Drafts, updates and actions inside the tools you already use, under three named levels of autonomy — and a stop before anything reaches another person.
Most memory products answer well and leave you to do the work: copy the draft, open the mail client, fix the recipient, hunt for the file, attach it, send it. The execution layer is the part that closes that gap, and the rules around it are visible before anything runs.
Press Option, and it writes at your caret
Inline composition reads the field around your cursor and the memory behind it, then writes the continuation straight into the app you are already typing in. It is a device-local write: nothing is sent, and you send it yourself.
Three levels, and the line does not move
Level one is reversible and local, and just runs. Level two is drafted and waits for you. Level three is anything that reaches another person — sending mail, posting a message, putting an event on someone’s calendar — and it always stops for approval. No prompt moves an action between levels.
Your plan or your key
Execution runs on the assistant subscription you already pay for, inside that plan’s limits, or on an API key you bring. You pick the provider and can switch without losing a day of memory. Keys live in the system keychain and nowhere else.
A record of what it did
Every action leaves what ran, on what evidence, and what left the device — marked when it passed through a third party. That log is what makes level one acceptable: automation you can audit afterwards is a different proposition from automation you have to trust in advance.
From context to a useful next step
Most memory products answer well and leave you to do the work: copy the draft, open the mail client, fix the recipient, hunt for the file, attach it, send it. The execution layer is the part that closes that gap, and the rules around it are visible before anything runs.
Understand
The request is read against the state of your work — who is involved, what was decided, what is still open — rather than the thread alone.
Prepare
The draft, update or tool action is assembled with the right file already attached and the open question already answered.
Approve
Anything consequential waits on one approval. Reversible work has already finished by the time you look.
What this changes
Spend less time rebuilding context
Send the follow-up with the right version attached
Walk into the 3pm already prepped
Close the loop you forgot was open
Keep the send button in your hands
Frequently asked questions
Clear answers before you start
Can it send something without asking?
No. Anything that reaches another person is level three and stops for approval. That is a property of how actions are routed, not a setting you have to get right.
Does driving it over the API skip the gate?
No. The same classifier and the same gates apply over MCP, CLI and REST. An agent calling in has no more authority than your own click.
Do I need an API key?
No. It can run on the assistant plan you already pay for. Bringing your own key is the alternative, not the requirement.
Which plan includes it?
Pro, along with the Memory API and the second-layer connections. Standard covers capture, recall and everyday execution.
Explore all Features
See how ShogunAI connects private memory, recall, and execution.