Understand the boundary, not just the button.
How to read the homepage’s interactive examples—and what still needs verification in a real deployment.
Approval belongs to the exact action
The approval example binds a decision to the sample report, recipient, total, and revision. Changing the recipient invalidates the earlier approval; executing the matching example consumes it. In a deployed workflow, check the actual payload, approver identity and role, expiry, policy version, and designated executor. An agent’s recommendation is not the reviewer’s authorization.
The agent example separates work allowed by a saved rule from an action held for a designated reviewer. Accounts payable and lead sourcing use fictional records, not integrations with Finance or Sales. Real roles and automatic rules must be configured and enforced by the execution service.
What a signed receipt proves
The receipt example uses real Ed25519 signatures and hash-linked records. It creates a temporary browser key when you start it. Verification checks those records against that key; changing a signed field breaks verification. The key is not a trusted RailCall production identity.
A signature does not prove factual correctness, successful execution, an uncompromised key, or hardware-backed signing. A valid remaining chain cannot alone detect deletion from its end. Complete-history claims require an independently trusted latest checkpoint and record count. For production verification, obtain a trusted signer key independently and verify an exported receipt bundle.
Local, team, and external are different permissions
The network example illustrates three boundaries: work on this computer, sharing with a permitted team computer, and an exact external transfer. Stopping the example cancels its pending transfer; resuming does not silently restore it. No network rule is changed by these buttons.
Real network-wide blocking requires coverage of every permitted route, including direct connectors and computer-to-computer traffic. A Station policy is not automatically an operating-system firewall. Stop controls have a defined enforcement scope and cannot undo completed sends or payments. Local-only reasoning is not the same as fully offline execution.
Saved steps are reusable; new reasoning is still work
RailCall does not charge a per-run execution fee for workflows running locally. Hardware, electricity, paid integrations, and fresh model calls can still cost money. Hosted execution and model usage follow the applicable pricing. Offline workflows need all required models, files, tools, credentials, and licenses available locally.
Read the published policies
See privacy and data boundaries, security practices, the threat model, Privacy Notice, and Terms. The September 21 website handoff includes separate legal review drafts; this website update does not adopt those drafts or change existing agreements.