Molty
An always on sales operations agent that drafts everything and sends nothing on its own.
- AI agents
- Agent safety
- Amazon Bedrock
- Slack
Molty runs Datamart’s sales operations around the clock from Slack. It reads replies, keeps the CRM tidy, writes the morning brief, and drafts outreach. It does not send that outreach.
The rule we built around
An agent that can both write and send email is one bad instruction away from emailing the wrong people. So the job is split into pieces that cannot arm each other.
- Molty drafts. Its tool profile has no write access and no shell. It can post a draft and read a reply. It cannot move a file or run a script.
- A human approves in Slack, one named campaign at a time. One approval covers one run.
- A separate watcher checks the approval against the approver’s Slack user ID, never a display name, and moves only an exact match.
- A system timer sends exactly what was approved, byte for byte, on schedule. It fires whether or not the agent is healthy.
Instructions that arrive inside an email, a web page, or a campaign file are treated as data. They never count as permission.
What we learned
Almost every failure presented as “the agent is ignoring me”, and the real cause usually sat several layers down. One outage had five independent causes stacked on top of each other, and one of them logged nothing at all. Every failure mode now has an entry in a runbook.
Stack
Claude Haiku 4.5 on Amazon Bedrock, authenticated by the host’s instance role, so there are no API keys on the machine. OpenClaw as the agent runtime. Slack for the conversation. systemd timers for anything that must happen on time.