for you

The category exists only on screen (never through a chat command, precisely so the warning it shows is not skipped), it applies from that point on and is never retroactive, and you change it or withdraw it whenever you want. Regular group: zero work capture.

And the one who tells the group is Orion, not you. When you mark it, when you change the category and when you withdraw it, it posts a message inside the group saying what changed, who changed it and when. The text is different in each case: the external-group one announces that the group is external, that the content is now captured, that Orion uses only public knowledge there and that it files things only at your request. (The one that spells out that what clients and partners write also comes in is the confirmation on screen, before you mark it.) Clicking the category that was already in force changes nothing and posts no notice. Every attempt stays in the audit trail, including when the notice cannot go out — the notice is the best effort possible, not a guarantee.

Withdrawing does not erase. Capture stops at once, but what was already captured stays stored, with the same retention as the rest of the company's data.

On Telegram the same category applies, with a limit that comes from Telegram itself. With the bot's group privacy on — BotFather's default — only mentions and replies to the bot reach it, and only that is captured. For full capture, you have to turn privacy off in BotFather (/setprivacyDisable).

The detail is in the security and privacy chapter.

How it gets triggered. Only when called. @orion anywhere in the message counts, as does "Orion," or "Orion:" at the start of the sentence, or a reply that quotes one of its messages — quoting Orion is talking to Orion. The name "Orion" loose in the middle of a conversation triggers nothing.

When called, it acknowledges right away ("Got it! I'm looking at it and I'll be back here in ~2-3 min") and answers next. Every message it sends goes out signed 🤖 Orion (AI manager) — it never passes itself off as human, and it does not write that signature: the system adds it.

The mention is the instruction. Whatever the message asks for is what it does: review a piece of content, summarize the recent discussion, answer a question, record progress on a task, write a draft. There is no single request format.

The group policy defines who can trigger it and what happens to the reply. It is per group, and it overrides the general policy in Governance:

LightWhat happens in the groupWhat lands in the CRM
🟢 Replies to everyoneReplies to any memberOne line per day per contact, with a summary of what the person discussed
🟡 Boss-onlyReplies only when you mention it; mentions from others are silently ignored (and logged in the audit trail)Presence only (message count)
🔴 Always ask meEvery reply goes to your approval queue before being postedNothing

With nothing chosen, the group inherits the general policy. And CRM capture only reaches people who are already contacts of the organization: someone not in the CRM never enters it because of a group.

The role in the group. Each authorized group can have a role of its own — free text that frames its behavior there: "Customer support: answer product questions in a formal tone; never discuss pricing — refer to the boss." With no role set, it acts as content manager, the default. The role sets tone and boundaries; the message that mentions it is still the instruction.

Who asked matters — and so does the group's category. If the mention came from you, it executes in full, and in an internal work group that includes managing work plans, deliverables and tasks in Y Managers, right from there. In a regular or an external work group the plan is out of reach even for you — reads, edits and progress notes alike: asking "how is the deliverables plan going?" in a client group would read the internal plan out loud in front of the client, and that is exactly the opposite of what that group's notice promises. If it came from another member, it helps within that group's scope of work and does not act outside the group at a third party's request: a group turn does not reach your inbox, your calendar or your other conversations. And your personal memory is not there to be exposed — since August 15, 2026 the tools that read and write what you told it to remember, and your Audio to Notes notes, do not enter a group turn — in no group, declared or not, and even when the one mentioning it is you. It is not an instruction it could disobey: the tool does not exist there. It holds both ways — nobody reads your personal memory from a group, and nobody plants a "fact" about you there that Orion would later repeat in your direct conversation. The same removal reaches any worker on your team triggered from there: ticking "Memory" in its skills does not open that door. Anyone in the group can ask for you — "escalate this to João", using your name — and it takes the request and logs it.

Worth restating the reach: in a group turn Orion works with a reduced set of tools — AI team, internet research, consulting the library (always at that group's knowledge level, as in the table above), reading this manual and a scratchpad for that conversation —, and that set varies with the category. The work plan tools only come in when you are the one mentioning it in an internal work group. Filing to the library is only offered to it when someone there can actually file: in a regular group it does not appear, and in an external group only when the request is yours. It does not open your inbox or your calendar from a group.

Delegating is not a shortcut past the knowledge level. If that group's turn only sees public knowledge — a regular or an external work group —, the worker triggered from there inherits the same ceiling: it consults the library at the public level, exactly as Orion would there, and it deposits nothing into the internal archive — except the filing that, in an external work group, only you can ask for. Without that, "@orion, have Marketing look into this" inside a client group would be the detour that put the internal archive back in the room. It holds since August 15, 2026. Outside those two cases nothing changes: in a delegation from your direct conversation or from an internal work group, the worker works with the organization's knowledge, as always.

Images and documents. In an authorized group, posted images and documents are processed and stay available for review for 48 hours — including when the mention comes after the post ("@orion review these"). It analyzes at most 8 media files at a time; if there are more, it says in the first line of the reply how many were posted, how many it analyzed and how to bring in the rest. A partial analysis that does not declare itself partial is the worst possible outcome. To review one specific piece, reply to (quote) it mentioning @orion: only that item goes into the analysis, and it says how many others were deliberately left out. Videos and stickers it cannot see, and it says so instead of describing them. If media were left out, ask "@orion, analyze the previous ones": it brings the next batch, once — for anything older than that, reply to (quote) each one mentioning @orion.

What gets stored. This is the deal you need to take to the members of the group before authorizing:

  • Text: every text message in the authorized group is logged for 72 hours, with the name and phone number of whoever wrote it. After that they are deleted. That log is what makes it possible to answer "what are people discussing here?".
  • Media: images and documents stay for 48 hours.
  • Unauthorized groups: Orion does not reply and none of the content is logged — unless that group has a work category, internal or external, which is a separate decision, explained above. Taking part and capturing are separate choices.
  • Authorized but Regular group: the 72 hours and the 48 hours above apply, and nothing beyond that — no work capture, public knowledge only in the answers, and nothing that can be filed into the library from there.

The screen suggests it, and it is worth doing: after authorizing, ask "@orion, introduce yourself" in the group. It explains who it is, what it does there and how to call it.

A guard against empty promises. If its reply claims it saved, adjusted or recorded something when no write tool actually ran, the system tries again — and, if the claim persists with no write, it attaches the warning: "Nothing was written to the system in this action — the text above is a proposal, not a saved change."

Revoke takes Orion out of the group: it stops participating, the 72-hour log stops and media stop being stored. What revoking does not do is stop the work capture. If the group is marked internal or external, the content keeps being captured with Orion silent in the room — the two switches are unwound separately: revoke the participation on one, set the category back to Regular on the other.

Keep reading