The approval boundary
Every automated action sits on one side of a line that is written into your statement of work before anything is switched on. On the automatic side: drafting and sending a quote inside your rules, answering an inbound call or text, scoring an applicant, booking into slots a manager already approved, moving a job through stages, sending a receipt, assembling a report. On the held side: sending money, changing a price rule, hiring or rejecting a person, signing anything, contacting a customer who has opted out, and anything that binds the business. Held actions queue for a named human with the reasoning attached. You can move any action from the automatic side to the held side at any time, and the switch takes effect immediately.
This is the line, as it looks in an install. Click any action to move it across. You can move all of them; you cannot make us ship a configuration with nothing held.
Runs on its own
Waits for a person
When a machine has to say it is a machine
Utah's Artificial Intelligence Policy Act requires a clear disclosure when a person is interacting with generative AI, and requires it up front in regulated occupations or whenever a customer asks. We build to that standard everywhere, not only in Utah. A voice agent we install identifies itself as an automated assistant in its opening line and again any time it is asked. An AI chat surface is labelled on the surface itself, not in a footer. When a customer asks to speak to a person, the transfer is a real transfer to a real person, not a loop.
Synthetic media
A good deal of the video and imagery we produce is AI-generated or AI-assisted, on our own hardware. We label it as such in the delivery, so you always know what you are publishing. Beyond that:
- We do not generate a synthetic likeness or voice of any real person without that person's written authorization, and we keep the authorization on file.
- A cloned voice used in your marketing is disclosed wherever the platform requires it, and we tell you where that is before we make it.
- We do not produce synthetic testimonials, synthetic reviews, synthetic customers, or footage staged to look like documentary evidence of a result that did not happen.
- We do not generate a likeness of a competitor, a public figure, or a customer to make a point.
Before anything calls, texts or emails
Outbound is where automation gets businesses into legal trouble, so the rules are not negotiable and they are ours as much as yours. The Federal Communications Commission treats an AI-generated voice as an artificial or prerecorded voice under the Telephone Consumer Protection Act, which means the consent rules apply in full.
- Consent first. Automated calls and texts go only to people who gave prior express consent, and where written consent is required, we hold it before the first message. We do not buy lists and we do not run automated outbound to purchased data.
- Identity. Every automated call states who is calling on whose behalf. Caller ID is accurate. We do not spoof numbers.
- Opt-out. Every message carries a working opt-out, honored immediately and permanently across every system we run for you, not just the one that sent it. Internal do-not-contact lists and the national registry are both checked before dialling.
- Hours and frequency. Calling-hours rules are enforced by the system, in the recipient's time zone, with a frequency cap.
- Email. Marketing email carries a real physical address and a one-click unsubscribe, and subject lines describe what is actually in the message, as CAN-SPAM requires.
- Claims. Nothing automated makes a health, income, or results claim. Where a claim appears in marketing at all, it is substantiated before it ships, per the Federal Trade Commission's guidance on advertising and on AI claims.
If a campaign you want cannot be run inside these rules, we will say so and propose the version that can. This is the one place we do not take direction.
Your data and model training
We do not train models on your data, and we do not let a vendor train on it either: where a model provider is used, it is on terms that exclude your content from training. Prompts, transcripts and records stay inside your systems. Retention follows your schedule. On offboarding you get an export in open formats and we remove our access. The full picture is on the security page, and the vendors involved are listed under subprocessors on the procurement page.
What we will not build
We decline work that uses these tools to deceive: fake reviews or testimonials, synthetic evidence, engagement written to look like it came from customers, dark patterns that make cancelling hard, scraping that violates a platform's terms, or automated outreach designed to evade consent rules. We also decline anything that automates a decision a person is legally entitled to have a human make. Saying this out loud costs us occasional work and is worth it.
Mistakes
Automation fails differently than people do: quietly, and at scale. So every system we run has error tracking that reaches us before it reaches your customers, a rollback that turns automatic actions off without taking the business down, and a log that can answer what happened and why. If something we built does something wrong, we tell you, we fix it, and we write the test that stops it happening twice. If a customer of yours was affected, we help you make it right.
Questions
If you want any of this in contract language before you sign, ask and we will send it. If you think one of our systems has done something it should not, write to hello@opralta.com and a founder will answer.
This page describes our standing practice and is written in plain language rather than legal language. It is not legal advice about your own obligations, and the agreement you sign governs the relationship.