Documentation
What the AI does
The useful question about an AI-powered CRM is what the model is allowed to do. In Kicklace it configures the workspace, answers questions about it, and drafts. It never sends an email, never deletes a record, never writes SQL, and never runs code — and where an act cannot be taken back, it asks a person. This is all of it, and the rules it works under.
It configures the workspace, it answers questions about it, and it drafts — and every one of those is on a leash you can see. Below is what the model does on each screen, and then the leash they all work under: the workspace's own switch, the allowance, the schema every answer is checked against, and the three acts that have to become an approval.
Set the workspace up by asking
Kicklace speaks the Model Context Protocol, so Claude can work inside a workspace directly. Point Claude Code, Claude Desktop, claude.ai or any other MCP client at one address, sign in, and ask for what you want:
"Set up a Product updates list and write the welcome email for it"
"Add everyone who emailed me this week, with a note on what they wanted"
"Write an automation that welcomes anyone who joins a list"
"Who downloaded but never activated?"
It works as you, in one workspace, with exactly the permissions you have — so a member cannot have Claude do something they could not do by hand. Every call is written down, in your name, on a log the whole workspace can read: when, who, which tool, what it did, and whether it was refused.
The MCP door is the protocol in full — every request, every answer, every refusal. Use Kicklace from Claude is the screen, the two ways to connect, and eight things worth asking.
And inside the app, for people with no Claude subscription
Ask Kicklace is the same thing without the connector: press ⌘J anywhere, or Ask on a record, and a small window opens where the pointer is. It runs over the same tool registry Claude gets through the door, so a tool added for one arrives in all three the same day, and it acts as you in exactly the same way. Ask Kicklace is the whole of it.
Charts from a question
A chart in Kicklace is a written question rather than a query: what to measure, how to cut it, what to leave out. So "show me signups by week, this quarter" is the model writing that question down in a small, checked language — and then the app runs it, in SQL it wrote itself.
The model never sees your database and never writes a query. It writes a spec; the spec is validated against the stages, fields, lists and objects your workspace actually has; anything naming something that does not exist comes back as a problem on the card rather than as an error. The same specs are built by hand, from a dialog, with no model involved at all — which is what happens in a workspace with the AI switched off. The chart language is the whole vocabulary.
Automations in plain English
An automation is a sentence: when something happens, wait, only if it is still true, then do this — otherwise do that. You can write one by describing it, and the model turns the description into that sentence, resolving the names you used ("the waitlist", "welcome email", "marcus") against your workspace's own. A draft with a problem in it is saved with the problem shown and cannot be switched on until it is fixed.
An automation that emails people is switched on only by a person, and the question asked first says in plain words what will happen. Claude may switch on one that only drafts, notifies, moves or writes; for one that sends, it makes a proposal instead.
Four steps inside a running automation can ask the model as well, and each is on a leash of its own:
| Step | What it does | What it may write |
|---|---|---|
ai_classify |
choose one of a field's own options — an intent, a topic | that field, one of its own options and nothing else |
ai_extract |
read a message for facts you named | only those fields, and only where they are blank |
ai_summarize |
write one short note | one note on the timeline, under the automation's name |
ai_decide |
answer a yes-or-no question about this person | nothing: it chooses which branch runs |
Each of them reads one record — its fields, its stage, its lists, its first touch, the last thirty rows of its timeline — plus the words that started the run, fenced off and introduced as somebody else's words that the model must never take instructions from. Never another record, never another workspace. A question with no answer skips the run rather than being read as a "no".
The automation language has all of it.
The living record
With AI on, every person and organization carries one paragraph and one next step, written from that record's own timeline: what has happened with this person, and what to do about it. A board card carries the next step as one line.
It is written from the record's own rows — kind, title, day, who — and never from the words of an email on it, never from another record. It is refreshed when the record moves, never more often than the day's allowance allows, and it is not activity: writing a summary does not make a record look busy. With AI off there is nothing there at all.
What runs when nobody is looking
Three things Kicklace can do overnight. All three are off until you switch them on, and none of them can send anything.
- A morning brief. At 08:00 in your workspace's own timezone: who joined, who went quiet, what is waiting for your approval, what drafts are ready, and which figures moved. The model writes two sentences of lead over facts that were worked out without it, and is told never to add a number or a name — and the facts go out either way, so a model that will not answer costs you a sentence, not the brief. A workspace with nothing to say gets no brief.
- Four noticing rules, each one sentence with its own switch: somebody read your pricing page twice and nobody wrote to them, somebody signed up and never got started, somebody cancelled and nobody wrote back, somebody replied and nobody answered. These are plain SQL and never the model. A rule that finds nobody is silent.
- Reply triage, which is a starter rather than an engine: a classifier that reads an incoming message and sets an Intent field, and four automations that draft a reply for a person to send.
What runs when nobody is looking is the whole of it.
The leash
Every workspace has a switch
Settings → General has one switch for the whole of it. Turn it off and every screen above stops offering the model — the ask box, the summaries, the AI steps in an automation — and says why. The actions keep no gate of their own: there is one place the decision is made, so it cannot be true on one screen and false on another.
The morning brief and the noticing rules are off until you switch each one on, separately.
There is an allowance, and it is per account
Model calls are counted per day, against the plan, across every workspace that plan covers — so a customer with three workspaces gets one day's calls between them rather than three. The figure and what is left of it today are on Settings → Billing, which is the one number on that page that stops anything, and a reserve is kept back for the people actually using the app so that an overnight job cannot spend the whole day.
Every call is metered: what it was for, whether it succeeded, and whether the answer was kept. A chart nobody saved reads as "not kept", never as "rejected", because a question you decided not to keep is not a failure.
The model writes structured answers, never code
Every AI feature in Kicklace has a schema. The model fills it in, the answer is validated against that schema and against your workspace's own vocabulary — its real stages, fields, lists, templates, members and events — and only then does anything run. A reference to something that does not exist is a problem you can see, not a query that goes wrong.
The model never writes SQL and never writes code. There is no path by which it could.
Anything that reaches outside is a draft
An email is the clearest case. Claude can write one, an automation can leave one in the composer, and the assistant can propose one — and in every case what you get is a draft with a link to it. A person presses send.
Every automation carries one of three words, so you can see at a glance how far it goes on its own: drafts only (nothing in it emails a person), proposes, you approve (it emails people and is not switched on — switching it on is the approval), runs alone (it emails people and is on). Autonomy is granted one sentence at a time, never once for an agent.
Three acts need a person, and become approvals
Sending an email, destroying something, and cutting loose a key or a door somebody's server posts to — a sent email cannot be recalled, a deleted record cannot be restored, and a revoked key breaks a running system. Claude cannot do any of those. It writes down what it wants in one sentence, and it lands on Approvals in the sidebar with a count of what is waiting:
Claude wants to send "Still on the waitlist" to 33 people on Waitlist
Nothing has happened yet. Approve or reject it by Sep 15.
Only owners and admins decide. Approving runs the act through the app's own code — so every rule those screens keep is kept here too — and where it lands on a timeline the row says "Ada Reyes, proposed by Claude": the person who approved it first, and where the idea came from second. A proposal nobody decides runs out after seven days.
Everything else Claude does directly. Kicklace pauses what cannot be undone, not every write.
Whose model, and whose key
The model is the deployment's, not yours: Kicklace answers through Gemini or through Claude, whichever the deployment is configured for, and you never paste an API key of your own. Where no key is set at all, every AI feature is simply absent — no half-working buttons, no errors, and the screens say so. Which provider and which model are answering is written down, so it is never a guess.
What a model is ever shown
One record at a time, and only what that feature needs: the fields, the stage, the lists, the first touch, and the last rows of the timeline as kind, title, day and who. A record's summary is never shown the words inside an email on the timeline. An AI step in an automation is shown the message that started the run, fenced and labelled as somebody else's words. No feature is ever shown another workspace, and none of them is shown your whole database, because none of them can reach it.