Deciding what an AI may do is easier when the answer is already encoded in the product. Kadaikodi’s position is that guardrails are not an AI feature — they are the precondition for having one, and they were built first.
Every entry point into the marketplace API carries a permission directive that the gateway enforces before a resolver runs: fifty-one of them across reads and writes. The service itself never validates a token; authorisation is a property of the schema, which means an assistant, an external agent and a human browser are all governed by exactly one policy rather than three that drift apart. The self-scoped operations go further — a worker’s schedule and stats, a customer’s addresses, payment methods, loyalty balance and holdings take no identity argument at all, so there is no parameter for a confused or malicious agent to swap. You get your own data because that is the only data the query can return.
Every mutation the service executes is written to an audit trail with the calling actor, the workspace and sanitised arguments — secrets and credential-shaped keys stripped by pattern, depth capped, arrays and strings truncated — so the record of an agent-driven change survives without turning the log into a data-leak surface of its own.
Then there is the switch that makes Kadaikodi unusual. The investment marketplace, where people would put real money into real small businesses, is gated by a server-side feature flag that is deliberately fail-closed: if the flag row is missing or the flag service is unreachable, investing is off, not on. That is the opposite of the platform’s ordinary default-allow rollout behaviour, and it is intentional — the product’s own legal risk register requires the surface stay closed until securities counsel confirms a lawful structure. The app mirrors the same default so a user sees a calm “not open yet” notice instead of a raw error. No model, prompt or agent can talk its way past it.
Kadaikodi also publishes AI terms rather than leaving the question implicit: personal data, order content, messages and reviews are not used to train generally available models in a way that identifies anyone; AI outputs including valuations and “expected returns” carry no warranty and are explicitly not advice; and AI features must not be used for automated decisions with legal or similarly significant effects on individuals without independent human review and the notices the DPDP Act and GDPR Article 22 require. Transparency and labelling obligations, including EU AI Act ones, sit with whoever publishes AI-generated content.
What is still open is measurement rather than control: there is no evaluation set for common Kadaikodi queries, no CI gate that runs one before a prompt change, no per-workspace AI spend alert, and no agent-run ledger that ties a single prompt to the operations it produced. Notably, the AI usage quota for Kadaikodi has been left deliberately unseeded in billing rather than shipped as an unenforced number — the platform would rather have no quota than a fictional one.
Pre-launch: these are shipped controls in a product that has not opened publicly, described as controls — not as a compliance certification, which Kadaikodi does not claim.
Ready to make this your story?



