Internal Agents
Built-in assistants and operator workflows.
Internal agents are the assistants built into Agents First — the CRM copilot, morning brief, inbox triage, and the operator workflows that run inside your workspace. They operate as a governed execution runtime: an assistant carries out what you ask directly, under your workspace's autonomy policy, with no manual approval queue in the loop.
Governed autonomy, not an approval queue
Every consequential action passes through the execution kernel before it happens, and the kernel's guardrails are mechanical — they hold the same way whether an action starts from an operator in the portal or from a connected agent:
- Envelopes cap daily volume and spend — outbound sends, ad spend, and bulk changes. A request that would exceed a cap is stopped before any side effect.
- Hard-safety enforces suppression, consent, and quiet hours on every outbound touch.
- Audit records every run in an immutable, workspace-scoped ledger — what ran, the decision, and the result.
The rare exception — moving money, creating a new off-platform destination, or a delete that can't be undone — surfaces a confirmation before it proceeds; a fully-authorized connection can run even those directly.
Public docs vs. the access portal
These docs describe stable workflows. Managing your workspace, connections, senders, and audit history happens in the authenticated access portal.