# SUPPORT.md — support channel plan (draft, nothing set up yet)

Pattern: follow the proven HyreKit mail mechanism exactly (memory: hyrekit-mail-is-a-sendas-alias, support-reply-cc-hyrekit-identity), since it already works and is tested.

Mechanism — final name is **SafetyLoop**, alias would be `safetyloop@offsite.ee`

Corrected 2026-10-10 (lane L5) after a live check — this is more involved than this draft originally assumed, so it was not created this lane (time-boxed, see below), but the exact mechanism is now verified instead of guessed:

today) shows EmailAddresses: ["SMTP:allie@offsite.ee"] only — hyrekit@offsite.ee is not a proxy address on allie's own mailbox, contradicting this draft's original assumption.

list (DL) object, forwarding to erkki@offsite.ee + allie@offsite.ee; the "SendAs" capability bin/hyrekit_reply.py relies on is a Send-As permission grant on that DL object**, trustee allie@offsite.ee (Add-RecipientPermission -Identity hyrekit@offsite.ee -Trustee allie@offsite.ee -AccessRights SendAs) — not a Set-Mailbox -EmailAddresses edit on allie's own mailbox.

safetyloop@offsite.ee (or a mail contact, whichever matches the hyrekit pattern exactly — re-check Get-DistributionGroup -Identity hyrekit@offsite.ee first), (2) Add-RecipientPermission granting SendAs to allie@offsite.ee, (3) a new bin/safetyloop_reply.py cloned from hyrekit_reply.py's mechanism (createReply in allie@offsite.ee → PATCH from/sender → send), never copying HyreKit's own identity/secrets. All three steps are within Allie's existing EXO admin app-only hand (bin/exo_admin.py`, no new consent needed) — genuinely creatable without the owner, just not done this lane (time-boxed against the rest of this lane's scope; two DL-admin mutations deserved a dedicated, unhurried pass rather than being rushed at the end of a QA+listing lane).

for this), revisit a hyrekit.io-style dedicated CC-DL only if the product gets its own domain.

PRIVACY.md/TERMS.md this lane) — this is explicitly the brief's own fallback, not a missed step.

What Allie answers directly (no owner escalation)

NEEDS_REVIEW / UNKNOWN) means, how to re-run an audit.

not issue a compliance certificate; point to the specific NEEDS_REVIEW/UNKNOWN items and what evidence would resolve them.

this; Allie explains the mechanism (see PRICING.md), does not change anyone's plan or issue refunds without the owner.

Escalate to the owner (money or legal only, per standing instruction)

applicable to my specific business" is a legal question, not a support question).

fined") — escalate immediately, do not improvise a legal position.

Response time

Follow the HyreKit precedent language ("usually within one business day, EET, UTC+2/+3") — [OPEN: confirm the owner wants the same commitment for a second product before publishing this externally].

Not yet done

No alias created, no DL decision made, no reply script written — this file is the plan, not the implementation. Needs an explicit owner "yes" (Exchange admin action) before [app-alias]@offsite.ee can send or receive anything.