Chapter 18 — Hiring and directing AI workers
An AI worker is a team member who is not human. It has a name that appears on the screens, a role description written by you, a closed set of tools, a work plan with deliverables it answers for, cycles, and an assessment at the end of each cycle. You hire it, give it work through chat, decide how much it can do on its own, and see everything it did in an audit trail.
The place for all of this is Orion → AI Workers Team (the page is titled "AI Team Governance").
Hiring your first worker
Open the page and you find the Hire a worker gallery: ready-made samples, each with what it does, the tools it uses, the integrations it needs and the monthly amount — all on the card, before you click. One click hires. In organizations already enabled for autonomous execution, the AI Manager then proposes its first work plan as an editable draft, and you sign it whenever you want; everywhere else, you are the one who creates the worker's work plan.
If an integration the sample requires is not yet connected on your account, the card warns you with a ⚠️ before the click. The worker is hired anyway, without it, and the screen says what was left out — never silently.
Prefer to build one from scratch? Add AI worker opens the same form you use later to edit:
- Name
- how it appears on the screens and how you call it in chat — "Marketing (Content)", "Sales (SDR)".
- Instructions
- the role description. Responsibilities, tone, boundaries. Orion reads this text every time it delegates work to the worker. It is where you write things like "always propose 3 options" or "never publish anything — deliver drafts".
- Skills
- the tools it may use (Internet, Google, Microsoft 365, Email, WhatsApp, CRM, Relationships, Booking, Routines, Memory, Deep research…). Only what is ticked is available; everything else is blocked at call time. Leaving everything unticked allows the full toolset.
- Integrations
- the third-party accounts you connected in Orion → Integrations, released worker by worker. Being connected is not enough — each worker only uses the ones you ticked for it.
- Posture
- the default leash. That is the subject of the next section.
Hiring a worker is a monthly line item on your subscription. The amount is on the gallery card and on the pricing page.
Two separate things: the work and the identity
Every worker you hire automatically gets a person identity in the organization — with an AI tag. That is why it shows up on the team screens, can be added to a team and gets a work plan like anyone else. The work record (price, autonomy, runs) is one thing; the organizational identity is another. You manage the worker the same way you manage people, with no parallel screen.
Two practical consequences: this identity does not consume a human user seat, and it cannot be removed directly on the Users page. To shut the worker down, you remove it in Governance — you don't delete the puppet, you dismiss the worker.
And the one current plan per period rule applies: an AI worker serves one team, like a person. If you want the same function on two teams, hire two workers. Trying to create a second, overlapping plan for the same worker is refused, with the explanation on screen.
Giving it work
Through chat, talking to Orion:
- "Ask Marketing to review this post." (and paste the post)
- "Have Research & Analysis pull the 5 biggest players in this market."
- "What did Sales do this week?"
Orion delegates by passing the worker's exact name. If you use a fragment that matches more than one — three workers with "Marketing" in the name, on different teams — it refuses and asks for the full name instead of guessing. If no worker on the team covers the request, it says so and does the work itself, or tells you there is nobody to do it.
The delegation carries the full content (the worker does not see your chat) and the files you just sent. The worker comes back with a report of what it did — and with the list of what is sitting still, waiting on you.
When the request matches a deliverable on the worker's current plan, Orion ties the delegation to that deliverable. That is how the work shows up on the plan, where the humans on the team see it. If it matches nothing, it delivers and tells you: "that fell outside Marketing's plan — want me to add it?"
The autonomy matrix
Every action a worker tries to execute is classified by code, before it happens, and sent down one of three routes:
- 🟢 Runs alone
- the action happens. It is still recorded in the audit trail.
- 🟡 Orion approves
- Orion runs a separate review, with a manager's head and explicit criteria (does the action serve the task? is the recipient right? is the content professional and free of invention? what is the risk if it is wrong?), and approves or rejects. If the review fails for any reason, the action is rejected — never let through by default.
- 🔴 Ask me
- the action is held, complete, in the "Awaiting your approval" queue. Nothing happens until you decide.
The worker's posture sets the default route for each action class. There are six classes and three postures:
| Action class | Shadow | Gated | Auto |
|---|---|---|---|
| Internal / reversible (CRM, records, drafts) | 🟡 | 🟢 | 🟢 |
| External — known contact | 🔴 | 🟡 | 🟢 |
| External — new recipient | 🔴 | 🔴 | 🟡 |
| WhatsApp group reply | 🔴 | 🔴 | 🟢 |
| Financial / billing | 🔴 | 🔴 | 🔴 |
| VIP contacts | 🔴 | 🔴 | 🔴 |
In each worker's table you can pin an exception: clicking a route on that class overrides the posture default. "Clear rule" returns it to the default. The Autonomy section stays collapsed when everything is on the default and opens by itself when that worker has exceptions — a rule you can't see is worse than the noise it saves you.
How the classification is done, in code and without guessing:
- Known or new recipient
- known is someone already in the organization's CRM (or in your personal CRM). Anyone who is not is new. If the CRM lookup fails, "new" wins — the more cautious side.
- A message to you
- the worker sending a message or email to the boss is a report, not an external action. It counts as internal.
- A calendar event
- it is only external when it has guests. With no guests, it is internal.
- An unknown tool
- any tool with no declared classification is treated as "new recipient". The default is to close, not to open.
Two honest notes about the table. Financial and VIP contacts exist as rows and your rules for them are respected — but today no tool is automatically classified into those two classes, because the platform does not yet have a deterministic signal for "this is money" or "this one is a VIP". The two rows are ready for when there is one.
And the exception worth understanding: a signed plan is authorization. When the action is tied to a task or deliverable on that worker's work plan signed by both parties, it runs straight through, even if the class route would have asked for review — because signing the plan is approving that work, and supervision becomes progress and the cycle assessment. Financial and VIP are never released through this path.
The "Awaiting your approval" queue
When an action lands on the 🔴 route, it is stored whole — tool, recipient, text — and you get this on WhatsApp:
> 🔴 Pending approval — AI team > Marketing prepared send_gmail (a3f91c22). > … > Reply approve or reject — or decide on the Governance page.
You decide in two ways:
- In chat: "approve", "reject". With more than one pending, it shows the numbered list and you reply "approve number 1".
- On the Governance page: the "Awaiting your approval" block shows recipient, subject and the beginning of the text, with the Approve & run and Reject buttons.
Approving runs the action exactly as the worker prepared it — your decision is the gate, there is no second check. Rejecting discards the prepared action.
While an escalation is pending, a bare "approve" from you is read as a decision about that queue, and not as approval of some other topic in the conversation.
The audit trail
At the bottom of the page, each classified action from each worker becomes a line: who, which tool, which route, which outcome. You can filter by worker, route, class, text and date range.
What lands there is not only what happened. A reply Orion decided not to give in a group (because the policy was "boss-only") also becomes a line — explained silence is better than mysterious silence. A send that failed is recorded as a failure, not as "sent".
The worker inside the team's cycle
This is the point that separates an AI worker from a loose robot: it goes through the same ritual as a human.
- Work plan
- the plan belongs to the worker and must be tied to a team. It is what says which deliverables the worker answers for. A worker with no current plan can still work, but its work belongs to no deliverable — and the worker itself is instructed to declare that in its report.
- Cycle report
- the worker writes and submits its own report, starting on the last day of the cycle, like any team member — what it delivered, with links, results, open items and next steps. Once submitted, it freezes and goes to the manager.
- Assessment
- the worker never assesses its own cycle. The system refuses the attempt. The manager is the one who assesses: Orion drafts the proposed assessment (stars + justification), files it as a pending proposal in your "Waiting on you" box and waits for your decision. Once applied, it freezes a performance record — with mandatory justification, as in a human's cycle.
- Continuous progress
- the worker is instructed to record progress at the moment it happens, not at the end of the cycle. Whoever reads "What was done" sees the mark of who did it: a worker's notes are filed under its name with the AI tag.
- The asymmetry of the CLEAR canon
- to enter a work plan, a deliverable has to come from a signed, current team deliverables plan. For a human, a deliverable outside that rule goes through and the warning is recorded. For an AI worker, it is a block: the platform refuses, with the explanation. The rule is deliberate — the human exception is usually legitimate; the AI one is not.
Cost, removal, and the honest limit
Each worker shows a measured-cost badge: how much it consumed in the current month and over the last 7 days, with the number of runs. Until there is a measured run, the screen says "no measured activity yet" instead of showing zero — no measurement is not the same as no work. Orion (the manager) appears in the list as a line of its own: management costs something, and its cost is spread across the workers' prices.
Remove deactivates the worker immediately: it stops acting, its pending approvals are canceled and the audit history is kept.
And the limit: daily autonomous execution — the worker waking up every day, pulling the next task from the plan and working without anyone asking — is in gradual rollout, enabled organization by organization. Outside of it, the worker works when Orion delegates (at your request or through a routine you created). Hiring, scope, the autonomy matrix, escalations, the work plan and the audit trail all hold from day one; the automatic cycle report and the manager's proposed assessment arrive with that same enablement.
Chapter 19 — Groups, customer service, and prospecting
On the three surfaces in this chapter, Orion talks to people who are not you. Each one has its own switch, and none of them turns itself on.
WhatsApp groups
When Orion is on your own number, it records the groups where traffic passes — only the name and the date of the last activity. None of the content. You see that list in Orion → Connection, in the "WhatsApp groups" block, and you can also ask in chat: "which groups are you seeing?".
Authorizing a group is what changes the game. The screen asks for confirmation and says what will now happen, because the decision affects other people: an AI starts taking part in a room where nobody signed anything.
How it gets triggered. Only when called. `@orion` anywhere in the message counts, as does "Orion," or "Orion:" at the start of the sentence, or a reply that quotes one of its messages — quoting the robot is talking to the robot. The name "Orion" loose in the middle of a conversation triggers nothing.
When called, it acknowledges right away ("Got it! I'm looking at it and I'll be back here in ~2-3 min") and answers next. Every message it sends goes out signed 🤖 Orion (AI manager) — it never passes itself off as human, and it does not write that signature: the system adds it.
The mention is the instruction. Whatever the message asks for is what it does: review a piece of content, summarize the recent discussion, answer a question, record progress on a task, write a draft. There is no single request format.
The group policy defines who can trigger it and what happens to the reply. It is per group, and it overrides the general policy in Governance:
| Light | What happens in the group | What lands in the CRM |
|---|---|---|
| 🟢 Replies to everyone | Replies to any member | One line per day per contact, with a summary of what the person discussed |
| 🟡 Boss-only | Replies only when you mention it; mentions from others are silently ignored (and logged in the audit trail) | Presence only (message count) |
| 🔴 Always ask me | Every reply goes to your approval queue before being posted | Nothing |
With nothing chosen, the group inherits the general policy. And CRM capture only reaches people who are already contacts of the organization: someone not in the CRM never enters it because of a group.
The role in the group. Each authorized group can have a role of its own — free text that frames its behavior there: "Customer support: answer product questions in a formal tone; never discuss pricing — refer to the boss." With no role set, it acts as content manager, the default. The role sets tone and boundaries; the message that mentions it is still the instruction.
Who asked matters. If the mention came from you, it executes in full — including managing work plans, deliverables and tasks in Y Managers, right from there. If it came from another member, it helps within that group's scope of work and does not act outside the group at a third party's request: a group turn does not reach your inbox, your calendar or your other conversations, and it is instructed not to expose your notes to the people in the room. Anyone in the group can ask for you — "escalate this to João", using your name — and it takes the request and logs it.
Worth restating the reach: in a group turn Orion works with a reduced set of tools — AI team, internet research and notes. It does not open your inbox or your calendar from a group.
Images and documents. In an authorized group, posted images and documents are processed and stay available for review for 48 hours — including when the mention comes after the post ("@orion review these"). It analyzes at most 8 media files at a time; if there are more, it says in the first line of the reply how many were posted, how many it analyzed and how to bring in the rest. A partial analysis that does not declare itself partial is the worst possible outcome.
What gets stored. This is the deal you need to take to the members of the group before authorizing:
- Text: every text message in the authorized group is logged for 72 hours, with the name and phone number of whoever wrote it. After that they are deleted. That log is what makes it possible to answer "what are people discussing here?".
- Media: images and documents stay for 48 hours.
- Unauthorized groups: nothing is logged, nothing is answered.
The screen suggests it, and it is worth doing: after authorizing, ask "@orion, introduce yourself" in the group. It explains who it is, what it does there and how to call it.
A guard against empty promises. If its reply claims it saved, adjusted or recorded something when no write tool actually ran, the system tries again — and, if the claim persists with no write, it attaches the warning: "Nothing was written to the system in this action — the text above is a proposal, not a saved change."
Revoke takes Orion out of the group: it stops participating and the logging stops.
Customer service
Orion can serve your customers on WhatsApp with a role you define. Two conditions, before anything else:
It requires a dedicated number. On your personal number the public role is locked off, on the screen and on the server — turning it on there would make Orion reply to your personal contacts. Either Orion's main number is dedicated to it, or you connect an additional number.
You write the role. In Orion → Public role: the Role (what it acts as for whoever arrives), the Tone, the Conversation flow (the steps, in order — you can start from a template for the role you picked and edit it) and the Boundaries ("never share pricing or internal details", "never promise delivery dates").
What happens on the other side:
It is fenced in. In customer service, Orion uses none of your internal tools. It talks, records and escalates — nothing more.
You get told. Orion summarizes for you what the visitor wanted — the conversation does not run in the dark.
It answers with what you published. Knowledge documents marked as visible to visitors (pricing, services, policies, how to buy) feed the answers. Anything not there stays under the boundaries you wrote: it does not invent, it escalates.
It feeds the CRM. Contacts and interactions are born out of these conversations, with a summary of what was discussed — one interaction per conversation, not one per message.
It can book appointments, when your organization has professionals and hours configured: the times come from the server, never from the model's imagination.
Additional numbers. Since August 5, 2026, an extra number comes in only through the official Meta API, and only in the customer service function — the old sales prospecting number option was withdrawn. The path is a quick sign-in with your business's Facebook, right on the Connection screen, and the WhatsApp account created stays in your name. What you need to know first:
- It is not switched on right away. WhatsApp reviews the account first. It usually takes hours and can reach 24h; during that period the number shows as "Under review" and cannot send or receive.
- The number must not already be in use on WhatsApp, and you get a code to prove it is yours (on a landline or virtual number, ask for the code by phone call — SMS never arrives).
- You need to add a payment method to your business's WhatsApp account; without it WhatsApp blocks sending.
- The number becomes a business line: it stops working in the regular WhatsApp app on a phone.
- WhatsApp's rules, not ours: free-form replies are allowed for up to 24h after the customer's last message; outside that window only pre-approved templates go out. And business-initiated conversations start with a low daily limit that rises as the number delivers with quality.
Prospecting
Orion → Prospecting is the prospecting worker's desk: contacts, email campaigns, the LinkedIn queue and the rules for what may go out. Five tabs — Overview, Contacts, Campaigns, LinkedIn and Settings.
The screen opens with what is blocking, not with the numbers. If the sending mailbox, the operating countries, an active campaign or contacts in the queue are missing, that appears at the top along with what to do — because a panel showing "0 sent" without saying why turns missing setup into suspected breakage.
The sending mailbox is yours, and it is dedicated. Emails go out from a Google Workspace or Microsoft 365 account you connect — never from a mailbox of ours. And it should not be your main email: cold outreach wears down the sender's reputation, and that wear needs to land on an outreach domain, not on the one your contracts and customers go through. There is a button to send a test email: connecting proves the authorization went through, not that there is a mailbox on the other end.
Operating countries. Nobody outside them is contacted. While the countries are not defined, the screen warns you prominently at the top, and turning sending on from chat is refused until you declare them. And a contact with no known country is never contacted, even while on the list. It was a lock learned in practice, not a preference.
Pace and volume. You set how many messages per day (up to 200) and the time window, in your timezone. Messages are spread across the window, never in a burst: dozens of emails leaving a single mailbox in a few minutes is exactly what providers read as a mass blast. If you type a number above the cap, the screen says it adjusted it and to what: nothing is trimmed silently.
A campaign is a sequence of three emails. The first goes out when the contact joins; the second three days later, from another angle; the third seven days after the second, short and closing. You describe in one or two sentences what the campaign offers and Orion writes the three messages; the campaign is born as a draft, for you to read and edit before turning it on. You can ask it to rewrite everything — but only with the campaign paused, because rewriting under people who already got the first email would make the second one talk about something else.
What the sequence respects on its own:
- If the person replies, the sequence stops immediately. The reply reaches you and the contact stops being prospecting: it becomes a relationship in the CRM.
- Each person enters a campaign only once. With no reply at the end of the three emails, the sequence ends and the contact rests.
- Anyone who asks not to be contacted again goes on the block list and is never approached again, by any campaign. Every email goes out with your company address in the footer and a one-click unsubscribe link — a legal requirement, and that is why the address is a mandatory field.
- People who already use the product never receive outreach.
Contacts. You upload a spreadsheet (an Apollo, Sales Navigator or CRM export, or your own — there is no required format) and the screen shows what it understood from each column before it saves anything. After the import it says how many were added, how many were updated, how many entered a sequence and how many were left out because of country. You can also add them one by one, fix a record and delete for real.
Automatic prospect sourcing is optional. By connecting an enrich.so key, the worker finds prospects on its own, using the profile you defined. Without it, everything else keeps working with the contacts you bring — and sourcing is billed to your enrich account, not here.
LinkedIn: the queue is its job, the sending is yours. The worker builds a queue of people matching your ideal customer profile and writes each invitation, quoting something real from that person's profile. Opening the profile and sending is you, in your browser — LinkedIn does not allow programs to send invitations, and automating it costs you the account. It is about 15 seconds per person. There is no connection to your LinkedIn account: profile data comes from enrich's database, and nothing is fetched inside LinkedIn.
WhatsApp prospecting does not exist today. The path was withdrawn on August 5, 2026 and remains off. Prospecting, here, is email and LinkedIn.
