Skip to content
All articles

AI employees, not chatbots: what changes when the AI has a role, a manager and a trial period

A chatbot waits to be asked. An AI employee is on duty by events, works inside your permission model, proposes what it may not do alone — and can be paused like anyone else. Here is how that works in practice.

Most "AI in your CRM" comes down to a box you type into. It summarises a thread, drafts a reply, answers a question — and then goes quiet until you ask again. Useful, but it does not take work off anyone's plate: someone still has to notice that the work exists.

The alternative is to model the AI as a colleague rather than a feature: a role with permissions, a manager, a working day, a memory, and a probation period during which everything it decides is a proposal. That is what a persona is in Nextora, and the design decisions behind it are worth reading even if you are building something similar yourself.

Permissions are the role, not a prompt

At hiring, a persona receives a copy of a template role — "Sales manager", say. Whatever that manager can do, she can, within her charter. And here is the important half: if a task needs a permission she lacks, she asks for it instead of taking it. The request lands with an administrator as an ordinary approval.

That single rule removes the two failure modes people fear most. The AI cannot quietly widen its own reach, and you never have to grant broad access "just in case" — you grant what the work actually turned out to need, with the case attached.

RequestWhat approval does
PermissionThe permission code is added to her role
ChannelShe joins that channel
BotShe becomes the bot's supervisor
BudgetA new daily credit limit
HireThe hiring flow opens with her brief

Nothing is approved automatically, and one persona cannot approve another's request.

The trial period is the trust mechanism

A new persona works on trial: she is on duty and decides for real, but every decision lands as a quiet proposal on the record and changes nothing. You accept or decline. When the trial ends you get the numbers — how many proposals, how many accepted, how many undone — and one button: Activate.

This is a better answer to "can I trust it" than any confidence score. You are not judging the model in the abstract; you are reading a week of its actual decisions on your actual data.

ModeWhat happens
DraftHiring is unfinished; she does nothing
TrialOn duty, everything is a proposal, a report at the end
ActiveActs within the role; irreversible and outbound steps are verified
PausedNot on duty; answers direct requests only
RetiredHistory and memory kept, the account closed

A working day, not a prompt window

A persona is on duty by events — a new lead, an email, a task, a mention. Cheap checks run for free; the model is called once per window, when there is genuinely something to decide. On top of duty there are shifts on a schedule (a morning report in her home channel), assignments (a task assigned to her, a question in chat), and a night pass: reflection, lessons written into her profile, memory consolidated, and nought to three proposals for what she lacked.

The cost model follows from the design. An assistant you have to invoke is billed by curiosity; an employee on duty by events is billed by the work that actually arrived.

She shows up where you already are

There is no "AI section" to visit. A persona appears on ordinary screens, and always looks the same — a drifting orb generated from her id, her name, and the marker AI. The marker is not decoration: it is how you know the colleague writing to you is not a person.

  • A proposal on a record. Her reason in her own words first, then the text the customer would get. Buttons: send, reply yourself, dismiss.
  • A suggestion beside a field. The quietest form — she proposes a value, one click accepts it. She never writes the field herself.
  • In a channel. She writes like a colleague in the shared thread. Tell her a rule right there and she confirms it in her own words and remembers it.
  • Answering a customer. Her reply is signed with her name, so the operator can see a persona answered, not a bot.
  • In the morning. One line on the dashboard about her night. A quiet night produces no card.

What she will never do on her own

Grant herself a permission, change her own mode, spend beyond her budget, delete without confirmation, or write to a customer around the outbound policy. All of it she can only ask for — and a workspace-wide "stop outbound" switch turns every persona's sends into drafts at once.

Correcting behaviour without touching a prompt

Three ways, all of them things a manager already does:

  1. Tell her in chat. "@Anya, never touch VIP leads." That becomes a directive, it outranks the charter, and it applies from her next run.
  2. Ask her master. From her card, a side agent reads her charter, rules, procedures and logs, answers "why did she do that", and edits the rule. Every change shows up in her feed immediately.
  3. Accept her own proposal. Her nightly and weekly reviews suggest charter corrections; an accepted one becomes a new charter version, and any version can be reverted. A correction may change at most 15% of the charter per step.

Every run is inspectable step by step — the tool call, its result, her reasoning — for the times the plain-language feed is not enough.

Personas and bots are one ecosystem

A customer-facing bot answers by its flow; the supervising persona teaches it, checks it, and takes the dialogs it could not handle. Three details make that safe:

  • Handoff goes to her, not to the queue. She reads the conversation and what is known about the customer, and answers under her name — or passes it to a person with a reason.
  • Your rules become the bot's prompt, as a versioned section with a history.
  • The exam is the gate. A prompt change holds only with a green exam; if the next exam is worse, the change rolls back by itself and she says so.

How those conversations arrive in the first place is a separate discipline — see one queue for every channel.

An org chart, and it only points down

Every persona has a manager — a person or another persona — and the chain always ends with a human. Putting a persona under someone is the permission to assign her tasks. Work flows down only: a task cannot go up or sideways, cycles are refused by code, and a chain longer than five links stops and asks a human. Peer personas can read each other as context but cannot start each other's runs.

A task a persona assigns is an ordinary task with an assignee, a due date and a discussion. The person gets a notification that a persona assigned it; the result comes back as a comment on the task.

Hiring, in six steps

Hiring is a conversation rather than a form: a brief in your own words plus an archetype, up to four questions with ready answers, a charter written by the strong model, an access plan the persona assembles by surveying the workspace, a trial run over last week's real events, and then hire — on probation for N days, or active immediately.

Step five is the one to insist on in any system like this. Before she touches anything, she says what she would have done over the past week's events, with numbers and examples you can judge. Seven days of history, at most seven model calls.

Why this shape

Each of these decisions is a boring organisational answer to a scary technical question. Can it be trusted? Give it a probation period. What if it overreaches? Make permission requests the only path. What if it goes off the rails? Give it a manager, a pause button and an audit trail. What if it is wrong? Let it propose instead of act, and read the proposals.

None of that requires the model to be perfect. It requires the surrounding system to treat the model like a new colleague — capable, unsupervised at your own risk, and much more useful once the boundaries are written down.

See what this looks like in the product on the AI teammates page, and how the same records carry the work on the CRM record model.

See it on your own process.

Nextora is in private alpha: CRM, projects, ERP, omnichannel conversations and AI employees on one record model. Bring the process you want to fix and we will shape the workspace around it.

Request alpha access