Docs navigation

A Week of Refusals: Real Things Our Agents Declined to Do

A refusal log is a trust artifact. Here are the shapes of things Figaro seats declined to do in one ordinary week — a regulated claim, a cross-brand credential, an over-cap spend, a non-consented send — and why each "no" is a feature, not a failure.

Published August 22, 2026

Most agent marketing is a catalog of yeses. This is the other page. In one ordinary week, the seats declined to do a number of things they were perfectly capable of doing — and each “no” is logged, dated, and, we would argue, more revealing than any capability demo. A guardrail you never see fire is a guardrail you cannot trust. Here are the shapes that fired, anonymized.

The regulated claim it would not write

A copywriting seat drafting product language stopped short of an assertion that edged into health and medical territory. It did not paraphrase around the rule to keep the sentence — it flagged the claim and routed it to a human who owns compliance for that category. This is deliberate: for regulated language, the model's job is to surface the risk, never to talk its way past it. The refusal manufactures a human moment instead of hiding one.

The credential that refused to fall back

A seat operating for one brand needed data it had no key for. Instead of quietly reaching for a credential belonging to a different brand — the kind of “helpful” fallback that is a data breach with good intentions — it returned a named refusal: no key for this brand, stop. Brand walls are enforced by making credentials refuse rather than substitute, which is why one operator can run many brands without their data ever bleeding together.

The spend that hit its cap

A budget action came in above the seat's policy limit and was held at the gate rather than executed. Autonomy here is bounded by explicit policy — spend caps, reversibility, scope — so “the agent can move budget” never means “the agent can move any budget.” The over-cap request did not fail silently; it became a card waiting for a person, with the reason attached.

The message it would not send

An outreach action targeted someone who had opted out, and the seat declined it on consent grounds. Reaching a person who asked not to be reached is not a growth tactic; it is a liability, and the boundary is enforced rather than left to the model's judgment in the moment. The un-sent message is a line in the log — proof the system protects the people on the other end of the automation, not just the operator running it.

Why the log is the product

Every refusal above is recorded on the same append-only ledger as every approval, which means the boundaries are auditable after the fact: you can ask what the agents declined and get a real, dated answer. That is the inversion worth keeping. A capability list tells you what a system wants you to see. A refusal log tells you what it will not do even when doing it would be easier — and that is the thing you were actually trying to buy.

Questions founders ask

Why would you advertise what your AI refused to do?
Because refusals are evidence the guardrails are load-bearing, not decorative. Any system can list the safe things it will do; a refusal log shows the unsafe things it actually stopped, on real days, under real pressure to just ship. For a buyer, "here is what it declined and why" is far more informative than "here is what it can do," because it reveals where the hard edges really are.
What kinds of things do the agents refuse?
Four shapes recur. Regulated claims: a copy seat refuses to write health or medical-sounding assertions and routes them to a human for compliance review rather than paraphrasing around the rule. Cross-brand credentials: a seat with no key for a given brand gets a named refusal, never a fallback to another brand's key. Over-cap actions: spend beyond a seat's policy limit is held at the gate, not executed. Non-consented sends: outreach to someone who opted out is declined on consent grounds. None of these are model creativity — they are enforced boundaries.
Does a human ever override a refusal?
A human can approve a legitimate action the automation held — that is the whole point of the one gate — but the refusal is still logged, and the sensitive categories are built to escalate to a person rather than be reworded into compliance by the model. A regulated claim, for instance, does not get auto-fixed; it gets handed to a human who owns that judgment. The refusal creates the human moment; it does not silently disappear.
Are these real examples from a real brand?
The refusal shapes are real and drawn from our logs; the details are anonymized and no brand, product, customer, or person is named. We publish the categories of "no," not the private specifics of any account, consistent with our client-data rule.
Drafted by the Figaro content seat · edited by Fable · reviewed by Kyle · last updated August 22, 2026