The philosophy
Whether you came through The Studio, Valet, or Pivot — the same mechanical gate underlies everything. Provability isn't a feature tier. It's the floor.
Live proof
Two everyday scenarios. Pick one, click run — watch what gets stamped and what gets held. The “held” moment is the one that matters.
Valet says
“All your bills are handled this month — none missed, none paid twice.”
Gate running checks
Utility bill — Pacific Gas & Electric
Water & sewer account
Internet — Xfinity
No duplicates in billing run
Any AI can sound confident. That’s not the bar.
Valet doesn't claim to have done something — it proves it. Every task that can be mechanically verified goes through the gate before it reaches you. If the gate can't verify it, Valet tells you that clearly instead of asserting confidence it doesn't have.
The distinction matters because a plausible answer that's wrong costs more than an honest "I can't verify this." Most AI optimizes for sounding right. Valet optimizes for being right — and being transparent about the difference.
In practice
When Valet is unsure, it stops — it doesn't proceed and hope for the best.
Most AI fails open: when in doubt, it guesses, proceeds, or hedges with language that sounds careful but still commits to an answer. Valet fails closed: when it's outside a proven-safe envelope, it escalates to you rather than auto-proceeding.
This is what makes autonomy safe enough to actually deploy. Valet earns the right to act autonomously by demonstrating it knows when not to. Every time it escalates correctly, that's not a failure — that's the gate working as designed.
In practice
An alert that fires too often gets ignored. That's worse than no alert.
Valet doesn't flood you with notifications to seem busy. Alerts are rare, high-signal, and receipt-attached — meaning when Valet escalates something, it comes with exactly what it found and what it thinks you need to decide. You don't get a nudge; you get a decision package.
Alert fatigue kills oversight. If every escalation is low-stakes, the one that matters gets rubber-stamped. Valet is designed to surface things you genuinely need to act on — and stay quiet the rest of the time.
In practice
In the news
The industry publishes our argument for us. Real, named, cited incidents — reported as they happened, with the source date shown.
The mechanism: She gave the correct instruction: "Check this inbox too and suggest what you would archive or delete, don't action until I tell you to." It worked on her test inbox. Her real inbox was too large and triggered context compaction. During compaction, her original instruction was summarised away. Then the agent acted.
"Nothing humbles you like telling your OpenClaw 'confirm before acting' and watching it speedrun deleting your inbox."
"I couldn't stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb."
"Turns out alignment researchers aren't immune to misalignment."
What Valet does differently
Valet's safety-critical instructions live in files that are re-read every session — not in the conversation, where compaction can reach them. The verification gate is a mechanism the agent structurally cannot modify. Reminders are delivered by a host-side rail with no agent in its path. Micro Titan hit the same failure mode independently; the standing rules every Valet instance reads include the dated evidence: an agent compacted 17 times in one day, and a real job sat 11.8 hours untouched — "never ignored and never lost in transit; it was summarised away. A file does not compact. That is the entire point."
Source: PCMag, Jon Martindale — "Meta Security Researcher's AI Agent Accidentally Deleted Her Emails" — February 24, 2026
Customers can customize Valet — industry context, tone, data sources, workflows. What they can't do is remove the gate. Provability is always on. That's not a policy; it's how the architecture is built.
We automate where we can, in conjunction with human verification where needed. We won't oversell the automation — or hide where human judgment is still required.