minarray
Menu

Built to limit what an agent can do, including ours.

Two halves of one argument: how the limits are enforced, and what we disclose so you can check them.

1.1

Isolation, and a real daily ceiling.

Every account is isolated at the data layer: one tenant’s runs, candidates, and credentials are never reachable from another’s. Quotas are enforcement, not a courtesy: each account has a real, configurable daily limit on the capabilities it uses, checked atomically before a run is even queued, and reset on the UTC day.

1.2

lead_research: it will not invent a fact.

Every result passes through one validation path that never invents and never upgrades: it drops what cannot be believed and downgrades what is unsupported. A candidate with no company name or no evidence is dropped outright. A LinkedIn URL that is not a real linkedin.com address is discarded rather than shown. An invented profile link is worse than a blank one, because it gets clicked. A candidate no source URL backs is forced down to low confidence. Every one of those interventions is written into the run’s own warnings, so “the research found less than it claimed” is visible rather than silent.

1.3

Durable memory: admitted, never inferred.

An agent set to persistent memory does not quietly accumulate whatever it read in a conversation. A fact enters memory through exactly one narrow, explicit tool call, so every stored fact traces back to the turn that admitted it. Retrieval is bounded and gated a second time on that agent’s own memory mode, and deletion is real: a deleted memory is immediately excluded from retrieval, not hidden from a listing while still informing answers.

lead_research.warningsrecorded interventions · verbatim from the validation code
  • never invents · never upgradesdropped <company>: no company name
  • never invents · never upgradesdropped <company>: no evidence given
  • never invents · never upgrades<company>: discarded a LinkedIn URL that is not a linkedin.com address
  • never invents · never upgrades<company>: downgraded to low confidence: no source URL backs this up
2.1

Live means live.

Every capability on this site carries a status. LIVE means it runs in production for tenants today. LIVE / GATED means it runs, and a human review gates every engagement. LIVE / INTERNAL means it runs, but only for us. There is no sign-up path yet. MODELED means it is specified and not built. If you ever find this site describing a MODELED capability as available, that is a defect: tell us and we will correct it publicly.

2.2

Telephony, plainly.

place_call puts real phone calls into the world, which makes it a regulated activity, not a feature toggle. There is no formal telephony compliance certification behind minarray today. What exists instead: every engagement that involves calling is reviewed by a person before the first call is placed, and we decline work we can’t do lawfully. When a certification exists, it will be named on this page. Until then, this paragraph is the disclosure.

2.3

personal_assistant runs founder-only.

A durable, voice-enabled assistant: text or speech in, text or synthesized speech out, every reply a durable attributable run, surviving restarts. It operates daily. It is not offered to tenants yet, because we ship capabilities to the registry when their operational story is provable, not when a demo works. Its row on this site stays LIVE / INTERNAL until that changes.

2.4

Why invites.

Telephony and store access are capabilities with real failure modes (a bad call, a botched restore), so a person weighs every account request against them before access is granted. Scarcity is a byproduct of that review, not the point of it.

2.5

What’s absent.

There are no client logos on this site, no testimonials, no compliance badges. That is deliberate: we publish the proof we actually own, the registry and the run records it produces, not names we’d be borrowing.

The registry these boundaries protect is on the front page, in full.

Request an invite