Identity and voice
A name, an avatar, a job title, a persona and a communication style. The same employee shows up in email, in the workspace and in meetings.
Guide — — by Mahmoud Zalt
How an agency carries more delivery per team: client-scoped AI Employees, approval gates, a full activity record, and a white-label route.
Because what you sell is time, and time does not compound. Every new retainer forces the same choice: hire ahead of revenue and carry the risk, or tell a good client to wait and watch them go elsewhere. Demand is rarely the problem. The month is the problem.
And the hours that disappear are never the hours you charge most for. They go to the monthly report nobody reads closely, the deck rebuilt because the positioning changed, the fourth round of edits, the CRM a week behind. Margin per client leaks out through production work, not strategy.
Most AI tools stop at the answer, and everything expensive happens after the answer. Ask a chat window for a quarterly content plan and you get a plan. You still build the calendar, brief the writer, chase the draft, format the deliverable, load it into the client's CMS and send the summary. That gap is where the margin goes.
An AI workforce is a different shape of tool because it is built for the after. You hire an employee into a role, it owns work rather than answering questions, and it carries the request through research, execution, review and follow-up. The unglamorous middle of delivery stops consuming the people you hired for judgment.
You start the way you already staff an account: you pick a role. There is a marketplace to hire an individual from, or you can hire a complete team in one move. If the role you need is not in the catalog, the Employee Builder makes a custom one, shaped like your own service lines.
You can also interview a candidate before hiring it. You talk to it first, ask how it would handle a live account, see how it writes and what it asks for, then decide. That step earns its place when the hire is about to touch a client relationship.
That whole sequence, marketplace to team hire to custom build to interview, is how hiring works on Sistava. It sits deliberately closer to staffing an account than to configuring software, because agency owners already have sharp instincts about the first and very little patience for the second.
A name, an avatar, a job title, a persona and a communication style. The same employee shows up in email, in the workspace and in meetings.
Reasoning depth is a setting per employee. Routine production stays cheap and fast, while positioning work on a strategic account gets more thinking.
Talk to a candidate before you commit. You see how it handles an account scenario and decide after.
Active, paused, benched when a retainer ends, or kept as a former team member with its history intact. Churn does not mean deleting the record.
The unit that works for an agency is not one employee, it is a team with a shape. You hire a whole team and give it an AI leader. The leader delegates work to the members and reviews what comes back, so you brief one place instead of coordinating five.
That is the difference between a pile of assistants and a pod. A team carries OKRs and KPIs, goals, and written guidelines for how work on that account is done. You get an org chart of the workforce, and a 3D office view on desktop where each employee sits at a desk you can click and message in real time.
Work runs in sprints with a goal, a weekly rhythm, a review, and a written account of what got done. If you already run stand-ups and a monthly wrap, you are mapping rather than learning to a new system.
| How your agency already thinks | What it maps to |
|---|---|
| An account pod per client | A team hired together, scoped to that client's work |
| An account lead who briefs and reviews | An AI leader that delegates and checks the result |
| Quarterly goals and monthly targets | Team OKRs and KPIs, plus goals and guidelines |
| The weekly meeting and monthly wrap | Sprints with a goal, a review, a written account |
| The staffing plan on the whiteboard | An org chart, plus a 3D office view on desktop |
| A benched contractor between retainers | An employee paused or benched, history intact |
It does the delivery work, by discipline, in the shape you would brief a junior team. The catalog spans over 150 live capabilities across sixteen areas, so the service lines you sell have a role behind them.
Output arrives as real files, not text you paste into a template. Word documents, PowerPoint presentations, spreadsheets, PDFs, CSVs and images. There is a document editor and a presentation builder in the workspace, plus text extraction, so an employee can read the brief you uploaded.
It can edit an existing file rather than rebuilding it, so your formatting and the client's template survive the revision. That removes a category of work every agency knows: the version that came back correct in substance and wrong in every other way.
The review loop maps directly onto client revisions. You highlight the exact sentence in the document, or pin a comment to a specific part of an image. The employee receives the comment with its context and returns the next version, without you explaining which paragraph you meant.
All of that assumes one thing you have no reason to believe yet. An agency does not have one client, it has a room full of them, and some of them compete. Before any of this is usable, the boundary between accounts has to be real. For client services, that is the whole question.
No, and the reason matters more than the answer. Memory and knowledge follow the employee's role. If an employee may not access a resource, it cannot reach that information through memory, through knowledge search, or by being asked in a different conversation. What it writes back into memory is scoped the same way.
The backend enforces this. Security does not depend on asking a model to keep a secret, or on an instruction that a long conversation might drift away from. The boundary sits below the model, in the layer that decides what the employee can see at all.
Press on that distinction with any vendor you evaluate. An instruction saying "do not mention other clients" is a request. An access rule that never puts the other client's data in reach is a boundary. Change an employee's role and its access changes with it. If a vendor's answer is "the model has been told not to", walk away.
| Dimension | Traditional | With Sista |
|---|---|---|
| What stops a leak | Remembering which window you are in | The backend refuses access the role does not have |
| What it remembers | Whatever was in the last long thread | Memory is read and written inside the role scope |
| Asking another way | A new chat can surface what the old one had | Another conversation does not widen its reach |
| Moving work between accounts | Copying files, hoping nothing extra came along | Change the role, and access changes with it |
| Adding a freelancer or client user | A shared login, or an over-sharing folder | Separate workspaces and collaborator permissions |
The workspace side matters too. You can run multiple workspaces, and add collaborators with permissions rather than handing over the keys. A contractor on one account, a client stakeholder who sees only their deliverables, and your account lead who sees everything are three access levels, not three people sharing yours.
The work does not scatter into a dozen tools and a drive you tidy quarterly. There is a company Drive, a content workspace, a built-in CRM, mailboxes, a company calendar with meeting workflows, tasks, routines, projects, sprints and dashboards, in one place.
Global search runs across pages, employees, teams, tasks, projects, files, sprints and CRM contacts. When you cannot remember which account a deliverable belonged to, you search once instead of opening four tools. Your employee can also take you there, opening the exact page rather than describing it.
Retainer work is repeating work. Duties define what an employee owns, skills define what it can use, routines put recurring work on a schedule, and tasks and projects hold the one-off pieces. Working hours mean an account's cadence is respected, not fired at random.
Playbooks are the piece agencies care about most. A playbook is an exact procedure and standard: your onboarding sequence, your report structure, your QA checklist before anything reaches a client. It can be strict when the process is the product, or you can hand over the outcome and let the employee find the path.
Rules cover behaviour in specific situations, which is where account quirks live: this client approves in writing only, that one never gets a call before eleven. Each employee also keeps a work journal of what it did, decided and hit, which answers a client asking what happened last week.
Every employee gets its own email address and can send and receive independently, which is cleanest when a client should reach whoever handles their account directly. You can also connect Gmail or Outlook so it sends and replies from your real inbox under your name, when the relationship is yours.
Beyond email it works through web chat, Slack, Telegram and a personal mailbox, so a team living in Slack does not have to move. Meetings are direct: add a Zoom, Google Meet or Teams call to the calendar, pick which employee attends, and it joins, takes notes, can speak, and turns the conversation into follow-up work.
That sentence describes running an agency in general, which is why the control layer matters more here than almost anywhere else. Autonomy is only usable when you can prove what happened, hold the risky moves, and catch a bad output before a client sees it.
Human approval on selected actions: external email, publishing, spending money, deleting data, triggering a workflow, or anything over a threshold you set. Rules are written in plain language, so approval depends on the situation.
Define what a good deliverable must contain and must avoid. Output is checked before it reaches you, and a failed check goes back for revision. Your QA checklist runs every time.
Protect sensitive information, enforce policy, reduce prompt-injection risk, block information-boundary crossings, and prevent runaway actions. Where an answer would expose restricted information, it can refuse or ask approval for that one piece.
Dashboards, an activity timeline, work journals, cost tracking and an action inspector, plus a view of what your employee was actually told.
Daily or monthly spending limits, credit monitoring, and routing simple work to efficient models while reserving stronger ones for work that needs thinking.
It chases stalled work, resolves common blockers, retries where sensible, and escalates only when a human decision is genuinely needed.
Put those together and accountability becomes concrete. When a client asks what was done on their account in July, you have an activity record and work journals, not a recollection. When they ask who approved the outreach, you have the gate and the person who released it.
The sensible first move is one account, not the whole book. Pick the client whose delivery work is most repetitive and least strategic, hire a small pod, and run a month with approval gates on everything outbound. One real retainer teaches you more than any evaluation matrix.
Client work is defined by other people's software. You do not choose the CMS, the ad account, the analytics stack or the ancient portal one client insists on, so reach matters more for an agency than for most businesses.
Beyond connectors there is a REST API, MCP, A2A, and inbound and outbound webhooks. Add web search, website scraping, browser automation, computer control, screen vision, terminal commands, file organisation, data-entry automation, and meeting attendance with transcription.
The part that saves agencies most often is using apps through your existing authenticated session. With permission, an employee can operate the same browser and desktop applications you already use, so a client tool does not need a good API, or any API, to be reachable.
If you carry e-commerce accounts, one detail is worth knowing precisely. Shopify is the only guided store workflow, and every action that changes a connected store is approval-gated at runtime, enforced in the platform rather than left as a toggle. Reads run unattended. Other providers ask first on every action.
A system with this much surface would be a burden to configure by hand, which is why the personal assistant is the control layer rather than a novelty. It sets up the workspace, learns your company, hires and configures employees, creates projects and tasks, connects apps, establishes routines, finds files or contacts, and checks progress and spending.
It can also explain the platform itself when you are unsure what something does. For an agency owner with no appetite for another admin job, that is the difference between adopting this and buying it and never finishing setup.
It is also the honest answer to how an agency starts without running a setup project. You describe the account and the service lines in plain English, and the assistant does the hiring, the scoping and the wiring. Sistava treats that as the front door rather than an optional extra, so the configuration work does not land back on the person in the building who has the least time for it.
There is a third option between building your own AI product and reselling someone else's. Two shapes exist, and both suit an agency that wants to own the client relationship rather than introduce a vendor into it.
The first is a managed white-label service: your customers see your brand, and the infrastructure and AI engine run behind it. You sell the offering and hold the relationship. The second is a one-time source-code licence with hands-on training, after which you run it on your own infrastructure and it is yours to shape.
Which fits depends on whether you want a product line or an owned asset. An agency testing whether clients will pay usually starts managed. An agency with an engineering function usually wants the licence.
Worth saying plainly: this is a business decision, not a technical one. Before white-labelling anything, run it on your own delivery for a quarter. If it does not change how much work your team carries, packaging it for clients will not fix that.
If what your clients buy is senior judgment and the relationship, none of this touches that. A client stays because a specific person understands their market, reads the room in a difficult meeting, and says the uncomfortable thing at the right moment. Any vendor telling you otherwise is selling you something.
What changes is how much delivery one team can carry, and how much of the production and reporting work has to be done by someone who could be doing strategy instead. The senior person still sets direction, still reviews, still owns the client. They spend fewer hours rebuilding a deck on the way there.
Yes, and it is enforced rather than promised. Memory and knowledge follow the employee's role, so an employee scoped to one client cannot reach another client's information through memory, through knowledge search, or by being asked in a separate conversation. What it writes back to memory is scoped the same way, and the backend enforces that, not a model asked to keep a secret.
Approval gates. You can require human approval before selected actions, including external email, publishing, spending money, deleting data, triggering a workflow or sharing confidential information. Rules can be written in plain language, so approval depends on the situation rather than a single switch. Output evaluations add a second layer, checking the deliverable against what it must contain and avoid.
Yes, in two shapes. A managed white-label service means your customers see your brand while the infrastructure and AI engine run behind it, and you hold the client relationship. A one-time source-code licence with hands-on training means you run the platform on your own infrastructure afterwards. Which fits depends on whether you want a product line or an owned asset.
No. If your value is senior judgment and the client relationship, that is not what changes. What changes is how much delivery your existing team can carry, and how much production, formatting and reporting work comes out of hours that could go to strategy. The senior person still sets direction and owns the account.
Through separate workspaces and collaborator permissions. A contractor on one account, a client stakeholder who sees only their own deliverables, and your account lead who sees everything are three access levels rather than three people sharing one login. Employee access is governed by role at the same time, so both sides are bounded.
Real files. Word documents, PowerPoint presentations, spreadsheets, PDFs, CSVs and images, with a document editor and a presentation builder in the workspace. It can edit an existing file rather than rebuilding it, so your template and the client's formatting survive a revision. Text extraction means it can read the brief you upload.
You mark up the deliverable in place. Highlight the exact sentence in the document, or pin a comment to a specific part of an image, and the employee receives that comment with its context. The next version comes back without you explaining which paragraph you meant, and untouched sections stay untouched.
Dashboards, an activity timeline, per-employee work journals, cost tracking and an action inspector. There is also a view of what the employee was actually told, showing the real context it received before it acted. Sprints add a written account of each cycle, usually the fastest source for a client summary.
A chatbot produces an answer and hands the rest back to you. A workforce moves a request through research, planning, execution, communication, review, storage, measurement and follow-up, which is the actual shape of client delivery. The part you were handed back is precisely the part your margin was leaking through.
That gap is why Sistava is built around employees and teams instead of a better chat window. The work an agency loses money on is never the answer itself, it is the twelve steps after the answer, and those steps only get carried by something that owns the outcome rather than the reply.
So the question is not whether AI writes faster. It is how many accounts your team could carry if the production and reporting layer stopped eating their week, and whether you answer that with a hire made ahead of revenue or with capacity bounded by role, gated on anything consequential, and recorded well enough to explain. Start with one retainer and let the first month answer it.