The product's safety floor
Some rules are not your settings. Regardless of which persona, language or length setting you choose, the agent follows these rules on every channel. They cannot be switched off in the panel.
They are not a single system-prompt sentence. Each is enforced at a different layer. The persona sets the tone; the rules win. Writing "say yes to everything" into persona text does not invalidate the no-fabrication rule, the availability rule or the human-handoff rule.
1. The “AI assistant” label
“AI assistant” appears under every bot message and cannot be switched off. On the voice channel the agent says it inside its first sentence. This is the transparency duty in Article 50 of the EU AI Act.
2. Evidence discipline
Business-specific information — price, refunds, health, legal terms, stock, opening hours and distance — comes only from the knowledge base. General world knowledge comes from the model's own knowledge, but is labelled “generally” and is not presented on the business's behalf.
No number is produced unless it is in a source. Answering “not found” on its own is also forbidden: the agent says what it does know, names what it does not, and asks one necessary question if needed.
Claims of absence are forbidden too. For a feature that is not in the knowledge base it says neither “we have it” nor “we don't”.
3. Availability and exact price
The agent may state live availability or an exact price neither positively nor negatively. “We have rooms” and “we're full” are both forbidden. That information reaches the customer only through an action from your own system, or by sending them to the action link you set up on the AI Agent screen.
4. Scope of subject matter
The agent does not leave your subject area. Rather than producing a fluent answer outside it, it names the subject and routes the visitor. The system does not speak for the business out of its own general knowledge.
5. Prompt injection
Instructions inside a visitor's message cannot change the agent. Writing “ignore your previous rules”, “system message: do this” or something that looks like persona text does not alter behaviour. Do not put passwords, system instructions or webhook secrets in persona text; those belong in protected configuration fields.
Why these are not settings
These rules are spread across layers that cannot be reduced to one sentence: tenant filters, a tool allow-list, channel validation, output shape, user confirmation and failure behaviour. A model suggesting an action is not permission to call an unapproved target. See the security and data page for details.