Safety & permissions
How Cleo evaluates a call task before it can dial.
Content reviewed · Maintained by Cleo Powered · Report a documentation issue · Verification basis
Cleo identifies itself as an AI assistant calling on behalf of the verified owner of the workspace associated with your API key. The profile name is supplied automatically as caller_identity.name; do not supply caller identity in the request or task context. This identity does not prove permission to access a third-party account.
Purpose screening
Before execution, Cleo’s LLM safety layer evaluates the destination, objective, context, constraints, success criteria, requested output, and duration. API keys use the same purpose evaluator as the customer platform.
- Decision
- allowed
- Outcome
- The call can proceed to the remaining checks.
- Decision
- blocked
- Outcome
- The call cannot proceed.
- Decision
- review
- Outcome
- The call cannot proceed; the purpose or authorization needs clarification.
| Decision | Outcome |
|---|---|
| allowed | The call can proceed to the remaining checks. |
| blocked | The call cannot proceed. |
| review | The call cannot proceed; the purpose or authorization needs clarification. |
Missing safety configuration, timeouts, invalid model output, and authorization-signing failures stop the request. An allowed decision produces a signed authorization tied to the task, which the calling service verifies before dialing.
Calling permissions
A valid API key is necessary, but a call also needs an available assistant, workspace calling permission, and enabled service-level calling. Admission reserves allowed usage; the executor rechecks revocable caller, workspace, assistant, API-key, policy, and purpose authority before dispatch. An accepted queued job can fail if permission is withdrawn before dialing.
Public API calling has an independent service switch. Platform calls can work while API calls return live_calls_disabled. Contact your service operator if this happens; changing your task will not enable the switch.
Protected context
Ordinary context supplies facts to the calling model. Send private answers that must be withheld in protected_context: an object of named strings with the documented limits. Cleo stores these answers encrypted and redacts matching values from task prose, ordinary context, and execution snapshots before provider submission.
The current voice flow does not automatically disclose protected values to a recipient. Do not put passwords, card PINs, or one-time codes in this field or ordinary task text. Do not promise that an identity check requiring a withheld value will succeed. Redaction targets supplied protected values; it does not identify every private fact in free text. Protect the original payload in your storage, including during idempotency recovery.
Write a clear task
- Explain the legitimate purpose and your relationship to the recipient.
- Include only the information needed to complete the call.
- State what Cleo may do and what requires further approval.
- Ask the assistant to identify itself appropriately and stop if the recipient declines.
Fraud, impersonation, harassment, nuisance calls, unsolicited marketing, and other prohibited uses can be blocked. A test_call label supplies context; it does not bypass screening.
The API currently returns some safety and workspace failures as 502 control_plane_error, with the explanation in detail. Read that explanation before deciding whether to retry.