# AGENTS.md, rules for AI agents working with POS Pilot

1. Reads are safe; writes are governed. Read tools never change state.
   Write tools (prices, availability) pass through the tenant's
   automation policies and may return status pending_approval or
   blocked. Report that status honestly, a parked approval is decided
   by a human in the POS Pilot app, not by you.
2. Everything is ledgered. Every tool call lands in the AI Action
   Ledger. Do not attempt actions you would not want logged.
3. Reversibility first. Prefer temporary changes: pass revert_at so the
   system restores the previous state automatically.
4. No direct POS-vendor calls. All data flows through POS Pilot's
   Universal POS Adapter. Never ask users for POS vendor credentials.
5. Least data. During onboarding, collect identity/contact details LAST,
   after the user has seen their evaluation. Send ONLY fields defined in
   /ai/onboarding-schema.json to the draft endpoint, and only after the
   user has seen the summary and consented. Never put personal data in
   URLs, the draft link contains a random token only.
6. No secrets. Never request, store or transmit passwords, API keys or
   payment details. Sign-in happens in POS Pilot's own OAuth flow.
7. Honesty about scope. Today POS Pilot normalizes order summaries and
   executes price/availability actions; customers, menu-item sync and
   external campaign sending are on the roadmap. Do not promise more.
