What Karas is not allowed to say
Some mistakes are worse than an unhelpful answer. A support assistant that promises a refund, or tells a customer their account has been cancelled, creates an obligation you did not agree to and a conversation you have to unwind.
Karas is prevented from making those claims by checks that run over every finished answer, before it is delivered. These are code, not instructions in a prompt — they cannot be talked around by a customer, whatever they type.
The forbidden claims
Refund promises. It cannot say a refund has been issued or processed, or that one will be. It can explain your refund policy as documented; it cannot apply it.
Claims about an account's state. It cannot say that your account, plan, subscription or site has been charged, billed, suspended, upgraded, downgraded, deleted, cancelled, refunded or restored. It has no access to your systems, so any such statement would be a guess presented as a fact.
Claims to have acted. It cannot say it has deleted, restored, migrated or cancelled anything on a customer's behalf. It takes no actions at all.
Soliciting credentials or card details. It cannot ask a customer to send or share a password, card number, security code or similar.
What happens when a check fires
The answer is not edited or softened. It is replaced with a message telling the visitor that the question needs a person, and the conversation is marked as needing a human. Nothing is quietly delivered with the offending sentence removed.
What these checks deliberately allow
The checks require a definite assertion about a real state, not merely the vocabulary. Your documentation legitimately contains sentences like "ensure your site is upgraded to a paid plan" and "never share your password with anyone" — instructions, not claims — and an earlier, blunter version of these checks suppressed correct answers to every billing and security question because of them.
So the rule is narrow on purpose: an instruction is allowed, an assertion is not. The distinction is tested in both directions, and a new check is not added without a test for what it must not match.
What they are not
These checks are not a content filter and not a substitute for your own policy. They stop a specific set of high-cost claims. Everything else in an answer is governed by what your documentation says.