The failure mode people expect from a sales bot is that it writes badly. The failure mode that actually costs money is that it writes persuasively about something untrue. A model optimised to keep a conversation moving will agree, reassure, imply and hint, and every one of those becomes a sentence your business has to stand behind when a client screenshots it.
Scalegram treats this as a product boundary rather than a prompt preference. There are things the bot may not say, and they are enforced in the same way regardless of what anyone writes in the playbook.
No flirting, and no romantic framing at all
This one surprises people until they have run a Telegram bot for a fortnight. Clients flirt with bots. Some do it to be funny, some do it because the bot is warm and available at two in the morning, and some do it because they have worked out that a model which is being charming is a model that has stopped following its instructions. That last group is the reason the rule is absolute.
A Scalegram bot does not flirt back, does not adopt romantic framing, and does not perform intimacy. It redirects to the business it is there to do. This is not prudishness. A bot that plays along is a bot that has been moved off its rails, and everything downstream, what it offers, what it confirms, what it grants, becomes negotiable from there.
No promise the business cannot keep
The second rule is the expensive one. A model asked "will I get my money back if it does not work" would rather say something comforting than something accurate. Left alone, it will invent a policy, promise a callback nobody scheduled, guarantee a timeline nobody agreed, or relay a commitment on behalf of a person who has not been asked.
So promises are treated as a category the bot cannot issue. Where a client needs one, the flow either quotes a policy you actually wrote or stops and asks a human. And anything irreversible, an invite, an upgrade, an access grant, does not depend on the bot's judgement at all: it waits for an operator tap at an ask-me checkpoint. The VIP invite flow is the fully worked example.
In a trading context this is not only a customer service question. Signals and copied trades are information and tooling, never financial advice, and no outcome is promised. Trading carries a high risk of loss. A bot implying otherwise is a compliance incident with a timestamp on it.
Not an adviser
Third rule, and the one with the sharpest edges: the bot does not give financial advice. It can describe what a product is, what it costs and how it works. It does not tell anyone what to trade, how much to risk, or whether a market is about to move. The line is between describing a product and recommending a course of action with someone's money, and it holds in every market and every language the bot speaks.
SINGUARD sells software. It is not a broker, a bank or an adviser, and neither is a bot running on its infrastructure.
Enforced outside the prompt
Here is the part that separates a rule from a wish. If a guardrail exists only as a sentence in a system prompt, it is a suggestion competing with everything else in the context window, and it loses that competition under pressure from a determined user. Prompt-level rules also evaporate the moment someone edits the playbook or the conversation runs long.
The rules above are hard-coded, checked on the way out, and not editable from the playbook. An operator can change tone, offer, objection handling and closing lines. An operator cannot switch off the block on flirting or the block on promises, and neither can a client with a clever message. The same argument applies to what a client can extract from a bot, which is covered in a customer gets nothing out of it.
They apply in every language
A guardrail written in English protects your English-speaking market. Bots answer in the language the client wrote in, which means the rules have to be enforced at the level of what the bot is doing rather than at the level of English phrasing. This is worth checking yourself in any market you cannot read, because a complaint from that market will arrive in that language too. The mechanics of language handling are in answering in the client's language.
How this shows up in practice
Most conversations never touch a guardrail, which is the point. The ones that do tend to cluster: a handful of clients test the bot deliberately in the first week after launch, and a slower stream of genuine questions about refunds and outcomes arrives forever. The second group is the useful signal. If the bot is handing the same question to a person forty times a week, the answer belongs in a written policy the flow can quote, and writing it down is a better use of an afternoon than any amount of prompt tuning.
What the operator still owns
None of this makes the bot safe on its own, and it is not meant to. It makes the bot bounded. You still write what the offer is and what it costs, and you are responsible for it. You still decide when a conversation goes to a person, and handover rules should be generous rather than clever. On a team, per area permissions at read, add, write and delete level decide who can change a playbook in the first place, which matters more than it sounds: most bad bot messages start as a well-meaning edit by someone who did not know what the sentence would do at scale.
The honest summary is that guardrails do not make an AI trustworthy. They make the set of things it can get wrong small enough that a human can supervise it.
"A model that wants the conversation to continue will find a way to say yes. Our job is to make sure the yeses it can hand out are ones the business can actually honour."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- Bots are hard-blocked from flirting and romantic framing, because a bot playing along is a bot that has already stopped following its instructions.
- Promises are a category the bot cannot issue: it quotes a written policy or stops and asks a person, and anything irreversible waits for an operator tap.
- The bot describes a product but never recommends a course of action with someone's money, and no outcome is ever promised.
- The rules are enforced outside the prompt and cannot be edited out of the playbook, and they apply identically in every language the bot speaks.
Frequently Asked Questions
Can I turn off the flirting block for my market?
No. It is hard-coded rather than a playbook setting. Operators control tone, offer, objections and closing lines, but the blocks on romantic framing and on promises are not editable.
What happens when a client asks something the bot cannot answer?
It either quotes a policy you actually wrote or hands the conversation to a person. It does not improvise a refund policy, a timeline or a commitment on behalf of someone who has not been asked.
Does the bot give trading advice?
No. It can describe what a product is, what it costs and how it works. It does not tell anyone what to trade or how much to risk. SINGUARD sells software and is not a broker, bank or adviser.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.