Appearance
Human in the loop & automation
Every action a process wants to take (create a task, send an invoice, pay) is an event. Each event is handled by the AI or by a person, and the share the AI handles grows only as it earns trust.
Autonomy levels
| Level | What happens |
|---|---|
shadow | The process runs every step but only records what it would do |
assisted | A person approves every action |
supervised | Eligible actions can run without a person, for the share of events the rollout allows |
Raising the level needs processes.promote (and four-eyes when it's on). Lowering it is immediate.
Which events can run alone
An action is eligible only when all of these hold: its tool isn't high-risk, it's under the step's amount cap, the run's checks were clean, and reviewers' agreement with the AI is proven. Anything else always goes to a person.
The rollout
| Setting | Effect |
|---|---|
percent | Share of eligible events the AI handles alone. Stages: 0 → 10 → 25 → 50 → 75 → 100. A newly supervised process starts at 10%. |
sample_percent | Share of automated events still checked by a person, so agreement keeps being measured even at 100% |
auto_ramp, max_percent | Raise the share one stage when enough checked events agree, never above the ceiling |
ramp_min_decisions, ramp_min_agreement | The evidence needed to ramp (default 20 checked events at 95%) |
rollback_agreement, rollback_min_decisions | Always on: below this agreement (default 85% over 10+ checked events) the share drops one stage at once |
daily_limit | At most this many automated actions a day |
paused | The kill switch: every action goes to a person |
Each run lands in a fixed bucket, so a run is handled wholly by the AI or wholly by a person, and raising the share only adds runs.
When an eligible event goes to a person, approving it counts as agreeing with the AI and rejecting it as disagreeing. That agreement is what moves the share.
Risk tiers
Each process has a risk tier (low, medium, high) from its use case: what it touches (health, card, bank-account or confidential data), whether it acts, and the regulations it falls under. Each tier caps the automated share and sets a minimum sample (defaults 100%/0%, 75%/5%, 50%/10%). A risk officer can grant one process a time-limited exception (at most 90 days).
API
bash
# Who handled each event, the share automated, agreement, the tier and the settings
curl https://app.neody.ai/api/v1/processes/<id>/automation -H "Authorization: Bearer $NEODY_KEY"
# Change the rollout (raising needs processes.promote; may return 202 for four-eyes)
curl -X PATCH https://app.neody.ai/api/v1/processes/<id>/automation -H "Authorization: Bearer $NEODY_KEY" \
-H "Content-Type: application/json" -d '{"percent": 25, "sample_percent": 10}'
# Kill switch (anyone who edits, promotes or approves for the process)
curl -X POST https://app.neody.ai/api/v1/processes/<id>/automation/pause -H "Authorization: Bearer $NEODY_KEY" \
-H "Content-Type: application/json" -d '{"reason": "Totals look wrong"}'
# The workspace's limits per tier
curl https://app.neody.ai/api/v1/automation/tiers -H "Authorization: Bearer $NEODY_KEY"A request above the tier's limit is refused with 422 and the reason. Ramps, rollbacks, pauses and every settings change are written to the audit log.