> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ledgerup.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Guardrails and Limits

> The boundaries Ari works within by design, where he needs a human, and what he doesn't do yet.

Ari is a strong teammate, not a finished one. Here's where he works within deliberate
guardrails, where he still needs a human, and what he doesn't do yet. We keep this page
current; if something here blocks your workflow, tell us at [support@ledgerup.ai](mailto:support@ledgerup.ai).

## Guardrails by design

These aren't gaps. They're how Ari is built to be safe:

* **No action without approval.** Ari will not send, create, change, or delete anything
  until a human approves the plan. There is no "just do it" mode for data-changing
  actions outside of tasks you've explicitly set to auto-execute.
* **No undo from Slack.** Once you approve an action, reversing it (voiding an invoice,
  following up on a mis-sent email) is a new action, not an undo button. The approval
  step is the safety net; use it.
* **No raw payment data.** Ari never sees or handles card numbers. Payment methods are
  tokenized and stored in Stripe, in line with PCI requirements.
* **Contract access is permission-scoped.** Team members can only view contracts for
  customers they have access to.

## Where Ari needs a human

* **Complex contract nuance.** Term extraction is accurate on standard agreements, but
  heavily negotiated or unusual contracts should be reviewed by a person before
  invoicing from the extracted terms.
* **Ambiguous reconciliation matches.** High-confidence matches complete automatically;
  anything uncertain (odd amounts, unclear payers, overpayments) is flagged for your
  judgment rather than guessed at.
* **Collections judgment calls.** Ari drafts and sends reminders on your playbook, but
  deciding to escalate a relationship, negotiate a settlement, or write off a balance is
  yours. He'll prepare the context; you make the call.
* **Data conflicts between systems.** When Stripe, HubSpot, and Salesforce disagree
  about a customer, Ari surfaces the conflict and asks you to pick the source of truth
  instead of silently choosing.

## Operational limits

* **Three places to talk to Ari.** Slack, email, and chat in the LedgerUp platform.
  Settings and email templates are managed in the LedgerUp control panel.
* **Thread context doesn't cross threads.** Ari remembers everything within a thread,
  but a new thread starts a fresh conversation (with full access to your data, minus
  the conversational context). Use
  [Instructions](/ari/work-together/instructions) for anything he should remember
  everywhere.
* **Live queries take seconds, not milliseconds.** Ari queries your systems in real
  time rather than serving cached data. First answers typically take a few seconds, and
  large cross-system analyses can take minutes.
* **Integration coverage varies by plan.** Out of the box, Ari works with Stripe,
  Chargebee, HubSpot, Salesforce, Attio, QuickBooks, PandaDoc, DocuSign, and email.
  The Enterprise tier supports additional integrations beyond this list; if your
  billing truth lives elsewhere, talk to us.
* **Slack threads aren't the system of record.** Slack messages follow your
  workspace's retention policy, so treat threads as the conversational view. The
  complete audit history lives in the LedgerUp platform and covers everything that
  runs through LedgerUp services. See
  [Activity history](/ari/manage/activity-history).

## What to do when you hit a limit

1. **Ask Ari anyway.** He'll tell you when something is outside what he can do, and
   often suggests the closest thing he can.
2. **Check your [Instructions](/ari/work-together/instructions).** Unexpected behavior
   is sometimes a standing rule you forgot. `@Ari why did you do that?` shows which
   prompts he applied.
3. **Tell us.** [support@ledgerup.ai](mailto:support@ledgerup.ai). Limitations get removed in roughly the order
   customers hit them.
