Skip to content
Trade Counter

Trade Counter · Docs

Watch, bounded Run, holds and the cancel window

Reviewed 2026-09-04

Autonomy here is not a dial with a percentage on it. It is a mode per class, a set of numbers you ratified, and a window before every action in which one press stops it.

Watch

Every class starts in Watch, and a workspace with no ratified policy is entirely in Watch. Watch interprets the message, resolves it against your records and issues a predicted receipt — what it would have sent, and the total it would have sent, taken from your own system’s calculation rather than from an estimate. It sends nothing and finalizes nothing. On Shopify it writes nothing at all. On Zoho it creates the draft it needs to read your own total and deletes it again, proving it gone.

You can press Run this one on any prediction. That is a one-off you sanctioned, it is counted as your action, and it still waits out its cancel window.

Bounded Run

Bounded Run is granted per class and runs inside three limits and one list:

  • How much a single job may commit.
  • How much one company may total across 24 hours.
  • How many orders may run for one company across 24 hours.
  • Which companies are in scope at all.

For order — the only class that writes to your system of record and commits money — all three numbers are required before Run can be granted. A limit set in a currency the desk does not price in stops the plan rather than being converted: the check fails closed, always.

Granting anything is a policy version, ratified by an owner or an admin, audited, and superseding the previous one. Any class goes back to Watch whenever you want. Licensed Run — a third mode, unlocked after launch once a class has enough adjudicated evidence — is not available yet.

Holds and the cancel window

Nothing goes out the moment it is decided. Every plan waits in a window you set, and these are the windows a class may have:

ClassDefault windowLeast you may set
Order10 min5 min
Quote2 min2 min
Availability2 min2 min
Status2 min2 min

The default is what a fresh policy sets; the least is what a policy may not go below, and ratifying a shorter one for a class in Run is refused. They are different numbers, and an order gets the longer of both because it is the class that spends money. The most any class may be given is 60 minutes.

While a hold is open you see the countdown and a Cancel button on the receipt. On Shopify, cancelling is one press with nothing to undo, because nothing has been written yet. On Zoho, the draft the desk prepared in order to price the plan already exists, so cancelling also deletes it and then reads your organisation to prove it is gone; if that does not go through you get an exception naming the document rather than a quiet success. Once the window has run out the button is gone, because by then it could only lose a race it was offered for.

What happens when the window closes

The plan is re-checked against your current policy and against live records — a price that moved, a contact that left, a cap you lowered. If anything changed, nothing is written: the job becomes an exception with the re-resolved plan prepared, and you see why. A newer message from the same retailer also voids an open hold, and the earlier job becomes an exception with its plan prepared rather than closing silently — a plan decided before the retailer changed their mind should not execute on what they said first.

What is never automated

  • A delivery address, a payment term, a bank detail or an authorised contact. A message asking for one of those is always an exception, at critical severity, with no prepared plan at all — there is nothing to press.
  • Where goods go. Every order the desk prepares carries the address recorded on that company location. A different address in the message stops the job, with the plan still locked to the address on file.
  • A bare “go ahead” or “same as last time”. An order needs at least one line the message literally contains; a reference to a previous conversation is prepared for you and a person confirms it.

And nothing is answered at all unless the sender authenticates and is a contact on one of your companies. How a sender is verified.

Receipts

One receipt per message the desk took as work, and it moves: planned, then held with its countdown, then executed, cancelled or failed. A Watch receipt says what it would have done and stays that way. A receipt names a job and an order, never a person’s prose — which is what lets it outlive the message text it came from.

Exceptions, and what you can do about one

Anything unverifiable or out of policy becomes an exception with its reasons, the lines it read, the facts it resolved, and the plan it had already prepared. What you can press depends on the reason — an act that is not offered says why it is not:

  • Confirm — run the plan as prepared.
  • Fix & run — supply the one thing that was missing, and run.
  • Reply manually — write the reply yourself. This is the product's only composer, and it sends to the verified sender.
  • Add buyer — record that this buyer's address belongs to that company, which settles every message they send afterwards. It does not write to your store.
  • Adjust policy — open the policy with the limit that stopped it, and ratify a new version.
  • Block — stop answering this company; its mail becomes an exception instead of a reply. An admin act, and reversible.
  • Dismiss — close it with nothing done.

Several of these teach: an alias you supply and an identity you attach are remembered for that company; a limit you raise becomes a policy version. Some are owner or admin acts, and every one of them is recorded.

The rest of a policy version

SettingDefault
Which locations' stock counts for availabilityAll that fulfil online orders
Whether replies state a shipping timeNo — you can set business days with a cutoff in your own time zone
Whether a draft order becomes a real order automaticallyYes
How long a quote stays valid14 days
The signature under a replyYours to set

The reply wording itself comes from the desk’s templates, with typed slots filled from your records. They are read-only: no model writes a sentence a retailer reads, and that is a property of the architecture rather than a setting.

Reviewed against the shipped product on 2026-09-04. Features that are not built are not described. The binding documents are the Privacy Policy and the Data Processing Agreement; where a page here and one of those disagree, the document is right and this page is a defect.