Skip to main content
The execution layer is still being built, so nothing below runs yet. It describes the contract the errands are being built against, which is fixed.

Your assistant relays, it does not decide

When Hence needs something, the task moves to needs input and your assistant repeats the question in its own voice. You answer in the conversation, and your assistant returns the answer. Hence does the errand; your assistant carries the words. What Hence needs falls into a few kinds, and the kind decides the mechanism.

A data point

Something only you know, that the portals do not show: the rate written on an original car loan contract, which of two employers a plan belongs to. Asked as a single question, with options wherever the errand knows the options. Hence never asks for a value it already holds. If your profile carries the answer, that answer is used, and what you tell it here is kept so the next errand does not ask again.

A yes or a no

Asked as a two-value question. Accept and decline are distinct answers, and cancelling the question counts as no. Nothing proceeds on silence.

An approval

An approval is a yes that authorizes a consequence — changing a deferral rate, sending a request to an issuer. Three rules attach to it:
  • It names the exact parameters. Not “change your contribution rate” but the current rate, the proposed rate and what it is worth.
  • It is bound to those parameters. The approval is checked again at the moment of acting; if anything changed in between, Hence asks again rather than proceeding on the old yes.
  • One approval authorizes one act. There is no standing yes.
Approvals come to you through your assistant, as an ordinary two-value question. A confirm page on our own domain exists and an errand can be built to require it, but no step defaults to it today.

A credential or a one-time code

This one never travels through the conversation. Hence sends your assistant a link, your assistant shows you the domain, and you sign in on a single-use page on our domain. Your assistant never sees the password or the code. Neither does the model: the value goes from your browser into the form it was requested for, once. That is the whole mechanism, and it is the reason these docs can promise that no credential appears in the flow.

Access to another service

Where a third party has a proper authorization flow, Hence uses it: a link into that service’s own consent screen, with the resulting access held by us and never passed to your assistant.

What you will never be asked

You will not be asked to hand your assistant a password, an API key or a one-time code; to approve something whose parameters are not shown; or to give a blanket authorization covering future acts. If something claiming to be Hence asks for any of those, it is not Hence.