Trust and authority

Power you can
point to.

Aro’s trust model is designed into the product: who it is, what it knows, what it may do, when it must ask, and how every action is recorded.

ID

Aro identifies itself.

People should know when they are interacting with an AI, whose outcome it represents, and what role it has in the conversation.

C

Circles bound context.

Information is organized around explicit people, purposes, and privacy boundaries—not one undifferentiated memory.

A

Authority travels with the mandate.

Aro does not infer unlimited permission from access. Each outcome carries its own allowed, ask-first, and prohibited actions.

!

Exceptions become decisions.

Escalations arrive with timing, evidence, tradeoffs, and response options so humans can decide quickly.

Identity

Aro presents its name, role, Presence level, and represented person or team. It should never impersonate you or hide that an AI is participating.

Authority

Every consequential capability is bounded. Aro can proceed, request approval, or refuse based on rules visible to you before action.

Privacy

Circles limit which context can serve which outcome. Access can be revoked, memory can be inspected, and sensitive information remains purpose-bound.

Accountability

The activity record links actions to sources, policy, approvals, and owners. You can understand not only what happened, but why.