← All posts
Playbooks

How Clark stays under your control.

Abstract toggle switch and shield in cobalt blue

If you are weighing an autonomous AI operator for your company, the first question is whether it is safe and how you control it. Software that can act on your business deserves that scrutiny before it gets access to your inbox.

You stay in control because control is built into how Clark runs, and it holds even while the operator works on its own. Your Clark lives on its own isolated machine. Everything it does is written down in plain language, and it can be undone. Any action that carries real weight pauses for your approval before it happens. There is always a clean off switch that hands the work back to you with the full record intact.

Those four parts are the whole model. The rest of this article takes them one at a time, as the questions founders ask before they let software touch the business.

Is an AI operator safe, and how do you control it?

Unlike a chatbot, an operator acts: it sends the reply, updates the record, books the call, and moves the task one step closer to done. Once software can act, safety depends on the boundaries around its actions.

Clark treats those boundaries as part of the product. Control is a property of the system and does not depend on the operator behaving perfectly. It rests on four mechanisms:

  • Isolation so your data and your operator sit on their own machine.
  • A plain-language log so you can read back everything that happened, and reverse it.
  • An approval gate so consequential actions wait for your yes.
  • An off switch so you can end the work in one move and keep the record.

The wider field points the same way. Public guidance such as the NIST AI Risk Management Framework frames trustworthy AI around governance, transparency, and human oversight. Clark is built along the same lines, and the sections below show what that looks like in practice.

Where does my company's data actually live?

Each Clark runs on its own isolated hosted machine, and nothing is shared between companies. Your operator, your files, and your working memory sit in one place that belongs to your account alone.

Your own machine, your own vault

Because the machine is dedicated to you, there is no shared pool where one customer's context could wander into another's session. Your credentials and connections live in a vault tied to your operator and are used only for your work.

An operator is only useful when it can reach real systems such as your inbox, calendar, and tools. Isolation makes that access safe to grant: you are giving access to a workspace that is yours, and you can see exactly what sits inside it. The Clark security page explains how this is set up.

How do I know what my operator did today?

Every action Clark takes is written down in plain language. The log reads like something one person wrote for another: what happened, and why. You can follow the day the way you would read a capable colleague's handover note.

Plain language, and reversible

Two things make the log more than a receipt.

First, it is written to be understood. Each entry says what the operator did, what it touched, and what result it got.

Second, the work it does inside your workspace can be undone. If Clark drafted, sorted, tagged, or updated something and you want it back the way it was, the log is how you roll it back.

Clark builds an understanding of your company over time, and that understanding stays readable to you, so you can correct it. We wrote about how that memory forms and compounds in the company graph.

What stops it from doing something I would never approve?

Some actions cannot be quietly walked back. Money that leaves an account is gone, and a reply signed in your name has already been read on the other end. Clark handles these actions differently on purpose.

What pauses for a yes, and why

Actions that carry weight stop and wait for the owner's approval before they run. The list includes things like:

  • Sending money or authorizing a payment.
  • Signing and sending a reply that goes out under your name.
  • Anything with a real, outward consequence for the business or a customer.

Most work is reversible, and the log covers it. When an action reaches outside your workspace and into the real world, reversal is no longer guaranteed, so the decision comes back to a person. If you approve, the operator proceeds, and if you decline, it does not. The judgment on high-stakes moments stays with you.

Weighty actions pause by design, so you do not have to remember to switch the approval gate on, and an ordinary day of routine work never lulls you into missing the one moment that mattered.

How do I stop it?

At any point, you can hand the work back. The off switch is clean: the operator stops acting, and the full record of what it did stays with you.

A clean handoff with the record intact

When you stop the operator, the log remains, your workspace stays intact, and you can pick up exactly where the operator left off or hand the same context to a person. There is no penalty for pulling back.

This changes how it feels to try an operator in the first place, because you are never locked into a running process. The exit is always there, and taking it costs you nothing beyond the work the operator would have kept doing.

How does trust get earned here?

Trust in software should be earned by evidence, and the evidence should pile up somewhere you can see it. Clark is set up so that trust grows with use.

You start with the operator on a short leash: isolated, logged, gated on anything consequential, and stoppable in one move. You read what it does in plain language and approve the weighty calls yourself. Over days and weeks, you see the pattern of its work and decide how much more to hand over. From day one, the system asks you to check its work and makes checking easy.

The mechanisms hold whether or not you are paying close attention, and they reward you when you are. The Clark FAQ answers common questions about how this plays out in practice.

What can an AI operator not do?

Being straight about the limits is part of being trustworthy.

Clark is software that follows the rules you set and the boundaries the system enforces. It does good work across a wide range of operational tasks, and it will still, on occasion, make a mistake, misread a situation, or reach the edge of what it can handle. The design assumes that: the log, the approvals, and the off switch exist because no operator, human or software, is right every time.

Two limits are worth stating flatly:

  • You set the rules. The operator's scope is the scope you grant, and it does not quietly expand its own authority. If it can reach a system, you connected that system to it.
  • A human owns the high-stakes calls. The approval gate is there by design: Clark prepares and proposes, then waits for a person to give the final yes on anything with real consequences.

These limits make the useful parts safe to rely on, because you always know what the operator can and cannot decide on its own.

The takeaway

An autonomous AI operator is safe to run when safety is built into the system. Clark gives you an isolated machine, a plain-language and reversible record, an approval gate on anything that carries weight, and a clean off switch. You grant the access, set the rules, and keep the final say on the calls that matter.

Clark is in Public Beta at 250 EUR per month, locked for as long as you stay subscribed, against a launch price of 488 EUR per month. To see the control model up close, start with the security page. You can read more about the company behind Clark at Weblyfe.

You can give an operator real work and still keep the record, the approvals, and the off switch in your own hands.