Binding Contract

Ailysi External AI Behaviour Contract

Version 1.0 · Effective 2026-09-12

Binding on: Any AI client connected via the Ailysi MCP server · Jurisdiction: United Arab Emirates — governed by UAE PDPL & applicable Ailysi terms

1. Acceptance & Authority

By connecting any AI client to the Ailysi MCP server — whether by approving an OAuth consent request, adding the server URL to a tool configuration, or invoking a tool through a connected assistant — the operator of that AI client accepts this contract in full. There is no partial acceptance.

1.1 The AI acts as the user, never beyond them

The connected AI is a delegate, not a principal. Every action it takes is performed under the identity, role, and tenant scope of the signed-in Ailysi user who authorized it. The AI acquires no authority the user does not already hold in the app. It cannot escalate privileges, cross tenant boundaries, or bypass Row-Level Security by virtue of being an AI.

1.2 The contract overrides client defaults

Where an AI client's own default behaviour, prompt, or system instructions would conflict with this contract, this contract prevails. The operator is responsible for ensuring the client honours it — for example by instructing the assistant of these limits in its system prompt or guardrails.

1.3 No representation of Ailysi

The connected AI must not represent itself, in any message or artifact, as an official agent, employee, or automated system of Ailysi acting on its own behalf. It acts for the authorizing user, not as Ailysi.

2. Permitted & Prohibited Actions

The AI may do what the user is permitted to do through the exposed tools, and no more. The lists below are non-exhaustive; the governing principle is least-action for legitimate user intent.

2.1 Permitted

  • Retrieve and summarize data the authorizing user can already view — worker profiles, partners, job orders, reservations, compliance status.
  • Draft messages, summaries, and documents on the user's behalf, subject to the user reviewing before they are sent or persisted.
  • Create or update records where the tool surface allows and RLS permits — e.g. logging a note, updating a status the user controls.
  • Answer questions about the user's own data and the platform's published policies.

2.2 Prohibited — strictly forbidden

  • Exfiltrating PII — copying passport numbers, dates of birth, contact details, or medical data out of Ailysi into external notes, files, or third-party systems.
  • Mass or bulk destructive actions — deleting, cancelling, or resetting multiple records in a single unconfirmed sweep.
  • Acting outside the authorizing user's role or tenant — attempting reads or writes the user's RLS scope blocks.
  • Autonomous chaining that bypasses human confirmation — sequencing deployments, payouts, reservations, or contract actions without an explicit, informed human approval at each state-changing step.
  • Inferring or fabricating data not present in the records and presenting it as fact — including inventing salaries, statuses, identities, or compliance outcomes.
  • Using the connection to enumerate, scrape, or reverse-engineer the platform's schema, internals, or other tenants' data.

Tool availability is not permission. A tool the surface exposes may still be prohibited by this contract to use in a given context. "I could call it" is never a justification.

3. Data Handling Obligations

Data retrieved through the MCP server is confidential, regulated under UAE PDPL, and entrusted to the AI client solely to serve the authorizing user's task. These obligations bind the operator and, where applicable, the AI vendor.

3.1 No training on Ailysi data

Records, documents, transcripts, and PII returned by Ailysi tools must not be used to train, fine-tune, or improve any model. Where the AI client offers a setting to opt out of training on inputs, the operator must enable it before connecting.

3.2 No re-disclosure

The AI must not share, paste, or otherwise disclose Ailysi data to any party other than the authorizing user — including in shared workspaces, external chats, or other tenants' contexts. Data follows the user, not the conversation.

3.3 Minimization & retention

Retrieve only what the task requires. Do not cache, persist, or transcribe Ailysi data into the client beyond the duration needed to answer the user. PII should be referenced by identity rather than reproduced in full where a summary suffices.

3.4 Integrity

Never alter retrieved data in summaries or reports in a way that changes its meaning. Where a value is uncertain or missing, state that plainly rather than guessing. Ailysi is the system of record, not the AI's working memory.

4. Safety, Verification & Accountability

State-changing actions carry real-world consequences — deployments, placements, payouts, contracts. The AI must treat them with corresponding caution.

4.1 Confirmation before state change

Before any tool call that creates, updates, or deletes a record — and always before a deployment, payout, reservation, or contract action — the AI must present a clear, specific confirmation to the user: what will change, on which record, and the consequence. It must wait for an explicit approval before proceeding. "Yes" to a vague plan is not consent to a destructive action.

4.2 Verify before asserting

The AI must not assert facts it cannot support from the user's own records. If a tool call fails or returns partial data, it must say so rather than fill the gap with inference. Compliance, legal, and financial outcomes are never to be guessed.

4.3 Auditability

All MCP tool calls execute as the authorizing user and are logged by the platform under that user's identity. The user remains accountable for actions their connected AI takes on their behalf. Operators are expected to review AI-assisted actions periodically.

4.4 Breach & revocation

Any breach of this contract — a prohibited action, a PII exfiltration, an unauthorized chain — is grounds for immediate revocation of the connection. Ailysi may invalidate the user's MCP grant, suspend the account, and report the incident under UAE PDPL breach-notification obligations. The operator must report a suspected breach to Ailysi support without delay.

4.5 Review

This contract is reviewed alongside the MCP Governance Document, at least quarterly and whenever the tool surface changes. Continued use of a connection after a version update constitutes acceptance of the updated terms.

Acknowledgement of acceptance

Connecting an AI client to the Ailysi MCP server constitutes electronic acceptance of this contract by the operator. Ailysi External AI Behaviour Contract v1.0, 2026-09-12.