Skip to main content

Money

What a UAE Spending App Taught Us About Advisory Only AI at Work

Building a card tool that recommends but never acts changed how we think about workplace agents, and what people actually trust software to do on their behalf.

Written by Sicherhaven

We built a UAE spending tool that reads a card statement and tells someone which card suits their actual spending. It will never move a dirham. That constraint was a product decision, and it turned out to teach us more about workplace AI than anything we set out to learn.

The short lesson: people trust software far more readily when it cannot act, and the trust they extend to a tool that only advises is qualitatively different from the trust they extend to one that does things. That difference matters when you are deciding what agents should be allowed to do inside a company.

The product constraint

Wealthwise reads a card statement on the user's own device and uploads nothing. It ranks 19 UAE cards from 8 banks against what the person actually spends on, and shows the annual cost of using the wrong card. It is advisory only: it never moves money and never places trades.

Every one of those choices narrows what the product can do. Together they also remove almost every reason to be nervous about using it. The mechanics of how that ranking runs against your own statement are worth reading on their own.

What people relax about

A tool that cannot act removes a specific fear, and it is not the fear you expect.

The obvious worry is financial loss. The one people actually voice is loss of control over a decision they consider theirs. Which card someone carries is tied up with how they see their own spending. An app that quietly switched things would feel like an intrusion even if the switch were correct. The same holds for how someone splits a salary when rent takes half of it, which is personal long before it is technical.

Advisory framing sidesteps that entirely. The software makes a case, the person decides. Being able to disagree with the recommendation and still find the tool useful is the thing that makes people willing to look at their own numbers honestly.

The same pattern at work

Carry that into a company and the shape holds.

Employees are rarely worried that an agent will be wrong in a dramatic way. They are worried that something will happen in their name that they did not choose. A message sent under their signature, a task reassigned, a record changed without them knowing.

That is why SicherOne is built so a human approves agent output before it ships. It is not only a safety control. It is the thing that makes people willing to let an agent near their work at all, because the agent is proposing rather than deciding.

Advisory is not automatically safe

The comfortable conclusion would be that advisory only means low risk. It does not.

Advice changes behaviour, which is the entire point. A ranking that puts one option first will move most people towards that option, and if the ranking is built on incomplete information the harm is real even though no button was pressed. One card can be the right answer for one household and the wrong one next door, which is the point of walking through three UAE households and the cards they ended up with. Reward rates, fees and eligibility differ by issuer and change over time, so a good advisory tool has to be explicit about what it does not know and tell people to check with their bank.

The workplace version is a summary that quietly frames a decision. Nobody approved anything, no action was taken, and the meeting still went a particular way because of how the agent phrased the options. Advisory output needs review for framing, not just for facts.

Trust follows the boundary, not the promise

The other thing that transferred cleanly: people trust a boundary they can see far more than an assurance they are given.

"It cannot move your money" is believable when the product has no such function. "It will not move your money without asking" requires the user to trust a setting, a policy and the company behind both. Same practical outcome, very different feeling.

Inside a company, that argues for hard limits over policies wherever you can afford them. If an agent has no ability to delete records, you never have to explain the safeguard that stops it deleting records.

Keeping data where it starts

Statement reading happening on the user's own device, with nothing uploaded, does the same work. It is a boundary rather than a commitment.

The workplace parallel is being able to self host private models, which SicherOne supports. For some organisations the difference between "your data is handled carefully elsewhere" and "your data never leaves" is the entire decision, and no amount of reassurance closes that gap.

What we changed in how we think

Three things stuck.

  • Decide what the software cannot do before deciding what it should do. The constraint list is easier to defend and easier to explain than a feature list.
  • Treat advice as an action with slower consequences. Review it for how it frames choices, not only for whether the facts are right.
  • Prefer visible boundaries to stated intentions. People believe what a system is incapable of. They audit what it merely promises.

None of that makes agents less useful. It makes the useful part easier to say yes to.

← All posts

We're building the future of community events and financial wellness

See how Eventify and WealthWise change the way people find events and manage money.

Get Started