Safety controls
Several independent limits sit underneath every skill.
One message per member per 24 hours
No member ever receives more than one AI message in a day, regardless of how many skills want to reach them. A global check sits on top of every individual skill’s cooldown.
This is the control that prevents the failure everyone fears: a member having a birthday, hitting a milestone, and going quiet in the same week, then receiving three messages.
Per-skill cooldowns
Every messaging skill has its own minimum gap, longer where it matters:
| Skill | Cooldown |
|---|---|
| Reactivation | 60 days |
| PT Upsell | 90 days |
| Review Request | One per quarter |
| Most others | 7 days minimum |
Money-flow guarding
Skills touching money default to Assist and cannot go to Autopilot without you explicitly choosing it. The AI cannot process a payment, issue a refund, or commit money on your behalf under any mode.
Tenant isolation
The AI can only see your gym’s data. Enforced at the database level, not by application code that could have a bug.
Name minimization
Briefings and internal logs use first name and last initial rather than full names.
Registered sending number
Messages go through your CRM from your gym’s registered business number. Members never get a text from an unknown number, and delivery is carrier-compliant.
Full auditability
Every action is logged with its inputs and outcome, visible in the Dashboard.
Outcome tracking
A background observer watches what happens after each AI action — did the at-risk member come back, did the trial convert — so the platform measures whether the AI is actually working rather than just running.
If you need to stop everything
Set every skill to Off in Agent Tasks. Takes effect immediately; anything queued stops.