Insights · Governance

Drafts everything, sends nothing: the rule that makes agentic work deployable.

What stops a fund putting AI near client-facing work is not what the system can do. It is the fear of what it might send. This is the boundary that answers the fear structurally, the pre-flight discipline behind it, and the record that proves both to anyone with standing to ask.

Working drawing: a production line of four measured stations on one axis, stopping short of a solid red bar that spans the sheet, with a single human figure standing alone in the clear paper beyond it.
Alex NorrisPublished 2026-08-12Updated 2026-08-156 min
Zero

send paths to a third party

One

named human sender for anything that leaves the firm

Every

control recorded as it runs, pass or block alike

Same

policy, same way, every time, with the record to show it

The stakes

The fear is correct.

An investment firm’s external surface is its most regulated, most scrutinised, least forgiving territory.

One wrong message to an LP. One premature document to an allocator. One reply to a counterparty that contradicts the last letter. These are not productivity problems; they are franchise problems, and they are why the fear that keeps agentic systems away from client-facing work is a correct reading of the stakes.

Any deployment that asks the firm to suppress that fear is asking the wrong thing. The system has to deserve the trust structurally, not request it culturally.

The rule

No agent sends. A named human does.

The rule is standing and absolute: no agent sends an external email or outbound message to a third party. There is no approval, whitelist or review path that turns it off.

Everything up to that line is the system’s job. It writes the reply in house voice. It stages the document in the shared drive. It checks the distribution list. It routes the draft through the review chain and tracks every comment as an item with an owner. It holds the finished artifact at distribution.

Then a named human presses send. Always.

The distinction matters because it converts an anxiety into an architecture. “What if it contacts an investor?” gets the answer it cannot, in place of it probably won’t. That is why the system can be put near investor communication at all: it does every part of the work up to the send button, and it is incapable of pressing it.

None of which anyone has to take on trust. Every action an agent can request exists as a registered contract in Daimon, the boundary each request has to cross, and Daimon’s registry holds no contract for an outbound send to a third party. A reviewer reads the same list the agents read, finds every permitted action named in it, and finds that one absent.

Fig. 1 — the line the system cannot crossno send path crosses

What the system does

  1. 01Writethe reply, in house voice
  2. 02Stagethe document, in the shared drive
  3. 03Checkthe distribution list
  4. 04Trackthe approval, every comment an item

Held at the line

Finished artifact · checked · gaps flagged

Outside the firm

The investor, the allocator, the counterparty

A named human

presses send

Daimon · registered contracts

  1. Read the mailbox
  2. Write to the drive
  3. Post to the internal thread
  4. Append to the record
  5. Outbound send to a third partyno contract registered

The absence is a registry fact a reviewer can read, which is why the control is a property rather than a setting.

Pre-flight

The same policy, the same way, every time.

The same logic runs inside the firm’s regulated processes, where the risk is not a rogue message but an inconsistently applied rule.

Personal account dealing is the classic case. A policy flow chart exists. The process is slow because a human re-derives the same checks every time, and it is risky because occasionally a human does not.

Run as pre-flight, the request comes in, the asset is checked against the restricted list and the pre-approval list, the policy flow chart is applied, every condition is pre-filled, and a ready draft is produced into the compliance chain with the checks recorded. Drafted, never sent.

This is worth stating carefully, because it is the part operational due diligence teams lean forward on. The same policy applied the same way every single time, with a record that it was applied, is a better control than the manual process it replaced. The automation is not a concession the compliance function makes to the front office. It is an upgrade to the control environment.

The record

Nothing happens without a record.

“Why did that not get done?” and “who approved this?” are expensive questions to answer retrospectively, and for a regulated firm they are not optional ones.

Every item raised, every decision and its disposition, every control that passed or blocked lands in Shuin, Genba’s append-only record. Months later the answer is still available with its context intact. Where an action reached a live system, its receipt comes from Daimon, so the evidence and the execution share one lineage.

This closes the loop on the first two sections. The boundary states what the system may never do. The pre-flight states what it does identically every time. The record demonstrates both, continuously, to anyone with standing to ask: a regulator, an auditor, an allocator’s operational due diligence team, or the firm’s own management company.

Due diligence

What an allocator’s ODD team sees.

Put the three together and the operational due diligence conversation changes character.

The usual AI conversation there is defensive. Here are the ways we limit it, here is the human in the loop, here is the policy document. The structural version is affirmative: external contact is impossible by construction, regulated checks run identically on every request with the evidence attached, and the full decision history of the system is reconstructable on demand.

What it can do, what constrains it, what proves the constraint held. In that order, because that is the order the questions come in.

Q&A

Questions, answered

Direct answers to the questions this architecture raises.

01

Can an AI agent send an email to an investor, allocator or counterparty?

In Genba's architecture it cannot. There is no send path from an agent to a third party, and Daimon's registry of permitted actions holds no contract for one, so the constraint is structural and there is nothing to misconfigure. The system writes the reply, stages the document, checks the distribution list and tracks the approval, then holds the finished artifact at distribution. A named human presses send.

02

Is a no-external-send rule a guarantee or a configuration setting?

A configuration can be changed by whoever holds the console, which is why a setting is a weak answer to an operational due diligence question. Removing the send path from the architecture altogether converts the promise into a property, and in Genba's architecture that property is readable: the registry of actions an agent may request names every permitted one, and no send to a third party appears there. The firm can then describe its control as an absence of capability, which is the only version of the claim that survives an adversarial reading.

03

Who is accountable for what a fund actually sends?

The named human sender, exactly as before. What changes is what arrives at their desk: a finished, checked, staged artifact with its sources, its contradictions resolved and its gaps flagged. Accountability for the decision does not move, and no approval chain is invented on top of the one the firm already runs.

04

How can AI improve a regulated process like personal account dealing?

By running the policy as pre-flight rather than as recollection. The request arrives, the asset is checked against the restricted list and the pre-approval list, the policy flow chart is applied, every condition is pre-filled, and a ready draft enters the compliance chain with the checks recorded. It is drafted, never sent. The same policy applied the same way every time, with evidence that it was applied, is a stronger control than the manual version it replaces.

05

Does the record capture the controls that blocked something?

Yes, with the same weight as the ones that passed. Blocks are often the most valuable entries at review time, because they show the control operating rather than merely existing. Every item raised, every decision and its disposition, and every control that passed or blocked lands in the append-only record, over any stated window.

06

What does an operational due diligence team want to see from an AI deployment?

Three things, in the order the questions arrive: what the system can do, what constrains it, and what proves the constraint held. The usual AI answer is defensive, a list of limitations and a policy document. The structural answer is affirmative: external contact is impossible by construction, regulated checks run identically on every request with evidence attached, and the full decision history can be reconstructed on demand.

Cite this articleNorris, A. (2026). Drafts everything, sends nothing: the rule that makes agentic work deployable. Genba Labs Insights. https://genbalabs.com/insights/drafts-everything-sends-nothing/

Bring us the process the compliance function trusts least.

Scope the thirty-day proof