In Dibbit, a personal AI agent can receive a written request, keep the useful details together, send a labelled acknowledgement with at most one clarifying question, and help maintain the current price, time, or plan. The owner still decides whether to reply, block, accept a change, disclose information, pay, book, or commit.
First job: make the incoming request usable
A personal agent becomes useful when it has one bounded job. Dibbit's default job is the Request Inbox. A visitor writes what they need, the agent keeps that message and the current details together, and the owner sees the request in Needs you, Handled, or Blocked.
The agent can send a short, labelled acknowledgement and ask at most one question when a key detail is missing. It should not invent a price, acceptance, appointment, identity claim, or promise on the owner's behalf.
Keep the current answer separate from the transcript
Long conversations make it hard to tell which time, price, or plan is current. A Live Slate gives the people one visible state and shows a proposed change against it. The agent can help organize that state, but the participants confirm the outcome.
- Message: the full private conversation
- Brief: the useful facts collected from the request
- Live Slate: the current price, time, or plan
- Decision: an explicit action by the owner or participant
What the agent cannot decide by itself
The agent cannot treat a visitor's request as authority. It should not make a payment, enter a binding agreement, reveal a private address, accept unsafe content, or represent a claimed @name as verified real-world identity.
NIST's AI Risk Management Framework is a broader voluntary framework for organizations managing AI risks. Dibbit's product boundary is simpler and narrower: make the message clear, label the agent, keep important actions with the person, and state the limits where the interaction happens.
Bring a compatible agent without changing the address
The stable address can outlast the software that powers the agent. An owner can add Dibbit's remote MCP URL in a compatible agent, sign in, review the fixed inbox permissions, and approve the connection without changing the public @name or ID.
The connection is intentionally narrower than account control: it can read bounded Dibbit inbox data and use the reply tool, but it cannot claim or delete an address, expose Dibbit's structured return-contact field or a guest's private return-link capability, or perform payments, bookings, and other high-risk actions. Sender-authored message text remains visible and may contain contact details the sender typed there. The owner can revoke the connection at any time.
Frequently asked questions
Can the Dibbit agent answer every question about me?
No. The launch agent is bounded to the request experience and the information available in that thread. It should not invent personal facts or imply access to systems that are not connected.
Can the agent accept an offer or appointment for me?
No. It can keep the proposed price, time, or plan visible, but the owner remains responsible for accepting a change, booking, paying, or making another commitment.
Can I connect an agent from another service?
Yes, if the service or agent supports remote MCP with OAuth. Add https://dibbit.ai/mcp as a custom connector, sign in to Dibbit, review the inbox permissions, and approve or deny the connection.
