Trust / Boundaries, control, and evidence

Know what the system saw, proposed, sent, and changed.

Korrd is designed so an operator can reconstruct every consequential action without trusting a hidden agent conversation or a vague “automated” status.

Control chain

Four distinct jobs. No collapsed authority.

AGENT / PROPOSE

Prepare the next action

Typed intent, evidence, assumptions, risk flags, case version, approval class, and expiry.

POLICY / AUTHORIZE

Check what is allowed

Identity, consent, suppression, quiet hours, limits, case state, required approval, and kill switches.

HUMAN / OWN

Exercise authority

Inspect and approve the exact message, schedule commitment, decision request, or PMS diff.

SYSTEM / VERIFY

Prove the result

Provider receipt, external read-back, immutable event, and visible exception when reality differs.

Data corridor

Reference first. Copy only what the workflow needs.

Buildium remains the property-management source of truth. Korrd stores synchronized operational state, evidence references, communication records, approvals, and its own audit ledger.

BUILDium / SOURCE

Current operational record

Work order, property, unit, resident endpoint, approved vendor, task history, status, and supported files.

Korrd / MINIMUM

Resolution state

Case version, next action, consent, policy, evidence reference, messages, approvals, external IDs, and audit events.

CLIENT / AUTHORITY

Operational decisions

Emergency response, repair scope, vendor eligibility, spending, legal duties, disputes, and final closure authority.

No confidential records through the public site.

The application and calculator ask for company-level operating information. Do not send resident names, phone numbers, addresses, work orders, recordings, vendor invoices, credentials, or API keys.

Messaging controls

A connected phone number is not permission to text.

Client separation
One client Twilio subaccount, registered brand/campaign, Messaging Service, and pilot number. No shared sender identity across unrelated clients.
Consent evidence
Store purpose, disclosure, version, source, timestamp, and revocation. A phone number in Buildium alone is not treated as consent.
Opt-out
STOP and natural-language opt-outs suppress immediately and cancel queued messages. START restores only after provider and Korrd state agree.
Identity
Unknown senders receive no property or resident information. Multiple plausible cases enter disambiguation instead of a guessed match.
Delivery
Ambiguous provider timeouts remain unknown and are reconciled; Korrd does not blindly send a possible duplicate.
Quiet hours
Routine sends use property-local time. Missing timezone blocks automation. Client policy and counsel review control production settings.

Messaging and call-recording obligations vary by use and jurisdiction. Production requires client counsel review; this page is not legal advice.

Permanent product boundaries

Some work should be routed faster—not automated further.

These limits remain even as Korrd adds voice, multilingual communication, routine autonomy, additional PMS connectors, vendors, and financial workflows.

EMERGENCY

Detect and transfer

Korrd does not diagnose emergency or repair conditions as fact.

AUTHORITY

Never impersonate approval

Korrd cannot fabricate the legal authority of an owner, manager, or resident.

SPENDING

No unrestricted funds

Any later financial action remains policy-bounded, authorized, provider-executed, and reconciled.

SENSITIVE

Human review

Fair-housing, accommodation, debt, legal, insurance, habitability, and disputes leave routine automation.

ACCOUNTING

Integrate, do not replace

Korrd does not become a general ledger, trust accounting, or owner-statement system.

CLOSEOUT

Evidence before closure

Missing proof, consent, approval, or conflicting source state blocks closure.

Control status

Implemented foundations are separate from production targets.

“Foundation” means code and tests exist in this repository. “Pilot gate” means the control must be implemented, configured, and accepted before live client activation.

FOUNDATION / IDENTITY

Tenant isolation

Tenant-owned contracts, PostgreSQL row-level-security migration, composite tenant keys, and in-memory cross-tenant denial tests exist. Production organization auth and a live database verification remain pilot gates.

PILOT GATE / SECRETS

Scoped credentials

Per-client provider connections, managed secret storage, encryption policy, credential rotation, and revocation procedures must be verified in the selected production environment.

FOUNDATION / JOBS

Durable execution contract

A PostgreSQL queue, transactional-outbox schema, retry contract, and pre-dispatch authorization interface exist. Production remains blocked until certified durable handlers and repositories are connected.

PILOT GATE / FILES

Private evidence

Private object storage, file validation, malware scanning or quarantine, hashing, expiring links, retention, and deletion are required before real evidence upload.

FOUNDATION / MODELS

Bounded proposals

Typed proposal-only outputs, server-owned metadata, evidence aliases, risk interruption, and minimized context are implemented and tested synthetically. Live model use remains an explicit provider gate.

PILOT GATE / STOP

Independent kill switches

Tenant controls for agents, SMS, email, voice, scheduling, writes, estimates, financial actions, auto-close, and workflow packs are required before those capabilities are activated.

Founding-stage answers

Specific answers, including what is not yet true.

Is Korrd currently connected to live client Buildium or Twilio accounts?

The public reference desk uses synthetic data and simulated external events. Live Buildium, Twilio, SendGrid, and voice connections are founding-pilot capabilities that require client onboarding, provider registration, sandbox testing, UAT, and explicit activation.

Does Korrd claim a security certification?

No independent certification is claimed. Production controls, hosting, subprocessors, retention, access, incident response, deletion, and contractual requirements are reviewed for the specific deployment.

Do agents directly text residents or edit Buildium?

No. Agents produce typed proposals. Deterministic code checks policy and approval, then a connector performs an allowlisted action. In the founding pilot, every consequential action requires human approval.

Does Korrd train a shared model on client data?

Korrd does not use one client’s resident, vendor, work-order, communication, or outcome data to train a shared cross-client model. Provider settings and any client-specific evaluation use are disclosed before production.

What happens when a resident reports an emergency?

Routine coordination pauses. The system plays or sends approved safety language where appropriate, routes the case to the client’s on-call path, records the escalation, and does not diagnose the condition.

Can a client see every automated action?

The design requires case timelines, message delivery events, consent changes, proposals, approvals, policy versions, provider results, PMS diffs, read-back verification, and exceptions to be available for review and export.

Inspect before access

See the controls on fictional cases first.

The synthetic desk demonstrates resolution states, evidence, approvals, message handling, policy interruptions, and verified closeout without using customer data.