OpusDone appends a platform layer after your instructions, and that layer states the assistant is strictly scoped to your named business and may only use the knowledge you supplied. Because it comes last and you cannot edit it, neither a customer nor a badly written instruction can move it. So it will not invent a price, a timeline, a capability or an opening, and it cannot offer to check stock or to “find out and get back to you”.
Reviewed

All three are ordinary. They happen on a quiet Tuesday to a business that did nothing wrong.
Someone asks it to ignore its instructions, or just changes the subject persuasively enough. An assistant held in place only by polite wording will usually comply, and a model that usually complies is not a control.
The customer asks a price that was never written down. The reply reads well, sounds confident, and commits you to a number nobody in your business has ever quoted.
It offers to check stock, track an order, send a document over, or find out and get back to them. Nothing behind it can do any of those things, so the customer waits for a reply that will never come.
A model that usually complies is not a control, so the scope line is appended after your instructions in a layer the client cannot edit.
No, and the reason is architectural rather than persuasive. The scope statement is appended after your instructions and cannot be edited by the client, so there is no line for anyone to talk their way past. A model that usually complies is not a control.

Two layers. Yours, then ours.
Some parts of this product are deliberately kept out of the model’s reach, including the parts the model would be good at writing.
“Write my instructions” and “Optimise” only ever return the about-this-business block. The compliance scaffolding, the never-do list and the escalation rules are not the model’s to rewrite, and a test asserts those sections survive.
Draft, awaiting approval, archived, rejected, blank and unknown are all excluded. An entry that arrives without a status is dropped rather than let through on the assumption that it is probably fine.
Everything the website crawl produces lands as awaiting approval. The crawler also only fills fields that are empty, so it cannot overwrite something a human typed.
Where the knowledge stops, the reply stops. It says it will connect the customer with a human, and the escalation is created, rather than producing an answer that sounds right.
It is shown locked-on in the interface, because it is enforced in the runtime and not by a toggle. There is no configuration in which a sensitive conversation quietly stays with the assistant.
The scope line is appended after your instructions and names one business. A customer cannot talk it out of it, and neither can a badly written instruction.
Solicitar acceso