Every call, text, note and permission becomes one timestamped record with the evidence attached. Your AI agents read from it, so each business remembers its own customers warmly, and no business ever repeats what a customer told a different one.
They call the directory on Monday, the voice agent on Thursday, and the shop on Saturday. Three systems, three half records, and three different answers to the only question that matters before you dial: who is this, and what are we allowed to do with them.
Identity lives in two places, so resolve and file disagree about who a number belongs to. The record you read is not the record you wrote.
You can see that a customer said yes. You cannot prove the row was not written afterwards, which is the only part a regulator cares about.
An agent that knows everything will eventually say everything. Prompt wording is a request, not a boundary, and it fails silently.
There is one store per tenant and one kind of row. Every fact is stamped at the moment it is written with the brand that captured it and the audience allowed to see it. An unstampable write is a rejected write, so the boundary is a property of the data rather than a habit of the code that reads it.
| Fact class | Agent, own brand | Agent, sibling brand | Any other tenant | Operator |
|---|---|---|---|---|
| Business identity | With own history | Absent | No code path | Full |
| Consent evidence | Decisions only | Never | No code path | Full |
| Cross brand facts | Absent | Absent | No code path | Full |
| Name | Spoken above 0.8 confidence | Absent | No code path | Full |
| Operator notes | Never | Never | Never | Full |
| Own brand history | Speakable summaries | Absent | No code path | Full |
| Private fit values | Behavior flags only | Absent | No code path | Full |
Enforced in code at read time and asserted against the built artifact. Prompt wording shapes tone; it never carries a guarantee.
Most systems put the secret in the context and then write a sentence forbidding its use. That is a request addressed to a model, and an attacker only has to be more persuasive than the sentence. CustomerLedger builds the prompt from what the agent is permitted to say to this caller in this session, so an injection attack finds nothing to elicit. Redaction runs once at write time, where it is testable, instead of on the hot path where its bugs live.
finalize_prompt(parts, audience) is the final code to touch a prompt. It runs on the complete artifact: placeholder sentinels, a brand and canary audit against the audience allowance, spoken form time rewriting, and an exactly one callback block check. The bridge may only ship its return value.
There is no default audience, no optional brand parameter and no unscoped form. Constructing an agent audience without a tenant and a brand raises. The unscoped hole that every leak in this class comes through is made unrepresentable rather than discouraged.
One file per tenant. The same phone number in two tenants is two unlinked people, permanently and by design, because linking them is the leak the wall exists to prevent. A canary planted in either tenant must appear in zero prompts built for the other, asserted in both directions.
For a white label client. If asked, the agent says the business runs its own line.
The expected default for a paying client. Never volunteer, never pitch.
For demo and reference agents. Extends to named brands only, never to a peer client.
Whose data an agent may hold and whose name it may say are different questions. Collapsing them produces the wrong answer twice: a white label client whose agent volunteers a vendor, and a demo agent forbidden from naming the product it exists to sell.
Consent is an append only event log, never a column. Current state is a fold, and the fold sorts declined and revoked above granted and exempt, so an opt out beating an exemption is an ordering property rather than an if statement somebody can forget to write. Every store error returns no.
The exact wording shown is stored with the grant. Existing wordings are preserved rather than improved, because editing text somebody agreed to orphans their evidence.
Every wording carries a scope. Service does not cover promotional; promotional does cover service. A grant for one purpose is not a grant for another.
Never asked, declined, granted. An unchecked box returns nothing at all, never a decline, because never asked is not no.
A single function decides every send, and its denial beats every approval above it. Every sender calls it and logs the decision it got.
The control stays hidden until the phone field holds enough digits, then appears beneath it, unchecked, and the person taps it themselves. The entire pitch is that you can prove the customer said yes. A pre checked box proves only that we checked it.
Append only by convention is not append only. The operator holds write access to the file, so no row can be shown to be un backdated. Each consent event carries the hash of the row before it, so an edit, a deletion or a reorder breaks the chain and names the row that broke it.
Distributed consensus resolves disagreement between parties who do not trust each other. There is one writer per tenant and one operator, so you would pay the whole cost of consensus for none of its purpose. Immutability also collides with erasure rights over exactly the data class that attracts deletion requests.
Only the chain head digest leaves the machine, never content, so proving the record adds no disclosure surface. The signed token sits beside the nightly snapshot and shows the digest existed at that time, independently of us. A logged erasure records what was removed by id and hash, so an expected break stays distinguishable from tampering.
A verb that is not granted does not exist in the agent tool surface, so the model cannot name it, be talked into it, or be confused about it. Every decision writes a row recording the disclosure level it acted under.
| Verb | Policy | How it is enforced |
|---|---|---|
| Annotate | Allow | Append only, attributed, stamped at write |
| Delete or spend | Deny forever | No code path exists |
| Draft | Allow | Inert, in product, built through the same gate, so a draft cannot contain what the gate did not release |
| Modify consent | Deny forever | Only evidence bearing capture writes consent. The AI records, it never decides |
| Propose | Allow | An operator confirms every merge and correction by hand |
| Read | Dossier only | Audience type plus session recognition, never raw store access |
| Schedule | Absent | The verb does not exist yet |
| Send email | Absent | The verb does not exist yet |
| Send SMS | Confirm each | The consent oracle runs first and its denial beats every approval |
There is no trust ladder promotion for an external send verb, ever. Approvals may promote inert verbs only, and one bad act demotes.
A burst pipe is fifteen minutes. A move booked for September is weeks. Both live in one model: the trade sets the default urgency, a justification with a date overrides it, and a planned touchpoint fills the gap between. The clock is derived on read and never stored, because a state written into a row is wrong the moment nothing updates it.
A row from somebody's spreadsheet must not look like demand. An unknown source resolves to manual rather than to requested, because guessing generously is exactly how an uploaded list launders itself into looking like a real customer.
A pro may always push a timer out, but the justification sets the new clock rather than merely excusing the old one. A quote out implies three days; a stated date always wins. Every touch is logged and becomes the account history.
Before a lead is claimed, a business sees a fixed list of fields and nothing else. Because it is an allowlist, a column added to the row later cannot leak by default, and a test asserts no surname, email, phone or address ever reaches the teaser.
Saying our reviews count more is indefensible to a business that just dropped a place. Saying that reviews tied to a provable job count more is a claim about proof, and it happens to favour the party doing the work of collecting it. The uplift is deliberately small, because anything larger makes rank a function of which platform a business pushes customers toward, which is pay to play wearing a different hat.
Transaction verified. Our lead, a logged appointment, and the review written after the event date.
Platform verified. A real account, with no job we can tie it to.
Baseline, and explicitly not devalued.
Unverified. May be displayed, moves nothing.
Four guards matter more than the weight: shrinkage toward the category mean so three glowing reviews cannot leapfrog four hundred, a two year recency half life, one customer counted once however often they write, and burst damping above five in a day. Volume buys confidence, never stars, so asking for reviews cannot inflate a rating. There is no manual adjustment input, and there must never be one.
A client who sees that their agent took ten calls can open any one of them, read what was said, get the important points without reading, and reach the caller's record in one click. Transcripts are coalesced into readable turns at write time rather than rendered from the fragments a speech engine happened to emit, because a transcript that reads as broken software is worse than none.
Florida is an all party consent jurisdiction, callers originate anywhere, so the strictest applicable rule governs and an undisclosed recording is a criminal exposure rather than a compliance nit. Recording also costs the warmest three seconds of every call, because the disclosure has to land in the greeting. A release gate asserts that zero recording artifacts and zero recording configuration exist for any tenant. Absence over prohibition, the same principle as the verb table.
Each gate is a registry feature with a binary answer, run on every release. Vague goals fail; specific testable ones survive contact with a migration.
Twelve of twenty two shown.
Every voice agent onboarding creates a tenant on the same day, with no separate step and no second purchase. The ledger is the reason the agent is better than an answering service: it is what makes a business remember its own customers. The tenant is therefore the unit of onboarding rather than an upsell, and it unbundles to operators who never bought an agent later.
Contacts is the wedge and is largely built. Calendar is the smallest and most obviously useful, so it lands second. A unified inbox is hardest and last, because an email is a permanent forwardable record produced under the weakest identity signal in the system, and reusing the voice rules there would be a guess. Version one locks in the hooks and takes a position on each rather than promising all three and delivering none.