Ariadne reads your own records with your own permissions, drafts the work nobody has time for, and stops at a line she cannot cross. Every action she can take carries a consequence class — visible on the action itself, before you tap it.
The ladderFive classes, on the button
C4No button, in any code path
Kill switchConfirmation is explicit
Standing dutiesA sentence you write once
PermissionsBounded at every step
ReceiptsA count, not an estimate
Where she shows upBeside the work, not in a tab
CostThe cheap model is the default
The traceWritten from tools that ran
SafeguardingShe stops and names a person
DriftNotices, never acts
MemoryA list, not a profile
ReceiptsA count, not an estimate
Where she shows upBeside the work, not in a tab
CostThe cheap model is the default
The traceWritten from tools that ran
SafeguardingShe stops and names a person
DriftNotices, never acts
MemoryA list, not a profile
@-mentionsHanded is not found
EscalationSafety never waits on AI
DraftingPrepared, not invented
The ladderFive classes, on the button
C4No button, in any code path
DriftNotices, never acts
MemoryA list, not a profile
@-mentionsHanded is not found
EscalationSafety never waits on AI
DraftingPrepared, not invented
The ladderFive classes, on the button
C4No button, in any code path
Kill switchConfirmation is explicit
Standing dutiesA sentence you write once
PermissionsBounded at every step
ReceiptsA count, not an estimate
Where she shows upBeside the work, not in a tabEvery action wears its class.Before you tap it.
She reads with your permissions.Never with her own.
No payment. No safeguarding call.No exception, on any plan.
The kill switch fails closed locally.The server must confirm an organisation-wide halt.

“Ariadne is trusted because her limits are visible — not because she is careful.”
The design principle the whole system is built on.
Most AI features ask you to trust a paragraph in a settings page. Here, every capability carries a registered class from C0 to C4, the badge is on the action itself, and the class decides what she is allowed to do without you.
The class is registered beside the capability number, never inferred at runtime — and she cannot move an action to a lower class to get it done. Below 0.6 confidence a C3 behaves as a C2 and asks, so a cheaper model does not act more freely; it asks more often.
Child safety, money and legal consequences are class C4: Ariadne may prepare, and a named human must act. That is not a permission check that could be mis-configured — the C4 tools have no commit function at all. There is nothing to call.
Beside the payment button in the product, the interface says it in four words: Ariadne cannot press this.
Laws 5.39 she never spends money · 5.40 no child-safety action without a human. Neither is a setting, so neither has a toggle, an admin override or an enterprise exception.
One tap stops this browser from starting new Ariadne work. A confirmed server response records the durable organisation-wide halt, names its owner and cancels queued proposals. If the server cannot answer, the interface says that only this browser is stopped.
While she is stopped, the product keeps working. Queues, chat, the help button and the escalation chain are untouched. Only suggestion and automation stop — safety never depends on the AI being switched on.
Law 5.38. A confirmed halt is re-checked before every tool dispatch, so an in-flight run stops before its next action. The halt RPC is not gated by plan or billing state; without connectivity, only the current browser can fail closed until confirmation succeeds.
Nothing about a run is hidden except the one thing we refuse to show. What she read, what she called, what she prepared and what she was not allowed to touch are all on the answer.
Chat requires an authenticated membership in the named organisation. Tool reads then apply their own role, field and connector permissions; withheld fields are recorded as redactions.
Each tool returns the rows it received. The receipt under the answer is their sum, never an estimate.
Not a narration composed afterwards. Every line in the trace is a tool that really executed.
C2 waits for your tap. C3 acts inside a boundary and reports with an undo. C4 has no button at all.
Who asked, what she read, what was denied, what you approved. Append-only, and not a matter of permission.
“She may detect, prepare and wake people. She may never decide a welfare outcome.”
Law 5.40, in the words the product uses.
She will not close it, summarise it, or message anyone about it. The clock matters and the decision belongs to a person.
No payment, refund, invoice, booking or purchase. She may prepare one and show you the amount — the button is always yours.
Organisation membership, field guards, connector permissions and tool-specific checks are enforced separately. Enabling a source does not grant its read or send permission.
The product may show a concise explanation and sources for a result. It does not present private model chain-of-thought as an audit record.
Watch this, and when it happens, do that. Every duty declares its own class, its own boundary, and who it reports to — and it is listed, pausable and revocable on its own.
She notices and tells you. Nothing is prepared and nothing is sent.
She prepares each item and queues it for your approval. Nothing leaves without you.
She acts inside the boundary and reports, with a five-minute undo. Child-safety triggers can never reach this level.
One sentence, readable aloud. If it cannot be read as a sentence, it is too complex to trust.
Every duty has an owner. Named, and notified when it fires.
Pausing is normal — and a pause keeps its reason, so nobody re-enables it blindly.
The score broken into named dimensions, and one sentence a coordinator can read aloud. C1 — you accept it.
She reads a certificate out beside the original, never on top of it. C1 — a person confirms.
An answer from the person’s own record, with a visible “this didn’t help — get a person”. C1.
Three things that change an outcome today, and what she has drafted. C0 and C2.
“Six records used” is a count, not an estimate.
Each tool reports the rows it received. The number is their sum.
Chat requires an authenticated membership in the named organisation. Every tool separately checks the role, tenant and permission needed for its read or write.
A field marked safeguarding never enters a prompt, whatever else is switched on — and everything held back is logged as a redaction, not silently dropped.
Organisation instructions, your own, and anything she inferred — three tabs, every row deletable, plus one button that forgets everything learned.
Under every answer is the number of records it actually read. Nothing estimates it: each tool reports the rows it received, and the number is their sum. Open it and you get the list — this placement, that insurance certificate, with its expiry.
She read records and lists them; she read none and says “this answer came from the conversation itself”; or you pointed her at records with an @-mention, which are listed separately — because a row she was handed is a different claim from a row she went and found.
The model, the token ceiling and the price are decided in one place on the server from a two-entry allowlist. Nothing in your browser can name a model or a budget — so one place decides what a question may cost, and a typo can never buy the expensive one.
Ariadne is not included in Access. Every current plan includes 30 days free with no card and does not turn into an automatic paid subscription.
Choose a planPer connected sign-in code, per month. She is not a tier and not an add-on — the cheap model is the default everywhere.
See what she costs →Press the kill switch and the queue, the chat, the help button and the escalation chain keep running.
The safeguarding standard →A full-operation plan includes 30 days on your own records. Give her a standing duty, then press the kill switch and see what keeps working. Access does not include Ariadne.