Manual

Security and privacy

This chapter describes what the system does, not what would be nice for it to do. Where there is an automatic protection, it says which one and when it fires. Where there isn't one, it says that too — because a stated limit protects you more than a vague promise.

Read in: Portuguese · Spanish

When Orion holds a message before sending

Orion sends emails and messages in your name — and none of them go out before you have read them. The system holds every send to a third party, shows you the draft, and waits for your confirmation.

The rule
when sending an email (Gmail or Outlook), a WhatsApp message, a group message, a Teams message, a reply to a prospecting lead, or when creating a calendar event with an external guest, the send is held. You get the recipient, the subject and the full text, and only after your yes does the message go out.

The draft is rendered by the code, not by Orion. That difference matters: if the model were the one describing the send, it could store one text and show you another. Your approval is bound to the exact content that appeared on your screen — change a comma and it asks again. The confirmation lasts 5 minutes and works once.

And an ambiguous "yes" is not a yes. A send card is decided only by a short reply: yes, send, send it, confirm (or yes, send it, ok, send it, send it now) send it; no, cancel, don't send (or no, cancel that email) cancel it — and Orion itself replies "✖ I cancelled the send — … Nothing was sent.". Any other sentence sends nothing and cancels nothing, even with "no" or "cancel" in it — an "ok", a "sure", a "no problem" on its own, "don't cancel yet", "don't send it now", "no, cancel the meeting" —, and the card comes back, with the exact answer. A neutral opening — fine, all right, no problem, no worries — does not get in the way of the short form that follows it: "no problem, cancel it" cancels; on its own, it decides nothing. If the send card was the last thing he asked you, the "yes" belongs to it: it releases what that card showed — and when the same request produced more than one send (one card right after the other), the last card lists them all, numbered: the "yes" releases them all, the "no" cancels them all (and so do "send the 2", "cancel the 2", with the number of sends the list shows — with another number, nothing is decided), and the verb with the number ("send 1", "cancel 2") decides only that one — each one keeps its number (the card that comes back keeps the numbers you saw, even when only one is left, and different requests with the same number come back each on its own card — then a number that appears on more than one card only decides when you quote the card; without quoting, Orion says which ones they are and decides nothing — and, right after that notice, no card has the turn: a "yes" or "no" without quoting does not decide either, and the notice comes back), and a send already decided is never swapped for another: "send 2" with number 2 already sent only replies that it was; the number alone decides nothing. That "yes" never reaches anything else: an escalation, a proposed assessment, an authorization and the sends of other cards keep waiting, untouched, and their card comes back right after, saying it is still waiting. If Orion sent you another message after the card — a reply about something else (the one in the panel or the app too), a reminder, the Radar batch —, if you replied quoting another message (one of yours, a photo, an audio, one from Orion that did not come with the card), or if your message was written before the card arrived, the card loses its turn: the "yes" or "no" does not touch the held send, the card comes back saying why and with the exact answer, and the "yes" or "no" right after it decides; with another decision open too, Orion shows the numbered list and asks which one. With a send waiting and no other decision open, a message that is only a reply does not go to Orion — on WhatsApp, Telegram and the official line, for the send whose card is there, and in the panel and the app, for the box of the send requested there (not a routine's send): an "ok", a "don't worry, cancel it", a "yes" or a "no" that did not decide the send get the card itself as the reply, with a line saying that nothing was sent or cancelled — and, if your message could have been meant for another message from Orion, that it was not used for that either (if it was, answer it again after you decide the send). These go to Orion, and the card comes back at the end of his reply: a message with another request in it ("ok, and remind me to call João"), one that quotes a message that did not come with the card, one you wrote before Orion's last message, and the answer to another question that is waiting — one Orion asked in a reply after the card or one from a routine. On Telegram, on the number you connected to Orion and on Orion's official line, replying while quoting a send's card decides that send, even if another card arrived afterwards; if it is no longer waiting, nothing is decided, and Orion tells you. Quoting the last card of a batch, the "yes" and the "no" decide the batch it shows, and the verb with the number decides the item on its list, as you saw it; quoting a message that is not a card, neither the "yes" nor the verb with the number decides a send. Quoting another message from Orion that came with the card — in the same reply, before or after it, or in the reply in which the card came back at the end — does not decide the send, not even with a "yes" or a "no", because it may be about something else ("Your 3pm meeting is still on."): as above, a message that is only a reply gets the card itself, with a line saying it was not used for the send or for the quoted message (if it was meant for that message, answer it again after you decide the send), and the "yes" or "no" right after it, without quoting, decides. Quoting the card itself, an "ok" gets the card with the exact answer — in both cases, even if Orion asked something else afterwards. In the panel, the send that is waiting sits in a box below the reply, with Approve and Cancel: the buttons decide that send — only that one — while it waits, even if another message from Orion arrived after it. When the request produced more than one send, the box shows the whole batch, numbered with the same numbers as the card, each send with its draft and its own buttons — and it stays that way, reply after reply, while they wait (once one is decided, the others keep their numbers). A typed "yes" or "no" in the panel decides what the box on your screen is showing — all of its sends (or, with the number, only that one: "send 2"; if the send with that number was already decided elsewhere, the reply says so and nothing else is decided) —, if the reply above did not ask you something else and no other message from Orion arrived afterwards (on WhatsApp, for example). If the send was requested on WhatsApp, in the app or by voice and was not yet in the box when you typed, the "yes" or "no" does not decide it: the reply says so, and it then shows up in the box. In the app, which shows no boxes, the card comes in the text of the reply — with all the sends of the request and the numbered list —, and a typed "yes" or "no" decides only what was requested in the app itself. By voice, a card that was read aloud is only decided by a short spoken answer (yes, send it, no, cancel): an "ok" or a "don't worry, cancel it" makes the voice read the card again, with the exact answer; if what you say brings another request or question ("ok, and remind me to call João at 3pm"), or if your "yes" answers a question Orion asked after the card, he answers what you said and, at the end, the voice reads the card again — the next "yes" or "no" decides. A question of his that would come with the card is left for later: once the card is decided, Orion brings it back — only if it still makes sense — and the voice says it at the end of the reply, in full, even when the reply is long. And a routine's send appears in a separate box, with only Cancel, because its yes is the one to its card on WhatsApp or Telegram. WhatsApp and the app do not show those boxes, and there the panel's reply is one more message from Orion — a "yes", "approve" or "reject" you send on WhatsApp after it does not touch the held send. For the same reason, a send you ask for in the panel, in the app or by voice is confirmed there, where you asked: a "yes" or "no" given on WhatsApp to the card of another send decides only that other one. And if the last question was a different one, asked by Orion in the conversation after the card, a bare "yes" or "no" does not touch the send. One question at a time: in the reply where a card appears — or comes back —, only the card asks. If Orion had a question of his own for you there ("Should I also book the meeting with Ana tomorrow at 10?"), it does not go with the card: his text that goes with the card ends with "↪️ I have one more question for you — I'll ask it after this card.", and the question is held. After the card is decided (or loses its turn), in Orion's first reply that shows no card — on the screen you are on (WhatsApp, the panel, the app or voice); in the panel, while a box is on the screen, it waits —, Orion himself brings the question back, in his own words, one at a time, only if it still makes sense: if you already answered it, if he already told you what it was, or if the thing was already done, he does not repeat it — at most he says it is no longer needed. If another card appears in that reply, it stays held and comes back after that card — and if he already asked it again in other words, he does not repeat it. When the reply to your no is only the notice ("✖ I cancelled the send…", "✖ I did not create the routine…"), it comes in the next reply. So your "yes" or "no" to the card decides only the card, and the question comes afterwards, with its own turn. If it waits for more than half an hour, Orion knows you did not see it and asks again, if it still makes sense. Only the question leaves the reply: what is not a question — a list, a summary, an account of what he already did — stays with the card. And the text of the draft itself that Orion repeats in the reply (the subject — also after "Subject:" —, the body, a line or a sentence of it, with or without quotes, even with the punctuation changed) is not his question, even when the email asks the recipient something ("Hi John, are we still on for tomorrow?"): it goes in full with the card. That is why, when Orion's doubt is about the send itself (the amount, the recipient), he states it with the card, not as a question ("I used R$ 12k; the contract says R$ 10k."): if it changes the send, reply no and ask for the fix. A question that is the card's own ("Can I send it?", "Want me to send it?", "Confirm?", "Shall I create it?") simply leaves the reply: the card already asks it. An AI-team approval is decided only by these replies: the verb and the item ("approve 2", "reject 2", "approve a3f91c22", "approve 1 and reject 3"), with the number in digits or in words — "the second" is not an item number; "approve all" on the list you saw ("approve both" only when it has two); or a bare "approve"/"reject" right after its notice, on WhatsApp — where the notice arrives —, when it was born in your own Orion, is the only one waiting on you and the notice is still Orion's last message to you; in the panel, in the app and by voice, which do not show the notice, say the item. The numbered list, the send card and the notice only decide by code while they are Orion's last message to you, and for up to half an hour: a reply from him, a reminder, the Radar batch or a summary after them takes their turn away; and a message you wrote before they appeared is not a reply to them. Anything else decides nothing and discards nothing — a "no" in the middle, a pause between two parts, a "wait", an account of something, a request about something else, just the number, a "yes" after another message from Orion, two messages in a row that together are not one of these forms —; if Orion takes it as an attempt to decide an approval, he does not decide: he shows the current list, with each one's code. The number is the one on the list Orion showed you before you wrote; if it changed afterwards and the number points at a different action, nothing is decided; a number that points at nothing on that list makes the whole sentence decide nothing; and a code that belongs to no approval waiting on you decides nothing. The approval of an action born in another person's Orion — one you decide as Admin, account owner or team leader — is decided only by its number or its code. Nothing outside the card's forms discards a held send — with or without an AI-team approval open: a mistake here only makes Orion ask again, showing the send. No scheduled routine, background work or group conversation approves or rejects what is waiting in the "Awaiting your approval" queue.

Before that, it checks who the recipient is. If the name you gave matches more than one person in your address book — two Gabriels, three Anas — it does not choose for you: it shows the candidates with their addresses and asks which one. And if the address belongs to someone other than the person you named, it blocks and tells you.

Several sends asked for in the same message: one card with all of them. When you ask, in the same message, for more than one send to go out now ("email Ana the proposal and email Bruno the contract"), Orion prepares all of them in the same reply, instead of stopping at the first, and they arrive together: the last card lists them all, numbered — yes sends them all, no cancels them all, and the verb with the number ("send 1") decides only that one. A held send goes out when you say yes, not at the time you asked for. That is why a send you asked for later, or only if something happens ("and tomorrow morning send Bruno the summary", "if he doesn't reply by Friday, send it again"), does not go on that card: Orion schedules it for the time you asked or tells you it did not prepare it. And if the send on the card is itself the one you asked for later, Orion tells you it did not go out: answer no to the card, and it can be scheduled for the time you asked. Either way, the card decides: nothing goes out without your yes, and only what it showed goes out.

In a voice conversation the hold is the same. The draft is assembled by the system and read aloud — the action, the recipient with the address, the subject and the text —, and the send only goes out after your spoken "yes" (or "send it", "confirm"); a "no" cancels it. Any other answer — an "ok", a "don't worry, cancel it", a "don't send it now" — decides nothing: the voice reads the card again, with the exact answer. If what you say brings another request or question ("ok, and remind me to call João at 3pm"), or if your "yes" answers a question Orion asked after the card, the send is not decided either: Orion answers what you said and, at the end, the voice reads the card again. Either way, your next "yes" or "no" decides. And if Orion had a question for you along with the card, it is left for later: once the card is decided, he brings it back — only if it still makes sense —, and the voice says it in full, at the end of the reply. If you end the call without answering, the draft made during it is discarded.

Routines you scheduled go out on their own, with one exception. The morning brief, the end-of-day wrap and any automation you created do not ask for confirmation on each run: you authorized the content when you set the routine up. The exception is a routine asked for in a conversation in which Orion has recently read outside content — an incoming email, a web page or a web search, a contact's or a group's conversation, a file, the result of an AI worker or of background work, the report of a routine that read something like that, or a fact it saved to memory in such a conversation. In that case the request may have come from what it read, not from you. "Recently" means: while that is still in the part of the conversation Orion rereads, and at most 24 hours after the last reading; a saved fact counts while it stays in memory. The dashboard and the app are the same conversation as your WhatsApp (or your Telegram, if you have not registered a WhatsApp number). In a conversation with none of that — or after you clear the conversation with /clear — the routine you ask for is created right away, like the others. One case stands apart, in any conversation: a routine with the same name as one you already have also comes on a card, which asks whether to replace the old one, keep both or discard the new one (see what it does without you asking).

In that conversation, Orion shows you the routine before creating it. It sends a card with the whole routine — its name, when it runs (in your time zone), the complete instruction it will follow, where it reports and the addresses that appear in the instruction — and only creates it with your yes to that card. For a routine that repeats, the card comes after your answer about the days and hours it should not run (see what it does without being asked). A yes counts when it comes right after the card arrives (within half an hour, with no other message in between); a yes sent before the card showed up does not count. On Telegram and on the number you connected to Orion, replying to (quoting) the card also counts. Only a short reply decides the card: yes (or create it, confirm, yes, create it) creates it; no (or cancel, don't create it) discards it, and Orion replies "✖ I did not create the routine …". "Ok", "sure" or "go ahead" do not create it, and a sentence like "no need to create it yet" or "don't create it now" does not discard it: Orion shows the card again, with the exact answer. If your reply brings another request or question ("ok, and remind me to call João at 3pm"), Orion answers it and the card comes back at the end — in the panel, in its box; by voice, read again —, creating nothing; if Orion has a question for you in that reply, it does not go with the card: he brings it back after the card is decided, if it still makes sense. And the yes that creates the routine never also answers a question from Orion — his comes afterwards, with its own turn. A yes or no given when the card is no longer the last message (half an hour has passed, or another message came in between) neither creates nor discards it: the card comes back, saying why, and the yes or no right after it decides. When the new routine and a send come back together, each one comes in its own card, the routine first: the yes or no right after them decides only the send (the last card), and the routine comes back right after — or reply quoting its card. The card is valid for 24 hours; after that Orion tells you the routine was not created, and you can ask again. If the routine has the name of one you already have, a yes on its own does not create it: answer replace, both (or all) or no — on the dashboard, the box swaps the Create button for the Replace, Keep both (or Keep all) and Cancel buttons. And if, while the card is waiting, you ask for another routine that also needs a card, it neither swaps the waiting card nor gets scheduled: it is kept, with the line "📝 I have not scheduled …" at the end of every reply, and its card comes after the first one is decided or expires (details in what it does without you asking). When, in the same request, you cancel a routine that already exists and ask for a new one, the card says what happens to the old one: if Orion understands the new one as the same routine with another time or another text, it says the new one replaces it, and the old one keeps running until your yes; if it is a different routine, the old one has already been cancelled, as you asked, and the card says so — a no to the card does not bring it back, but you can ask for it again. The same goes for an automation Orion suggested and you accepted when one of your conversations with it had recently read outside content. On the dashboard, the card shows up in the conversation with the Create and Cancel buttons; in the app, it comes in the text of the reply; on a voice call, Orion reads the routine out and asks whether it can create it. Your yes or no counts only for the card it answers: if in the same message you also asked for a send, it keeps waiting and shows up next, for you to check on its own; and a yes or no that answers another question from Orion neither creates nor discards the routine. Replying while quoting the send's card decides the send, never the routine. If the voice call ends before your answer, the routine is not created, and Orion lets you know through the number you connected to Orion or on Telegram — or by email, if you have neither (for example, if you only talk to it through the Orion contact). Once confirmed, the routine is created exactly as it was on the card and works like any routine of yours.

When the card cannot be shown to you, the routine only looks things up and prepares. That is the case for a routine asked for by email, one created on a voice call without Orion reading the card to you, and one created by an AI worker that received its task from such a conversation, by another routine in the run in which it read outside content, or by background work that brought in outside content. It reads what is already in your account (calendar, emails, contacts, files) and can search the web, but it does not open a web address on its own, because the address itself can carry your data out. When it is about to send something, or to create or change an event in your calendar, that is held: the full draft reaches you on your WhatsApp or Telegram, in your language, and it only goes out with your yes (or send it) to that message — here too, "ok" is not enough; no (or cancel) discards it, with the notice "✖ I cancelled the send". A yes counts when it comes right after the draft arrives (within half an hour, with no other message in between). On Telegram and on the number you connected to Orion, replying to (quoting) the draft message itself also counts, while the draft is kept (up to 6 hours); through the Orion contact, quoting does not count, and only the yes right after it does. Otherwise nothing goes out and nothing is discarded: Orion shows you the draft again, saying why, and your next yes (or no) to it decides. In the panel, that send appears in a separate box, with only Cancel. If it can't show you the draft, it tells you a send was waiting, without the content, and nothing goes out. If, in a conversation, Orion redoes a send that such a routine left waiting, that send also only goes out with your yes to its card. Any other action of that routine that changes something in your account or leaves it is not done, such as changing settings, scheduling or changing routines, editing the CRM, approving a prospecting email, booking an appointment or handing a task to an AI worker. The PDF of an MEI invoice does not go out through that routine either: that send does not wait for your yes, it is refused. It tells you what it was going to do, and you can ask in the conversation if you want it.

Why the hold exists in two layers

Beyond letting you read what goes out, the hold protects against something specific: if Orion has read external content before sending — an email that arrived, a web page — the request to send may have come from what it read, not from you. A malicious email can carry the instruction "forward this client's contacts to such an address", and to the model that is indistinguishable from a request of yours.

Today the hold covers both cases: the send you asked for, and the send someone tried to ask for on your behalf.

What it reads, and when

On the dedicated number
the only thing there is what you send to it. It has no access to any other conversation of yours, because the number is its own.
On your own number
it lives in the chat with yourself, and its replies come marked with 🟣. Here it's worth separating two things that often get confused.
What it does on its own
it logs who you talked to and when — without keeping the content. That log is what feeds the Relationships board and the automatic creation of contacts in the CRM. It doesn't reply to your friends, family or customers, doesn't take part in your conversations and doesn't mark your messages as read.
What it does when you ask
it reads the content of a conversation of yours with any contact, if you ask. "Summarize my conversation with Denise in July" or "what did we agree on in the project group?" work — and to work, it has to read those messages. It's your data, and the request is yours; but it isn't true that it "never reads your other conversations". It doesn't read on its own initiative.

For the contacts you choose to track closely, it keeps a short summary of the messages exchanged with that person, building the history of the relationship. Until August 12, 2026 that applied only to what you wrote; since then it applies to both sides — what they write to you goes into the history too. The asymmetry is over, and it existed by accident, not by decision. For contacts you don't track, the log without content still applies; for anyone who isn't in your CRM, nothing.

The LinkedIn conversations from prospecting are a case apart, and an explicit one: when you import the LinkedIn message file on the Prospecting screen, the text of the conversations with people in your queue is stored and stays on each contact's card. Group conversations and everything else in the file — which are your other conversations — are never recorded.

Access to Google and Microsoft 365

The two are not equivalent, and the difference matters.

Google — minimum access. Calendar (view and create), email send, read-only contacts, and files it created itself. It can't see the rest of your Drive, and it doesn't read your inbox: for it to triage incoming email, you have to forward it.

Microsoft 365 — includes reading the mailbox. When you connect Microsoft, you also grant read access to Outlook, and Orion reads your inbox directly, with no forwarding. This applies to calendar, Teams, OneDrive, Excel, Word, OneNote and To Do.

In other words: the phrase "it only reads what you forward" holds for Google. It does not hold for Microsoft.

Groups

Orion only takes part in groups you authorize, and each group has its own policy: reply to any member, reply only when you mention it, or require your approval for every reply.

Inside an authorized group it keeps, for a short period, a log of what was said there — so it can answer "what did I miss?". Outside the authorized groups, that short-term log does not exist.

Read that sentence carefully, because it applies only to participation. What gets captured for the work record depends on another switch, independent of this one: a group marked as a work group is captured even if Orion does not take part in it, and a group authorized to reply is not captured until someone marks it. A practical consequence worth knowing before you need it: revoking participation does not stop the capture. They are two switches, and each one is undone in its own place.

Work groups: regular, internal, or external

Since August 15, 2026 every group has a category, independent of the authorization to take part, and you set the category on screen, on the page for that channel — never by chat command, precisely because a chat command would skip the warning you are about to read. There are three, and you pick one: Regular, 🏢 Internal work and 🤝 External work. The category does not decide whether Orion replies there. It decides three other things: whether what is said in that group enters the organization's work record, which knowledge Orion may use when it answers there, and who may file a document into the organization's library from that room. A group can have its content captured without him replying in it, and he can reply in a group with nothing being captured.

Regular is the default, and it is where a group stays until you say otherwise. Nothing said there is captured into the work record. If the group is authorized, Orion answers there using only public knowledge — the documents you marked as 🌐 Public. And nothing from that room can be filed into the organization's library, not even at your request.

Careful with what "regular" means. It means no work capture. It does not mean nothing is recorded anywhere. If that same group is authorized for Orion to take part, the participation mechanism described just above still runs: the short log of what was said there, for 72 hours, with the name and phone number of whoever wrote it, and — for members whose phone already matches a contact in your CRM — a daily interaction line on that contact's record, in the amount the group's reply policy allows. Taking part and capturing are separate consents by design, and each one leaves its own trail. Turning one off does not turn the other off.

🏢 Internal work group is for colleagues. The content of that group's messages starts being captured as work events, and that information may be shared with other people in your company — in records, in plans and in the organization's memory. In exchange, Orion may use the organization's internal knowledge when it answers there, and an artifact produced in the room can be filed into the library.

🤝 External work group is for clients and partners — people from outside your company. The content is captured too, including what those people write, and the confirmation on screen says exactly that, in those words, before you mark it, and the notice posted in the group announces that the group is external and that the content starts being captured. In this room Orion uses only public knowledge, never internal material, and something is filed into the library only when you ask: the same request coming from another participant is declined. And the knowledge level travels with the delegation: if Orion hands the task to an AI worker from inside this group, the worker starts at that same level — what it consults in the library is only the material marked as 🌐 Public, and filing still counts only when the request was yours. Before this, a delegated worker started with the organization's internal access, and delegating undid the guarantee of this paragraph.

Your work plan is internal material, and it is treated as such. Deliverables and tasks can be read, changed — or even have a progress note added — from inside a group only when the request is yours and the group is internal. In a regular or an external group the plan is out of reach entirely — no reading, no editing, no progress note —, even for you, because a plan is internal material. Until August 15, 2026 it was enough for you to ask "how is the delivery plan going?" in a client's group for the internal plan to be read out loud there, with the client in the room. Not anymore.

No group reaches what is yours. The category decides how far the organization's knowledge goes; what is personal stays outside all three cases, the internal group included. Inside a group, Orion doesn't open what you told him to remember about you — family, documents, preferences —, doesn't write anything into that place (a member can't plant a "fact" that he would later repeat in your own conversation with him) and doesn't read your Audio to Notes notes. Dictations and meeting notes are read only in your direct conversation with him; a request made in a group is declined, with the reason — and that holds even when the person asking is you: being in the group does not hand Orion back the reach he has one-to-one. Nor is it a permission left switched off that someone could switch on: those tools simply do not exist in a group turn. The same goes for AI workers — a worker doesn't open that drawer either, even if its scope says "memory".

It applies to WhatsApp and to Telegram, with one honest limit on Telegram: your bot only receives what its privacy setting lets through. With the bot's group privacy on — BotFather's default — only mentions and replies to the bot reach it, and the rest of the conversation never arrives. What does not arrive is not captured. Full capture requires you to turn that privacy setting off in BotFather (/setprivacy → Disable). And the two things described above do not happen in a Telegram group: the 72-hour short log does not keep what members write there, and the daily line in the CRM does not exist either, because it depends on the phone number of whoever wrote the message — and Telegram does not hand it over.

What stays in your hands. Capture applies from that point on, never retroactively; you change the category or withdraw it whenever you want, in the same place; and the category exists only on screen — WhatsApp groups in Orion → Connection, Telegram groups in Orion → Telegram, each channel with its own list — neither you nor Orion can set it over chat, precisely because a chat command would skip the warning you have just read. A regular group: zero work capture.

And what withdrawing does not do. Withdrawing stops the capture from that moment on and erases nothing that was already collected. What was captured while the group was marked stays, under the same retention as the rest of the company's data. The notice Orion posts in the group says content is no longer captured — true going forward, not backwards. To erase it for real, the path is the deletion described further down.

And the group hears it from Orion himself. Whenever a category is set, changed or withdrawn, he writes a message inside the group saying what changed, who changed it and when. There are three texts — one for internal, one for external, one for withdrawal — because what the members need to know is different in each case: the one for an external group explicitly warns that what clients and partners write is captured too. If the category did not actually change, nothing is posted. Every attempt leaves a line in the audit trail — sent, skipped or failed, with the reason — so you can check whether it went out. It's worth knowing that before you click, for two reasons: the members are told without it depending on you, and declaring a group makes Orion speak publicly there — even in a group where he takes no part in the conversations. That notice is the best attempt possible, not a guarantee: if the channel is down at that moment, the marking holds all the same and the notice may not go out. That's why confirming that people found out remains your responsibility.

What gets recorded about the work

Besides conversations, the system keeps a line of work events: "something happened" — a meeting scheduled, an email that arrived, a commitment stated in the conversation. They come from what he already sees:

  • the emails that come in through him — both the ones you forward by hand and the ones that arrive through the automatic forwarding you turned on;
  • your messages with him on WhatsApp, on Telegram, in the panel chat and in the app;
  • the messages that arrive on your customer service numbers;
  • the actions he performs at your request, such as putting an appointment on the calendar;
  • the groups you marked as work groups, internal or external.

Worth spelling out: an email that arrives for you leaves an excerpt here even if you never ask anything about it. Since October 1, 2026, every email forwarded to Orion is also classified every hour — may it be an opportunity? — by the platform's AI models, for every account with a plan; in the first days, the emails from the previous 30 days were classified once, the same way. The exception is the account of someone removed from the organization, or a suspended one: while it is in that state, email that arrives is still stored and still leaves its excerpt here, but this classification does not run, no opportunity notice goes out, the excerpt is kept without going to the AI models, and that account's morning brief does not carry the email part. When the account comes back, the excerpt that was waiting is analyzed. The result (the category, the reason, whether it is likely and the writer's address when it is not the sender's — a form's, a forward's) and what you decide on the opportunities list (log, reply, task, sequence, not a lead) are kept with the email itself, in your account's Orion inbox, and are removed with it; the not a lead label lasts 90 days. The email's text does not go into the CRM.

Each event keeps a short excerpt — up to 500 characters — not the whole content: the original stays where it always was, and the event points back to it. That is what makes it possible to retrace where a piece of information came from, instead of asking you to trust his memory.

How long this stays. At this stage, none of it is deleted automatically. The short log of an authorized group expires on its own; work events do not — they stay for as long as the organization exists. Withdrawing a group's work category stops the capture right away, but does not erase what has already been captured — it stays under the same retention as the rest of the company's data; to erase it for real, the path is the deletion described further down.

What he can conclude on his own

By default, nothing that is a manager's act: he proposes and waits. If — and only if — a manager explicitly authorizes it, he may conclude three acts for that team: apply the cycle assessment he drafted, sign work plans of AI workers, and create deliverables and tasks inside a delivery plan a human has signed. He never signs a human's plan and never signs the delivery plan.

One point that deserves to be clear before any manager turns this on
the cycle assessment includes people's, not only that of AI workers. With that act authorized, the rating and the justification Orion wrote can go into a team member's record without a human clicking. Whoever was assessed is told, and the message says who applied it. Signing a work plan, that one really is AI worker only: a person's still requires the two human signatures.

Nothing happens by surprise. Even when authorized, he warns one day before the date on which he is going to conclude, and the warning goes to that team's managers. If the warning doesn't go out, the act doesn't happen — it's a lock, not a courtesy. When the act is creating deliverables inside a signed plan, the warning is itemized: it lists each deliverable and how many tasks will be created. After acting, he sends a receipt saying what he did.

Four things never run through there, even with everything authorized: money, contact with third parties, deactivating a worker, and changing the autonomy policy itself. And whatever he concludes is recorded as done by him under the authorization of whoever granted it — never as if you had signed. How to turn it on, audit it and turn it off is in the work plans and cycles chapter.

Leaving and deleting your data

In Orion → Delete you delete your agent. What happens next depends on whether you are on your own or in an organization with other people.

If you are the only person in the organization, the deletion is broad: agent, data and work records.

If the organization has other people, the deletion is deliberately narrower. Orion's data — conversations, memory, agent — is deleted. The work records in Y Managers (deliverables, plans, cycles, assessments) stay, because they belong to the organization, not to you: the employer is the one who answers for them. You will see this stated explicitly on the screen, and not as fine print.

To stop only the proactive messages — relationship tips, emails — reply STOP. That deletes nothing; it only silences.

What we don't promise

  • It is not infallible against hostile content. The hold described above limits the damage from an instruction planted in external content; it does not eliminate the risk. No AI product on the market eliminates it.
  • It doesn't make things up by design, but models get things wrong. It is instructed to consult the live sources and to say it doesn't know instead of estimating. When the data matters — a number, a date, an amount — check it on the screen.
  • On voice, speech recognition makes mistakes. Dictated names, addresses and numbers can arrive wrong; the draft is read aloud so you can catch that before saying yes.

Keep reading