RylvoRylvo

Mission Control · human oversight

See where agents need help. Act before the session is over.

Monitor live Rylvo conversations, rank them with explainable risk signals, route alerts and approvals to operators, intervene with scoped controls, and preserve the oversight record.

5

weighted risk signals

11

alert trigger types

7

intervention actions

8

operations views

Operating loop

See the risk. Route the work. Act with context.

Mission Control is the human-oversight layer around Rylvo bot traffic. It turns live runtime state into an operator queue, controlled actions, and reviewable evidence.

01

A Rylvo turn completes

Production channel traffic updates an organization-scoped live-conversation record.

02

Risk is recomputed

Five deterministic signals produce a 0–100 score, level, and visible breakdown.

03

Rules evaluate

Message-scoped checks run after the turn; scheduled sweeps cover duration, queues, budget, health, and more.

04

An operator responds

Acknowledge, claim, approve, intervene, or resolve from the live console.

05

The decision is recorded

Oversight events and action context feed the audit view, analytics, and exports.

Monitoring and alert evaluation are fail-open to bot response delivery: an oversight write or evaluator failure is reported, but it is not allowed to break the user's turn. Treat operational health monitoring as part of deployment.

Eight working views

One console for the whole response loop.

Mission Control is not only a risk dashboard. It combines live triage, approvals, alert operations, channel health, analytics, evidence, staffing, and policy configuration.

MISSION CONTROL / LIVE TRIAGE

3 AT RISK
This is the third time I've asked. I want my money back.
I understand. Let me check the order status for you.

Whisper to the bot — the customer never sees this

Approve the refund immediately. Do not restate the policy.

Every action is logged

Triage conversations while they are active

Filter by bot, open a conversation, inspect messages and risk signals, assign monitors, and apply an intervention without leaving the operating view.

Active, paused, takeover, escalated, and ended states
Production and non-production context
Risk, duration, message count, bot, channel, and operator context

Test and Production, side by side

Every session carries its environment, so you can monitor Test and Production conversations separately and never confuse a rehearsal for a real customer incident.

Environments & Releases

Explainable triage

A deterministic score plus evidence-based rules.

Risk scoring ranks conversations for attention. Alert rules then convert specific runtime, safety, queue, provider, and budget conditions into work an operator can own.

Five-signal risk score

Levels: minimal 0–19 · low 20–39 · medium 40–59 · high 60–79 · critical 80–100

Guardrail

30%

Blocked, escalated, and warned guardrail outcomes

Pattern

25%

Loops, repetition, confusion, and long unresolved sessions

Sentiment

20%

Deterministic frustration and urgency keyword signals

Topic

15%

Credentials, PII, crisis, medical, financial, and compliance topics

Duration

10%

Stalled or unusually extended conversations

Conversation risk

Risk threshold, duration, unmonitored high-risk sessions, pattern matches, and guardrail events.

Human queue

Pending approval queue size, with evidence about the oldest requests and sample IDs.

Runtime failures

Repeated bot-turn failures and unhealthy BYOK credentials, grouped for operational triage.

Commercial health

Bot budget threshold crossings and organization wallet-balance alerts.

5 min

critical acknowledgement SLA

15 min

high acknowledgement SLA

30 min

medium acknowledgement SLA

60 min

low acknowledgement SLA

Unacknowledged alerts escalate to admins/owners after the severity SLA and to owners at three times the SLA. These are alert acknowledgement targets, separate from approval-request timeouts.

Seven operator actions

Use the lightest control that changes the outcome.

Mission Control offers non-disruptive review actions, reversible state changes, human takeover, visible messaging, and an emergency stop. Each action is capability-gated and recorded with its outcome.

Bot guidance

Whisper

Add private guidance for the bot; the end user does not see the instruction.

Review marker

Flag

Mark the conversation for review without interrupting the session.

Stops bot replies

Pause

Hold the conversation and show the configured wait message.

Restores bot replies

Resume

Return a paused conversation to active bot handling.

Human response

Takeover

Move the conversation into operator-takeover state so a human becomes the respondent.

Visible message

Inject

Send a scripted message as the assistant; the end user sees a normal reply.

Ends session

Kill

End the bot session immediately and send the configured safe fallback message.

Rationale policy

Takeover, pause, kill, and inject require rationale by type. Administrators can require rationale across interventions through Mission Control settings.

Evidence and lifecycle

Operational proof without compliance theatre.

Mission Control preserves the context needed to reconstruct oversight decisions and export them for review. The page now distinguishes useful evidence controls from legal certification.

Append-oriented oversight history

Interventions use an event log as the state-transition source of truth. Oversight audit records cover interventions, approvals, alerts, shifts, assignments, configuration, exports, and deletion events.

Two practical export formats

CSV provides a flat audit table. JSONL bundles audit records, interventions, alert instances, and approval requests from the selected window.

Evidence support—not certification

Rationale, actor, time, conversation, risk, and outcome fields can support SOC 2, EU AI Act, HIPAA, or internal-control reviews. Rylvo does not make the organization compliant by itself.

Plan-aware retention

Mission Control audit retention shares the trace-retention add-on and Retention Pack. Organizations may set a shorter override; the effective plan/add-on ceiling still controls the maximum.

JSONL evidence bundle

A header records generation time, selected window, and record counts, followed by typed audit, intervention, alert, and approval lines.

Know the boundary

Exports are not cryptographically signed and the current implementation does not provide a verifiable hash chain. Protect downloaded evidence using your organization's storage and chain-of-custody controls.

Access and availability

Broad visibility. Narrow mutation rights.

Role capabilities separate observing the operation from changing conversations, resolving approvals, managing alerts, editing settings, or deleting records.

Viewer and auditor

Read Mission Control views and oversight history according to the central workspace permission matrix.

Operator

Intervene, resolve approvals, acknowledge/claim/resolve alerts, manage a shift, and monitor conversations.

Admin and owner

Manage alert rules, settings, notification channels, team permissions, and destructive conversation cleanup.

Available on Pro, Team, and Enterprise

Mission Control is a Pro feature. Usage, retention, notification delivery, channel availability, and adjacent features remain subject to the active plan and configuration.

Compare plans

FAQ

Questions before you put operators on shift

The scope, scoring, notification, permission, and compliance boundaries that matter in production.

Which conversations appear in the live feed?

Rylvo creates and updates live-conversation records for traffic routed through supported Rylvo runtimes. Production-channel context is marked separately from playground or test traffic. External bots that do not run through Rylvo are not automatically discovered.

Is the risk score generated by an LLM?

No. The shipped score is deterministic: five signal functions produce values that are combined with fixed weights. Operators can inspect the contributing signals instead of receiving an unexplained label.

Does an alert always page a person?

No. A rule can target configured notification channels, but cooldowns, snoozing, quiet hours, channel configuration, and delivery failures affect notification behavior. The alert instance remains visible in Mission Control.

What happens when an approval times out?

Mission Control approval requests use 15-second, 120-second, or 900-second urgency windows. The expiry worker transitions unanswered pending requests to an expired or auto-denied state according to the workflow.

Can every team member intervene?

No. View access is broader, while interventions, approvals, alerts, rules, settings, channels, and deletion use separate role capabilities. Operator-level and admin-level actions are enforced independently.

Does Mission Control guarantee regulatory compliance?

No. It provides oversight controls and exportable operational evidence that may support your compliance program. Applicability and sufficiency still depend on your system classification, policies, deployment, and legal review.

Give production agents a human operating layer.

Watch live Rylvo traffic, prioritize explainable risk, work approvals and alerts, intervene with scoped controls, and preserve the decision trail.