Trust
Trust

Aptoria Trust Spine System Card: Boundaries, Intercepts, and Action Records

A plain-language system card for the actions Aptoria prohibits or requires humans to review, the pending actions that can be cancelled, and the records available for review.
Updated September 2026
The short answer
Is AI property management safe? No product can make that universal promise. Aptoria reduces specific risks by keeping 14 published action classes restricted, giving eligible pending actions a scoped cancellation window, and recording supported workflow context for review. These controls do not certify legal compliance. Safety still depends on the property, jurisdiction, provider, configuration, source records, and responsible human judgment.

What we’ll cover

The restricted floor — prohibited actions and defined consequential actions requiring human review
The soft-commit workflow — a cancellation window for eligible pending actions
Action history — reviewable records with available verification context
Property-management software can affect money, housing, vendors, and tenant communications. A security page alone does not explain who remains responsible for those outcomes. This public system card describes Aptoria’s current product boundaries so a customer can compare the copy with the configured workflow, provider state, and resulting activity record.

1. Prohibitions and Human Review

Aptoria’s current execution controls keep 14 published consequential action classes on a restricted floor. Customers are not offered a setting that enables autonomous execution for these classes. Aptoria may organize source records, identify a review step, or prepare a draft, but the authorized person retains the decision and any required external process.
The current public action classes are generated from the same reviewed product-control registry used by Aptoria’s other trust surfaces:
Action class
Restriction
Reason for the hold
Terminate a lease
Human review required
Ending a tenancy is a judicial-process decision with statutory notice timing — always yours.
File or advance an eviction
Human review required
Possession actions require jurisdiction-specific process and must never be automated from an unsupported legal conclusion.
Deny an applicant
Human review required
FCRA adverse-action rules require human sign-off and proper notice.
Deny an accommodation request
Human review required
Fair Housing Act — only the landlord may decide, with a documented reason.
Deduct from a security deposit
Human review required
Deposit deductions run on statutory clocks with itemization duties — always yours.
Serve a rent-increase notice
Human review required
Notice timing is tiered by tenancy length under state law — served by you, on your decision.
Send a formal collection demand
Human review required
Formal dunning carries consumer-protection formatting duties — never autonomous.
Pool your data to set rents
Prohibited in Aptoria
Your numbers never feed a shared pricing model. Hardcoded — no setting can switch it on.
Set rent from external data
Prohibited in Aptoria
Launch policy prohibits automated rent setting from external data, including public-data inputs.
Report a resident to a credit bureau
Human review required
Credit reporting remains unavailable for launch; a configured provider or approval cannot enable it.
Downgrade or close a habitability concern
Prohibited in Aptoria
A model cannot reduce urgency or close a habitability concern without accountable human review.
Override a deposit deadline
Prohibited in Aptoria
Deposit deadlines cannot be extended or suppressed by an agent, workspace setting, or model.
Impose a mandatory fee
Prohibited in Aptoria
The agent cannot create or impose a mandatory fee; enabled fee workflows require separately reviewed authority.
Score a resident’s risk
Prohibited in Aptoria
Proprietary resident risk scores are permanently prohibited. Review source facts and make required decisions as a human.
Approval cannot enable prohibited actions. Human review does not activate a workflow. This boundary is not a legal conclusion or compliance certification.
The floor is an execution boundary for supported Aptoria workflows. It does not monitor activity completed outside Aptoria, establish that a customer’s process is lawful, or remove the customer’s responsibility for the decision.

2. The Soft-Commit Workflow

Eligible irreversible autonomous actions routed through Aptoria’s soft-commit workflow receive a 15-minute cancellation window before execution. The pending record shows when that control applies. Standing-authorized workflows, provider-managed operations, and actions already completed outside the pending state can follow different authorization, settlement, cancellation, or remedy rules.
What the window does — and does not do
When an eligible action is still pending and the cancellation control is available, cancelling it prevents that Aptoria soft-commit execution. Notification delivery and the availability of the control depend on the configured workflow.
The window is not a universal hold on payments, messages, vendor work, or provider operations. It cannot reverse a provider or external action that has already completed; corrections, refunds, disputes, and other remedies follow the applicable workflow and provider process.
Other supported actions follow their published approval and escalation rules. Review the action class, provider state, policy, and current status before relying on a cancellation control.

3. Reviewable Action History

Supported Aptoria workflows record available action, policy, approval, and outcome context in the workspace. Some supported records include hash-chain verification context that can help reveal a later mismatch. Coverage depends on the record type and workflow; an activity entry is not proof that an external provider delivered, settled, filed, or accepted an action.
Action history is an operational review artifact, not a complete legal record. It does not establish admissibility or promise acceptance by a court, regulator, auditor, insurer, tenant, or provider. Customers remain responsible for their own retention duties and for preserving source and provider records appropriate to the matter.
Where export is supported, review the export scope and available verification details before relying on it.

4. Product Control Specification

A product label such as “AI agent” does not describe what the software may do. The useful specification separates assistance from authority, records the controls that can narrow an action, and identifies the evidence needed to verify an external outcome. This table summarizes the current public control model; availability still has to be checked for the specific workflow and account.
Control field
Current public specification
AI operating model
Policy-bound assistance and execution for registered workflows; not unrestricted autonomous management.
Human gate
The published restricted floor and any effective policy result requiring review keep the decision with an authorized person.
Permissions
Account policy may narrow supported actions; it cannot weaken the published floor, sealed constraints, or an active kill switch.
Spending authority
Supported workflows may use configured amount thresholds, subject to product and provider availability.
Sensitive housing decisions
Applicant denial, accommodation denial, lease termination, eviction, deposit deductions, and other listed consequential classes remain human-owned.
Evidence and reasoning
Supported records can link policy results, reason codes, source references, approvals, execution state, and provider receipts when returned.
Reversibility
A pending cancellation window applies only to eligible soft-commit actions; completed external effects may require compensation or may be irreversible.
Provider boundary
An internal success state is not proof that a provider delivered, settled, filed, or accepted an external action.
Integration boundary
A catalogued integration is not automatically an authorized production connection; account authorization, supported scope, and receipts still matter.
Geographic and legal scope
United States-focused educational and workflow support does not establish that a particular action is permitted in a property’s jurisdiction.
This is a product-control record, not a certification of legal compliance, workflow availability, or external outcome.
How to use this specification
For a purchase or implementation review, replace each general row with the exact workflow, property, provider, policy version, responsible person, exception path, and expected receipt. Treat an unsupported or unavailable field as a release blocker rather than filling the gap with a marketing assumption.

Why These Boundaries Matter

Bounded automation is useful when its authority, stop points, and evidence are visible. The human-required floor prevents selected consequential decision classes from being delegated through supported Aptoria controls. Soft-commit can add a cancellation opportunity to eligible pending actions. Action history makes the product’s own workflow easier to inspect. Each control has a defined scope, and none transfers legal or operational responsibility away from the customer.
That scope is part of the product design: availability can depend on the property, jurisdiction, provider, account, plan, configured policy, and current release. The Trust Center and Availability pages publish the current status and launch requirements for customer-facing workflows.

How to Evaluate the Controls

Review the Trust Center entry for the workflow, including current limits and launch requirements.
Use a non-consequential test to confirm the human-required path and escalation owner.
For an eligible soft-commit action, inspect the pending status and test cancellation before production reliance.
Inspect the resulting activity record and compare it with the source and provider records.
Confirm retention, legal, accounting, security, and provider requirements with the responsible professionals and vendors.

Key takeaways

Aptoria publishes a human-required floor for defined consequential action classes in supported workflows.
The 15-minute soft-commit cancellation window applies to eligible pending actions, not universally to provider or external operations.
Action history is a reviewable operational record with workflow-dependent verification context, not a legal or compliance certification.
Evaluate AI software with a field-by-field control specification instead of inferring authority from an “agent” or “automation” label.
Evaluate each workflow against its current configuration, provider state, limits, and responsible human owner before relying on it.

Frequently asked

Is AI property management safe?
It can be safer when authority is narrow, consequential decisions stay human-required, pending irreversible actions have clear stop points, and activity is reviewable. Those controls reduce defined risks; they do not guarantee legal compliance or a correct external outcome. Evaluate the exact workflow, provider, jurisdiction, configuration, and human owner.
Can I trust AI with my rental property?
Trust should be earned workflow by workflow. Start with a low-consequence task, confirm the source records and authority boundary, test the exception and cancellation paths, and inspect the resulting activity record before expanding scope. Keep legal, housing, financial, and emergency decisions with the responsible people and professionals.
What should an AI property manager never do alone?
Aptoria’s current public floor contains 14 restricted classes: terminate a lease, file or advance an eviction, deny an applicant, deny an accommodation request, deduct from a security deposit, serve a rent-increase notice, send a formal collection demand, pool your data to set rents, set rent from external data, report a resident to a credit bureau, downgrade or close a habitability concern, override a deposit deadline, impose a mandatory fee, score a resident’s risk. The human-required classes require an authorized reviewer; approval cannot enable prohibited actions or activate a held workflow. Separate spend thresholds can also route money actions for approval; a threshold hold is not the same as the fixed restriction floor.
Can Aptoria send or advance an eviction notice on its own?
No. Serving an eviction notice and filing or advancing an eviction are blocked execution kinds. Aptoria may organize available records or prepare material for review, but the responsible person and qualified adviser must verify the authority, grounds, content, timing, delivery, service, filing, and jurisdiction-specific process.
How does Aptoria handle Fair Housing-sensitive decisions?
Applicant denials and accommodation-request denials remain human-required. Supported AI-generated tenant or applicant messages can be routed through pre-send housing-language review, but that review can miss issues and is not a legal determination or compliance certification. Written criteria, source accuracy, human review, and qualified advice still matter.
Can I configure Aptoria to autonomously execute a human-required action class?
No customer setting currently enables autonomous execution for the published human-required floor. Aptoria may prepare supporting records or a draft, while the authorized person retains the decision and external process.
Does the human-required floor mean each routine step needs approval?
No. Approval depends on the supported action class, current capability status, configured policy, provider state, and exception path. Consequential decisions on the published floor remain human-required.
Is the action history a legal evidence package?
No. It is an operational record of supported Aptoria workflow activity. It does not replace source documents, provider receipts, legal records, or professional advice, and acceptance by an external party is not guaranteed.
Does the 15-minute window apply to urgent repair coordination or completed payments?
Only eligible pending actions routed through the soft-commit workflow receive that window. Provider-managed, standing-authorized, completed, and external actions can have different timing and remedy rules.
Questions about a specific setup: contact Aptoria and identify the property, workflow, provider, and action class. We will scope the answer to the current configuration and published availability.

See it run your building.

Aptoria does the routine work within limits you set, and asks before anything consequential. Starts at $19/mo for up to 5 units.