There are two futures of AI being sold to merchants right now, and we think both of them are wrong.
The first future is the fully autonomous one: an AI that runs your store while you sleep, no questions asked — including, unfortunately, the questions you'd want it to ask. Give an unaccountable system write-access to prices, refunds, and customer relationships, and every mistake it makes is a mistake you discover after the fact, in your revenue, with no explanation attached.
The second future is the safe-but-useless one: an AI that only ever suggests. It drafts, it recommends, it nudges — and every single output lands in your lap as one more thing to review, edit, and execute. That's not a colleague; that's a very confident intern who can't be left alone with anything.
Autonomy without accountability is a liability. Autonomy with a receipt is a colleague.
The gate, precisely
Confirm-gating is the middle path, and it's narrower and more specific than “human in the loop.” In Lumnya, any action that touches money or a customer goes through the same four steps, every time:
- Preview — you see the exact change: before/after price, refund amount, the email as it will be sent.
- Approve — one tap for yes, one for cancel. No buried settings, no default-to-act.
- Execute — Lumnya performs precisely the previewed change, nothing adjacent.
- Log — the action lands in the audit trail with who approved it, when, and the reasoning.
The key property is that the preview is falsifiable. A promise like “I'll fix your pricing” can hide anything. A preview like “Oxygen Pro: €520 → €572” can be checked against your own judgment in two seconds. Confirm-gating works because it converts trust from a feeling into a comparison.
Autonomy is earned, not assumed
Every agent in Lumnya starts in recommend mode. The Inventory Forecaster's first reorder proposal arrives with its math showing — stock status, thresholds, priority — and waits. After weeks of watching an agent be right, you can widen its leash, one agent at a time. Autonomy in Lumnya isn't a product tier. It's a trust level you grant, per specialist, based on a track record you can inspect. You can see the same standard applied to a live buying decision in our Stocky migration guide.
This mirrors how you'd manage a human hire, which is not a coincidence. Nobody gives a new employee the company card on day one. But nobody makes a five-year veteran ask permission to send a routine email, either. The dial exists because the relationship changes.
The log is what makes trust scale
Approvals handle the moment of action. The audit trail handles every moment after. When something looks off next Tuesday — a price you don't remember setting, a refund you want to double-check — “why did it do that?” has a concrete answer: the entry, the data it used, the reasoning, the approval. No black boxes, no archaeology.
We think of the log as a product feature, not a compliance checkbox. It's the difference between an assistant you have to babysit and a team member whose work you can review on your own schedule.
What we refuse to ship
- Silent changes — if it matters, you saw it first or it didn't happen.
- Unexplained actions — every entry in the trail carries its reasoning.
- Default autonomy — recommend-first is the factory setting, always.
- Trust theater — no borrowed badges, no claims we can't back. (Our Security page lists what's actually true.)
The industry will keep promising fully autonomous everything, because it demos well. We'll keep shipping the gate, because stores run on it. If that trade appeals to you, the waitlist is open.
Comments
…Every comment is read and approved by a human before it appears — the same confirm-gated rule the product runs on.
Loading comments…
Filed under Product
All posts