Every product in this category sells capacity: credits, builders, agents, a monthly fee per agent. None of them sells the thing a business owner already knows how to manage, which is an employee with a job description, a budget, a boss, a paper trail and a weekly report. Everything below makes Sanaf more like a hire and less like a meter.
This came out of a research pass in September 2026: we read the products people compare us against, the 2026 surveys of businesses adopting AI and the literature on why these projects fail, then ranked the work by how much pain it takes away. We do not put dates on any of it. Things move, and a roadmap with dates on it is just a list of broken promises with extra steps.
Next
Specified, and the work we intend to pick up first.
Budgets, refunds and a pause button
The problem. The loudest complaint in this whole category is a bill nobody saw coming, and the second loudest is being charged for work that failed. An owner will not hand real work to something that can quietly spend a month of budget in an afternoon.
What we intend to build. A spending cap per job, set in the console, that stops the next run rather than warning after the fact. Work that fails refunds itself. A pause switch that stops everything, including the scheduled and unprompted work, with the record showing nothing spent while paused. Before it acts, the approval card says roughly what this will cost, from its own history.
A receipt and an undo for every action
The problem. Most owners will not fully trust this kind of software with even routine tasks unless someone is watching it, and the incidents that get written up are rarely attackers. They are ordinary software doing the wrong ordinary thing to its own company.
What we intend to build. Every action stores one plain sentence saying why it did that. Anything reversible gets an undo for a window afterwards, run under the same rules as the original. Anything that cannot be taken back says so on the card before you approve it, not after.
Source: Upwork Research Institute and Small Business Expo surveys, 2026; incident counts from Cyera research.
An authority chart
The problem. Right now the rules about what may happen without asking belong to the job, not to the person asking. In a real business the office manager and the apprentice do not have the same signing authority, and software that ignores that is software you cannot leave running.
What we intend to build. Who may ask for what, and spend how much, set per person. A restriction on a person beats a permission on the job. Reads run under the asker own access where the app supports it, and a private conversation stays private from the rest of the team.
Later
Specified, and waiting on the things above it to land first.
The Monday letter
The problem. Not being able to prove the thing is worth its bill is one of the two biggest reasons this software gets cancelled, alongside security. Most products answer it with testimonials or a calculator that makes up its own numbers.
What we intend to build. A short letter that arrives without being asked for: what it did, what it is waiting on and from whom, where it was corrected, what it cost, and what it wants to do next. Time saved is counted against a figure you gave us, and labelled as your figure. In a week where nothing happened, no letter is sent.
Source: Upwork Research Institute 2026 barriers survey; Gartner forecast on agentic project cancellations.
Work that arrives by email
The problem. For a trade, a firm or a shop, the quote request and the supplier invoice and the client question land in an inbox. Every product in this category waits to be spoken to in a chat window, which means it only sees the work someone remembered to forward.
What we intend to build. A shared inbox becomes somewhere Sanaf works, the same way a channel is. Mail arriving becomes a conversation with the sender as an outside party, duplicates are dropped, and a reply is drafted for approval rather than sent. Replying to someone outside the business always asks first.
Watchers
The problem. An employee who only ever responds is half an employee. The useful part of a good one is noticing: the invoice that went past due, the customer who has gone quiet, the job that never got scheduled.
What we intend to build. Conditions Sanaf watches for in the systems the business already runs, each with its own budget and a limit on how often it may speak. It raises something only when it is worth saying, and every firing is in the work log whether it spoke or not.
Money jobs with two keys
The problem. Invoicing and chasing payment is the work businesses most want off their desk and least want done wrong. Doing it properly needs the receipts and the authority chart to exist first, which is why it is not sooner.
What we intend to build. Listing what is overdue, drafting the reminder, recording a payment and voiding a mistake, as first-class actions rather than generic app calls. Posting asks first, refunds above the owner threshold are never automatic, and a reconciliation pass reports anything that does not match.
An evidence pack for regulated work
The problem. A firm that has to answer to a regulator or a client audit cannot use software that will not show its work. It needs the record scoped to one matter, not to the whole workspace.
What we intend to build. An export for a period and a matter containing the instructions, inputs, outputs, which model, which version of its instructions, and every approval and override. Work scoped to a matter returns nothing from another matter, tested as strictly as we test one workspace against another.
The first week
The problem. A new hire is useless on day one because it knows nothing about the business, and most of these products ask you to fix that by typing instructions into a box.
What we intend to build. Import what the business already has, its site, a folder, the history of an inbox, before the first conversation. Then a week of shadowing where it posts what it would have done without doing it. It ends with a one-page contract naming the job, the budget, who approves and the first thing it will watch.
Exploring
Researched, with a real obstacle still in the way. We may not build it.
More places to work
The problem. Slack and Microsoft Teams cover most of the businesses we talk to, but not all. Discord runs whole communities, and plenty of teams live in Google Chat or Zoom instead.
What we intend to build. We researched all three. Discord needs a always-connected worker to hear a mention at all, which is a different shape of infrastructure from everything else we run. Google Chat and Zoom both sit behind a marketplace review, and Zoom cannot be installed by the person who wants it without an administrator approving it first. We would rather say that than list them and let you find out.
Memory the whole workspace shares
The problem. What Sanaf learns while doing one job does not currently help it with another. Correct it once about how the business prices a callout, and it can still get it wrong somewhere else.
What we intend to build. One set of facts about the business that every job draws on and every job can add to, with the same rule as everything else: it may ask the owner when something contradicts what it already believed, rather than quietly picking one.
Single sign-on and provisioning
The problem. Signing in is with Google or a code sent to email. A company past a certain size will not add software that cannot join its identity system, and will not manage accounts by hand.
What we intend to build. SAML for sign-in and automatic joining and removing of people. If either is a hard requirement for you today, tell us before you commit to anything, because we would rather lose the sale than be the reason a rollout stalls.
Publishing a page to your own address
The problem. A page Sanaf builds can be shared as a link that works for a week. That is right for a report and wrong for anything a business wants to keep, such as a sign-up page it means to send to customers.
What we intend to build. Publishing to a real address the business owns. The reason it is not simply the next thing we do is that it raises questions a tool call should not answer on its own: whose hosting, whose domain, and who is paying for it.
What we are not building
A roadmap that only says yes is a wish list. These are decisions, not omissions, and each of them is a thing we have been asked for.
- Phone, SMS and WhatsApp channels. Sanaf works where your team already talks, and the work we hear about most arrives by message and by email.
- Swarms of agents that hand work to each other. One employee you can hold responsible is the entire idea, and a swarm is the fastest way to lose the paper trail.
- A template marketplace. The jobs ship with the product and we keep them honest ourselves. A marketplace makes that somebody else problem.
- Per seat pricing. You pay for work done, not for how many people are allowed to ask. Charging per seat would punish exactly the businesses that get the most out of it.
- Anything that needs your passwords inside the model. Sign-ins stay vaulted outside it, and that constraint has already cost us features we would otherwise have shipped.
What already exists is on the changelog, dated by the day it landed.