This is the honest list. Not a list of things we have promised not to do, or things we have turned off for now — a list of things an agent has no way of doing at all. The difference matters, and the last section explains why.
It will never file a return
No agent files GST or TDS. Not with your confirmation, not at three in the morning on the deadline, not ever.
Filing is unlike everything else Finocket does, in three ways at once. It cannot be undone — a filed return is filed, and the fix is another filing, not a correction. A wrong figure carries a penalty, in money, to you. And it is made in your name, to the government, as your statement about your own business.
So an agent may do the work up to that line and no further. It can pull the figures, reconcile them, tell you what does not agree, tell you what changed since last month and have the return ready and waiting. You press file. That last press is the whole point of the arrangement, and handing it to software would be handing over the part that is actually yours.
It will never message your customer
Nothing an agent produces reaches a customer, a supplier or anybody else outside your team on its own — no email, no WhatsApp, no SMS, no reminder that just goes.
An agent can find every invoice that is overdue, draft what you would say, and put it in front of you. Sending is a separate act by a person, and any message that goes out afterwards runs through the same consent and quiet-hours rules as everything else you send. See Outreach & consent.
The reason is simple: a message to a customer is your relationship with that customer. A wrong one cannot be recalled, and you would find out about it from them.
It will never move money
No agent pays a bill, releases a payment, refunds anything, changes your bank details or touches a payment method. It can tell you a bill is due on Thursday. It cannot pay it on Thursday.
Finocket does not execute payments on your behalf anywhere in the product, so there is nothing here for an agent to be given access to in the first place.
It will never create another agent
An agent cannot make a second agent, cannot widen its own permissions, cannot raise its own budget and cannot switch on a part of Finocket you have left off. Every agent that exists was created by a person in your workspace, and the list on Automations is the complete list. It does not grow while you are not looking.
It cannot reach past what you ticked
An agent sees the parts of your books that survive every one of these at once:
- What an agent of this type may ever reach. Fixed by us, in code that is reviewed. A stock-watching agent has no route to your payroll, and never had one.
- What you ticked when you set it up.
- Which parts of Finocket your workspace has switched on — see Modules. An agent cannot reach a module you do not use.
- Whether that particular kind of action may be taken alone at all, or has to come to you first. Anything not explicitly allowed to act alone comes to you.
These narrow; they never widen. This is the part people misread, so it is worth saying plainly: ticking a permission that this type of agent is not allowed to have grants it nothing. The tick is real, the permission is not. The first list wins, every time, and the agent's screen shows you what it can actually reach rather than what was ticked.
It works the same way as your team's permissions: a role that is not admitted by every layer is inert, however it looks on the form.
Why these are structural, not promises
A promise is only as good as the next release. What is written above is not a promise; it is a description of what is missing.
The part of Finocket that runs your automations has no way to send a message — no connection to email, WhatsApp or SMS exists in it, so there is nothing to misuse, mis-set or accidentally leave switched on. It has no route to filing and none to payment. It cannot create an agent because it cannot write to that part of the database at all. When a run finishes, it writes down what it found and stops; anything that reaches you afterwards is delivered by a different part of the app, through your own notification settings.
We test for the absence, not for good behaviour. The checks that run before any release walk the whole of the automation machinery and fail if a route to sending, filing or paying has appeared anywhere in it — so this article cannot quietly stop being true while still saying it is.
Everything an agent does do is on the record: what ran, when, what it concluded and what it cost, in Activity. And you can stop any of it at any moment, which takes effect straight away.
Related: What an agent is, Approvals & automation, Team & roles.
