Consent + agency
MagnusAI acts on your behalf only within the green-light matrix you explicitly grant. This document spells out how that works in legally meaningful terms.
1. Default state
Every permission is OFF by default. New accounts start in Cautious mode (confirm every action) until you change the mode.
2. Permission tiers
- Cautious: confirm every action via push or in-app modal.
- Balanced: pre-approve low-risk actions; confirm money + posting.
- Autopilot: pre-approve everything in your green-light list. Voice-confirm above your $-threshold.
- Custom: per-permission grant matrix in the dashboard.
3. In-the-moment consent
Before any irreversible action MagnusAI surfaces a prompt with: the action itself, the reversibility flag (irreversible / scheduled / reversible), the dollar amount if any, and an explicit confirm button. Voice confirmation is accepted.
4. Voice authentication
Set a $-threshold (default $100). Any action above it requires a voiceprint match. Voiceprint is a hashed embedding stored locally + cloud — not raw audio. Friend grabs your phone? They can't spend your money.
5. Capability gating
Capabilities are color-coded: GREEN (auto-allowed), YELLOW (regulated, sign-off required), ORANGE (gray intent — never built), RED (illegal — auto-rejected), UNKNOWN (escalates with research). Money / minors / medical / firearms / privacy / gambling / securities are always YELLOW or harder.
6. Audit trail
Every action MagnusAI takes is logged with the "why" — which capabilities were considered, which scopes were checked, which user instructions led here. Tap any row in /app to see it.
7. Revocation
Revoke any consent grant at any time from /app. Revocations take effect immediately for all in-flight and future actions.
8. Emergency stop
Single voice command ("MagnusAI: stop.") or button in the app pauses every in-flight action instantly. Resume requires explicit re-grant.
9. Minors
Under-18 accounts are minor-mode by default with a restricted capability subset. Parental consent is required for non-minor capabilities and is verified out-of-band before any tool dispatch.
Last updated: April 2026. Draft v1 — pending legal review.