BusyIncorporated
← Safety overview

Part 4 of 5

The decision comes to you

How 2FO approves an exact action outside the Persona’s control.

The work pauses at the decision.

A Persona can prepare work that needs permission without deciding the permission for itself. It drafts the email, identifies the recipient, or prepares a proposed bid change. The action waits.

Busy sends an approval request to you by push notification or SMS. The request carries the specific action, the recipient or target, and an expiry. You can see what you’re approving before anything goes through.

We call this Two-Factor Override, or 2FO. The decision arrives outside the system asking for permission.

A yes in chat isn’t the whole control.

When an assistant asks “May I email Dan?” in a conversation, the same AI can be responsible for asking, interpreting your reply and sending the message. It still has to infer what your yes applies to.

With 2FO, the approval is attached to the action being reviewed. The permission check and execution sit outside the Persona. Approval releases that action; it isn’t relayed as a loose instruction for the model to act on later.

The Persona is then told the result. It doesn’t need to reinterpret your approval or choose a new action to carry out.

Approve this action, or deliberately change the rule.

A one-time approval stays one-time. Approving a message to a new recipient doesn’t silently authorize outreach to everyone else.

Where lasting permission is appropriate, you can grant it explicitly—for example, adding a contact to the approved list. That is a different scope of approval from sending one prepared email.

The distinction lets the Persona become more useful over time without turning every exception into unrestricted access.

No answer is still an answer for the system.

If you decline, the action stays blocked. If the request expires before you answer, it also stays blocked. An approval request doesn’t wait indefinitely and then proceed by default.

The request is recorded outside the Persona’s own process. Its status doesn’t depend on keeping one chat or one run alive. Busy can report that the request expired, that nothing was sent, and where the draft remains.

Why we built it this way.

Jeff once forwarded a friend’s request to Vera. She prepared the document and reply, then returned them only to Jeff because the friend wasn’t on her approved list. He had to share the document and forward the message himself.

Opening Vera’s communication to everyone would remove that inconvenience and a useful boundary at the same time. 2FO gives the owner a way to authorize the specific send while keeping that boundary in place.