World
Approvals before anything ships
The operator is allowed to be fast. It is not allowed to be unsupervised on the steps that spend, send, or delete.
A useful operator without a stop is a liability. Kaer's stop is not a vibe and it is not a system prompt. It is a gate on the actions that leave the building.
Sending, paying, publishing, cancelling and merging all stop and wait for a person, with the full action attached. You choose what else joins that list; the agent cannot remove anything from it.
You set who can sign. You see what is waiting. You can reject a step without throwing away the rest of the run. This is the difference between delegating an outcome and hoping a chatbot does not email the wrong customer.
The gate sits on top of three other controls. Isolation: work happens on isolated machines with nothing shared between jobs, and Computer sessions do not share a cookie jar with your laptop. Work that can go wrong goes wrong in a box.
Audit: the run is a record. You can see what was attempted, what was approved and what was refused, and every action and approval is timestamped and attributable, ready to export or query from your own systems.
Scope: each connection carries the narrowest scope that completes the task, granted by you and revocable one tool at a time. And the stop holds: the operator cannot skip the gate because the prompt was confident. Confidence is not a permission.
The Security page describes each control, and the blog post What Kaer will not do without you walks through what an approval looks like.