Docs / Merchant guide
WallaB concierge & guardrails
Configuring the AI cancel-save concierge: allowed actions, discount caps, moderation, and auditability.
WallaB is the AI cancel-save concierge: when a shopper heads for the cancel button, WallaB starts a real conversation, diagnoses the reason, and proposes a save offer — strictly inside limits you set.
Guardrails you configure
Everything lives in Settings → WallaB concierge:
- Enabled — the master switch (off by default; with it off, WallaB makes no offers and simply confirms cancellations kindly).
- Allowed actions — which offer types WallaB may propose: a discount, a pause, a product swap, or skipping the next delivery.
- Maximum discount — a hard percentage cap (default 15%). WallaB can never offer more.
- Maximum pause — 1–12 whole months (default 3).
- Swap products — optionally restrict swaps to a specific product list; left empty, any active product in your catalog is eligible.
- Tone — free-text guidance (up to 500 characters), e.g. "Warm and casual — we're a small family roastery."
- One-off add-on limits — an optional price cap and product allow-list for "add to your next delivery" add-ons. A one-off (or a reordered past item) is added to the subscriber's next order and billed with it — never charged on its own — and only on pay-as-you-go subscriptions; a built-in per-day velocity limit stops add-ons from stacking up.
The server is the enforcer, not the model
The AI only ever proposes an offer. Before anything reaches a shopper, the server independently validates it against your guardrails — an out-of-policy proposal is dropped, and the reply stands without it. The model is never trusted to enforce its own limits.
Discounts follow a replace, never stack rule: a new concierge discount replaces the active one, so WallaB will only propose a discount that is strictly better than what the subscription already has — and once a subscription is at your cap, no further discount offers are valid. An accepted concierge discount does not expire: it applies to every order from then on, until you change it or a later save offer replaces it.
Moderation, both directions
Every message is screened by a moderation filter in both directions — what the shopper sends before the AI ever sees it, and what WallaB writes before the shopper ever sees it. Screening covers all five portal languages (English, Spanish, French, German, Brazilian Portuguese) at once. Flagged shopper messages get a calm de-escalation reply instead of an AI turn, and after repeated flags the plain cancel confirmation is surfaced directly so nobody is ever trapped in a conversation.
Reliability without an AI key
WallaB runs on a three-tier brain: the live AI model when configured, a library of your own proven past saves as the second tier, and a deterministic fallback that always answers. The cancel-save flow — and every guardrail — works even with no AI provider connected.
Everything is auditable
Every conversation is stored with its full transcript, and every AI decision (replies, proposed offers, dropped offers, moderation events) is logged. You can review exactly what was said and offered in your dashboard's Conversations and Activity views.
No dark patterns
A plain "just cancel" path stays visible throughout the entire conversation — no countdown timers, no guilt copy, no pre-checked add-ons. That's a product rule, not a setting.