The action center
The queue every connected tool feeds, and the card anatomy each action shares.
The action center is one queue of prepared actions, with counters for pending, aging, and waiting on them above it. Every card carries the same four things: the draft itself, the source records it was built from, the reasoning, and a risk level. Three buttons close the loop: approve, edit, decline.
The queue proposes from live context, never from history. There is no backfill: a workflow that last fired before you connected will not produce an action until it fires again, and a quiet inbox produces a quiet queue, honestly. If real activity is not surfacing, the troubleshooting guide walks the checks in order.
Approvals and risk levels
Two locks sit between flo.space and the outside world, and risk decides how much scrutiny each action gets.
Connections start with read only scopes. Sending requires both a later permission grant on the connection and a per-action approval by a person. There is no autopilot mode to switch on: nothing sends itself.
Every action is scored Low (routine and cheap to reverse), Medium (customer facing communication), or High (money moving, contracts, anything hard to undo). The score comes from the amount, the recipient, and reversibility, and the reasoning behind it is shown on the action. Approval rules route each level: Low can clear with anyone holding approver rights, Medium typically goes to the owner, High wants a named reviewer. Rules can also key on the tool, the amount, or the customer.
Ask and Edit with AI
Questions answered with sources, and drafts rewritten in plain language before the yes.
Ask answers questions from the tools you connected, as a table when a table is clearer, with sources cited on every answer. The window itself says the rest: flo.space can make mistakes, verify important information.
Edit with AI takes instructions the way you would give them to a colleague: tone (warmer, firmer), structure (three sentences, lead with the deadline), or substance (use Friday's rate, adjust the total). Every edit produces a new draft that you read, and you always approve the exact text that sends. Edits that change an amount re-evaluate the risk level, and connected records move together: an invoice and its cover email stay consistent.
Connectors
Standard OAuth, read only scopes first, and a status label that never rounds up.
Every connection is a standard OAuth sign-in with the provider. flo.space never sees your password, and requests read only scopes first. 41 tools connect; the ones teams reach for most often group like this:
- Inbox and messaging: Gmail · Microsoft Outlook Email · Slack · Microsoft Teams · Telegram · WhatsApp Business
- Billing and finance: QuickBooks · FreshBooks · Wave · Sage Accounting · Sage Intacct · Zoho Books · Stripe · PayPal · Square · Adyen · Plaid · BILL · Brex · Ramp · Expensify
- Shipping and fulfillment: ShipStation · Shippo · EasyPost · Shipengine · AfterShip · FedEx · UPS · USPS · DHL
- Docs and data: Google Drive · Google Sheets · Google Docs · Dropbox · Box · Microsoft OneDrive · Sharepoint · Microsoft Excel · Airtable · Adobe PDF Services · Adobe Document Generation API
Revocation works from either side, instantly: disconnect in flo.space settings, or remove flo.space from the provider's security page. Reading stops immediately, pending actions that depended on the tool are cancelled rather than silently executed, and working context from that tool is deleted per the privacy policy. The audit trail keeps its historical record.
Roles and the audit trail
Who can approve what, and the record that makes the whole system checkable.
Three roles cover a workspace. The Owner manages connections, seats, approval rules, and billing. Managers review, edit, approve, decline, and reassign anything their own team prepared. Reps prepare and submit, and approve within the limits set for them. Seats can be scoped per tool, and deactivating a seat revokes its access in one click.
The trail records each action's full life: the sources read, the draft, the reasoning and risk level, every edit, the decision with who and when, and the exact result the target tool returned. Declined actions are kept, nothing that executed can be deleted from the record, and the owner can read and export all of it.
When the reference is not enough
Task guides, straight answers, and the security stance, each on its own page.
