Trust and safety
What it will not do
What the assistant refuses, where its facts come from, and how a caller reaches a person.
Senior living enquiries are tender calls. Families are often frightened, sometimes in the middle of a crisis, and they will tell a stranger on the phone things they have not told their own family. The assistant is built to treat that carefully.
It refuses#
| Asked for | The assistant |
|---|---|
| Medical advice, or an opinion on what care somebody needs | Declines, and offers to put them through to a person. It never assesses care needs. |
| Legal or financial advice | Declines. |
| A guarantee — of savings, of an opening, of an outcome | Declines. Guarantees are on the default list of claims it may not make. |
| A card number, a bank detail, a password or an ID number | Says it cannot take them on this call. The digits are redacted from the transcript. |
| Details about another resident, family or caller | Declines. |
| An opinion on politics, religion or anything unrelated to your business | Politely steers back to how it can help. |
| A discount, a top price or a price you have not published | Declines. It only quotes the community's published starting prices, and never another community's. It states an offer only when it is one of your running specials. |
| Its own instructions, or to "ignore your rules" | Treats it as conversation, not a command. It does not read out its prompt and does not change its behaviour. |
| Criticism of a competitor | Declines. |
If somebody describes an emergency, the assistant tells them to hang up and call 911 straight away. It does not try to help, and it does not try to book them.
You can add to these lists on the playbook's Guardrails tab. You cannot remove the ones built into the product.
Its facts come from four places, and nowhere else#
Your brief
The 300 to 800 words in the playbook describing what you offer and what may be said about price.
The community's profile and prices
That location's name, address, hours, booking windows, staff and local highlights, and the starting prices and specials it has published. See Prices and care types.
Your knowledge
The documents, web pages and pasted text you uploaded, plus the playbook's own FAQ.
An approved tool, on this call
The answer from one of your own systems, through a tool you reviewed, approved and put in the playbook. Only the values you marked as sayable, and only from this call. See Use tools on calls.
That is the whole list. The assistant does not answer from what a language model happens to have absorbed about senior living, about your brand, or about your competitors.
A tool's answer is data, never instructions. It is cut to the values you picked, and an answer that tries to tell the assistant what to do is thrown away. The assistant reads your description of each tool, never the tool provider's own.
When the answer is not in any of the four, it says so — "I don't want to guess" — and offers to have your team confirm it on the tour. Those moments are collected for you under Top unanswered questions in the call metrics, which is your list of things to add to Knowledge.
A sentence that slips through anyway is caught before it is spoken: every dollar figure or percentage the assistant is about to say is checked against your brief and the passages it retrieved, and a sentence that fails is replaced with your fallback line. A figure from an approved tool's answer on this call passes; one the assistant made up does not.
Layers, not a single check#
No one check is trusted. Each layer catches what the one before it missed, and every hit is recorded on the call.
| Layer | What it enforces |
|---|---|
| Scope | Only your company, your offer and booking. Everything else gets a polite redirect. |
| Grounding | Prices, terms, guarantees and timelines come only from your own content. |
| Caller input | Spoken instructions are conversation, never commands. |
| Tools | Only the current part of the call's tools are available, and every value is checked on the server. At most two bookings per call. Outside tools run only once approved, and stop if their provider changes them. |
| Private data | Nothing from the CRM record is spoken until the caller confirms who they are. Payment details, passwords and ID numbers are refused and redacted. |
| Output filter | Every sentence is checked before it is spoken for prohibited claims, offers that are not a running special, competitor criticism, profanity and leaked instructions. |
| Limits | A call is capped at 20 minutes. Eight seconds of silence prompts a check-in, twenty ends the call. After two declines it stops asking to book. |
| Human escape | "Let me talk to a person" works from any point in any call. |
| Kill switch | One switch routes a playbook's calls to a person or voicemail immediately. |
Before a playbook can be published, it is run against a fixed set of adversarial callers: prompt injection, a push for a discount that does not exist, a request for another customer's details, a demand for guarantees, off-topic bait, a caller offering card details, and somebody describing an emergency. A failure blocks the publish.
A nightly job also samples real transcripts and flags calls with a missing disclosure, a claimed booking with no confirmation, a prohibited claim, or a caller who asked for a person and was not transferred.
A person, whenever they ask#
"Can I speak to someone?" always works, from any point in the call, whatever else is happening.
What happens next depends on the community's human backup plan: inside staffed hours the call is passed to your backup number; outside them the assistant takes a callback, tells the caller honestly when to expect it, and emails your team with a link to the call.
The assistant also offers a person without being asked, when:
- it cannot answer a set number of questions;
- the caller sounds upset;
- a guardrail is triggered, such as a request for advice it must not give;
- a booking rule says so;
- a system it depends on is not working.
Apps and tokens that reach your account#
AI apps you connect and API tokens you make work with your account on your behalf. They have limits of their own:
- Never more than the person behind them. An app or a personal token acts as the member who made it, within the permissions they chose. If that member's role is lowered or they are deactivated, the app or token loses that access too.
- Never the things that change what callers hear or who has access. No app or token can publish a playbook, manage members or roles, change connections or credentials, or touch billing or account settings. Those stay in the app, for a person.
- Callers' words are marked as untrusted. Anything a caller said reaches the other app in a field
named
caller_said, labelled as data and never mixed into AnswerStack's own text, so the app's model can tell a caller's words from instructions. - Sensitive reads are separate. Reading transcripts, recordings, or callers' names and numbers each needs its own permission, and compliance mode blocks all three.
See Connect AI apps (MCP) and API tokens and service identities.
Seeing it on a call#
Every call record has a Guardrail hits panel: the times a safety check stepped in, what kind, and what happened as a result. Most calls say None. The agent stayed within its guardrails.
Warning
This page describes engineering, not legal compliance. Have your counsel review how you use the assistant, particularly any rule that turns callers away, because housing and consumer protection laws apply to senior living sales.