Skip to content
Trust & AI Safety

AI-managed. Human-controlled.

Connecting Claude, ChatGPT, or any AI agent to your directory doesn't mean handing over the keys. Here is exactly what an AI agent can do on Directories.ai — and the specific, fixed list of things it never can, no matter how it's asked.

What your AI agent can do

  • Create, edit, and publish listings, categories, articles, FAQs, and pages
  • Research and propose new businesses for your review queue
  • Review and approve listing claim requests you’ve received
  • Invite unclaimed listings to claim their profile
  • Run recurring work — content refreshes, listing audits, claim outreach — on a schedule you set
  • Import data from your own connected database
  • Propose a change to your site’s code as a pull request for you to review

What it can never do

  • Read your mail-provider keys, model API keys, or database credentials
  • Create or read your organization’s API key
  • Mint a new credential of any kind — even a narrowly-scoped one like a visitor-tracking key
  • Change your billing or subscription
  • Add, remove, or change access for team members
  • Change your custom domain or listing slugs (this breaks live URLs)
  • Push a change directly to your live site — every code change is a pull request, never a direct push

How this actually holds up, not just as a promise

Enforced where it can't be bypassed

The exclusions above aren't just missing menu items — several are enforced at the database layer itself, so they hold regardless of which tool, dashboard, or future integration touches your data.

Every write is logged

Every change an agent makes shows up on your Tasks page — what changed, when, and which task it was working on. Nothing an agent does happens silently.

Listing edits are undoable

When an agent updates a listing, the previous values are kept. If a change is wrong, you can see exactly what it was before and roll it back.

Code changes are pull requests, not pushes

If an agent proposes a change to your site's actual code, it arrives as a pull request on your repository. A person reviews and merges it — nothing reaches production on its own.

Scoped access, not shared access

Your organization's API key only ever reaches your own directories — never another organization's data. A tracking key for visitor analytics can only write events for the one directory it was issued for. Narrower-scoped credentials still can't be created by an AI agent on its own; that stays a decision you make in your dashboard.