Frequently Asked Questions
IronFist AI is an autonomous agent platform built by StableState LLC. You get a dedicated AI agent deployed on isolated Azure infrastructure that can manage your email, calendar, documents, social media, code repositories, and more, depending on your plan. Your agent operates 24/7 using tools and procedures you teach it.
Visit https://www.ironfistai.com and click "Continue with Google" to create your account. You will then select an agent role template (or describe a custom agent), choose your plan, provide your AI provider API key, connect a Telegram bot (with identity verification), and select your integrations. Your agent is provisioned automatically in about 3-5 minutes.
You need a Google account (for sign-in), an API key from your AI provider (Anthropic, OpenAI, or Google), and a Telegram bot token (create one via @BotFather). During setup, you will also verify your identity by sending /start to your bot from Telegram. All integrations (Gmail, Calendar, Drive, etc.) are configured after your agent is deployed via the dashboard.
You provide your own AI provider API key, your own communication channel, and your own integration credentials (Google, Microsoft, GitHub, etc.). StableState provides the orchestration, tools, memory, governance, and infrastructure. This means you control your AI usage costs directly through your provider, and your credentials are never shared with other subscribers.
During onboarding, you paste your Telegram bot token (from @BotFather) into the channel step. The portal verifies your token is valid by checking it with Telegram. Once verified, you will see a prompt asking you to open Telegram and send /start to your bot. This step verifies your Telegram identity so your agent only responds to you, not to anyone else who discovers the bot.
Once you send /start, the portal automatically detects your message and confirms your chat ID. The Continue button becomes active and you can proceed. This usually takes just a few seconds.
This is a security measure. Your Telegram chat ID is locked into your agent's configuration so that only you can interact with it. Without this step, anyone who finds your bot's username could send it messages and potentially access your connected services. The /start verification ensures your agent knows exactly who its owner is.
After you click Deploy, the platform provisions your dedicated infrastructure in about 3-5 minutes. You will see a progress indicator with stages: creating infrastructure, deploying your agent, configuring persona and permissions, running health checks, and going live. Your agent receives a unique persona based on the role template you selected, and its tool set is configured based on your tier. Once deployment completes, your agent is online and you can message it immediately via Telegram.
Three things to get the most out of your agent immediately. First, open Telegram and send your agent a message to confirm it responds. Try "Who are you and what can you do?" to see its persona. Second, go to the Integrations tab on your dashboard and connect the services you want your agent to use (Gmail, Calendar, Drive, etc.). Third, teach your agent a procedure by telling it something like "Every morning at 8am, check my calendar and send me a summary."
Starter ($199/month) includes 30 tools, 1 channel, and 200 daily operations. Professional ($449/month) includes 50 tools, 3 channels, 2,000 daily operations, and optional voice add-on. Business ($899/month + $499 onboarding) includes 75+ tools, unlimited channels, 10,000 daily operations, and voice included. Enterprise is custom-scoped. See full plan details.
Starter and Professional plans include a 7-day free trial. A valid credit card is required to start the trial. You will not be charged during the trial period. If you do not cancel before the trial ends, your subscription automatically converts to a paid plan. Business and Enterprise tiers do not include a free trial.
If you cancel during your 7-day trial, you will not be charged. Your agent and all associated data are deleted immediately. There is no data export window for trial cancellations.
Stripe automatically retries failed payments 3 times over 7 days. If all retries fail, your agent is suspended (it stops processing messages) and you enter a 14-day grace period. During grace, you retain dashboard access and can export your data. If payment is not resolved within 14 days, your agent and all data are permanently deleted.
Yes. You can upgrade or downgrade your plan at any time through the Billing section. Upgrades take effect immediately with prorated billing. Downgrades take effect at the start of your next billing cycle. Tool and channel limits adjust automatically.
Yes. Your StableState subscription covers the platform, infrastructure, tools, and orchestration. Your AI provider costs (Anthropic, OpenAI, or Google) are billed directly by your provider based on your agent's token usage. StableState does not control or bill your AI provider usage.
Depending on your plan, your agent can send and read emails, manage your calendar, search and create documents, automate browser tasks, post to social media, monitor GitHub repositories, process data, and much more. Your agent uses tools that match your selected role template and tier.
Role templates pre-configure your agent with a persona, default procedures, and suggested integrations tailored to a specific use case. Available templates: Executive Assistant (calendar, inbox, briefings), Outreach Operator (cold email, lead gen), Social Manager (posts, engagement, DMs), DevOps Monitor (deploys, incidents, PRs), and Research Analyst (data, market analysis). You can also describe a completely custom agent.
Yes. After your agent is deployed, you can teach it procedures through your communication channel. Procedures are step-by-step instructions your agent follows for recurring tasks. For example: "Every Monday at 8am, pull my calendar for the week, summarize it, and send me a briefing email." Your agent stores and executes these autonomously.
Yes. Your agent has persistent memory stored in your dedicated database. It remembers facts about you, your preferences, past conversations, and task history. Memory persists across sessions and is never shared with other subscribers.
Approval gates are safety mechanisms that require your explicit approval before your agent executes high-risk actions. By default, gates are enabled for sending emails, financial operations, data deletion, and browser write actions. Your agent will message you in your channel asking for approval before proceeding. You can opt out of specific gates through the dashboard, but doing so shifts full responsibility to you.
The dashboard is your control center after deployment. From the Overview tab, you can see your agent's status, tier, tool count, last activity, and daily operations usage. The API Keys tab lets you update or rotate your AI provider key. The Channels tab shows your connected communication channels. The Integrations tab is where you connect and manage all your services. The Procedures tab shows any saved procedures your agent has learned. The Approval Gates tab lets you control which action categories require your approval. The Billing tab connects to Stripe for subscription management.
Go to the Integrations tab on your dashboard. Each available integration shows its current status (Connected, Available, or Requires upgrade). For services that use OAuth (Gmail, Calendar, Drive, Outlook, Teams, GitHub, LinkedIn), click "Configure App" to enter your OAuth Client ID and Client Secret, then click "Connect" to authorize via a popup window. For services that use API keys (Browserbase, PagerDuty, CRM webhooks), click "Enter Credential" and paste your key. You can test any connection with the "Test" button and disconnect at any time with "Disconnect."
You need to create a Google Cloud project with OAuth 2.0 credentials. Go to console.cloud.google.com, create a project, enable the Gmail API, Google Calendar API, and Google Drive API, then create OAuth 2.0 credentials (Web application type). Copy the Client ID and Client Secret. In the IronFist dashboard Integrations tab, click "Configure App" on the Google service, paste your credentials, then click "Connect" to authorize. Your agent will request only the scopes it needs for each service.
You need to register an app in Microsoft Entra (formerly Azure AD). Go to entra.microsoft.com, navigate to App registrations, create a new registration, and add the required API permissions (Microsoft Graph: Mail.ReadWrite, Calendars.ReadWrite, etc.). Create a client secret. In the IronFist dashboard Integrations tab, click "Configure App" on the Microsoft service, paste your Application (client) ID and client secret, then click "Connect" to authorize.
Yes. Go to the API Keys tab on your dashboard. Enter your new key, click "Update Key," and the portal validates the new key with your AI provider before saving it to your dedicated Key Vault. The update takes effect on your agent's next message cycle. Your old key is immediately replaced and cannot be recovered.
In the Approval Gates tab, you can see which action categories currently require your approval (email sending, social media posting, financial operations, data export, bulk actions). To opt out of a gate, you must read and accept a per-category acknowledgment that confirms you understand your agent will act without asking first. You can re-enable any gate at any time. Each opt-out and opt-in is timestamped in your tenant record.
Yes. Complete isolation. Every subscriber gets a dedicated Azure resource group containing their own Cosmos database, Key Vault, Container App, and managed identity. No other subscriber's agent, infrastructure, or identity can access your data. Your agent's memory, procedures, credentials, and outputs are completely private to you.
All credentials are stored in your dedicated Azure Key Vault, which uses FIPS 140-2 Level 2 validated hardware security modules (HSMs). Only your agent's managed identity has runtime access. StableState engineers do not have routine access to your Key Vault, and credential values are never displayed in the admin panel. See our Credential Handling Acknowledgment for full details.
No. StableState's admin panel displays only operational metadata: agent status, health, uptime, and resource utilization. It does not expose message content, memory, procedures, credential values, or agent outputs. Your data resides in your dedicated Cosmos database, not in a shared system. See our Privacy Policy for full details.
If you cancel a paid subscription, your agent is suspended immediately. You have 30 days to export your data (memory, procedures, episodes) via the dashboard. After 30 days, your Azure resource group and all associated data are permanently deleted. Trial cancellations are deleted immediately with no export window.
All infrastructure is deployed in the Azure East US region (United States). Your dedicated Cosmos database, Key Vault, Storage Account, and Container App all reside in this region. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Core integrations available on all plans: Gmail, Google Calendar, Google Drive, Microsoft Outlook, and Microsoft Teams. Template-specific integrations include LinkedIn, Instagram/Meta, and X/Twitter (Social Manager), GitHub, Azure DevOps, and PagerDuty (DevOps Monitor), CRM webhooks (Outreach Operator), and web scraping and document processing (Research Analyst). Browser automation is available on Professional tier and above. All integrations are configured post-deployment via the dashboard Integrations tab.
Social media platforms (Meta/Instagram, X/Twitter, LinkedIn) have their own API access policies, rate limits, and approval processes. For example, Meta requires a registered Developer App with approved permissions, and blocks headless browser login. X/Twitter requires API access at their Basic or Pro tier. These are platform-level requirements outside StableState's control. We display disclaimers so you understand what is needed before connecting.
After connecting an integration, click the "Test" button on its card in the dashboard. The portal sends a test request through your agent's credentials and reports whether it succeeded or failed. If a test fails, check that your credentials are valid, your API quotas are not exhausted, and the required permissions are enabled in your provider's developer console. You can also ask your agent directly via Telegram to try using the integration.
Yes. Click "Disconnect" on any integration card to permanently remove its stored credentials from your Key Vault. You can reconnect at any time by going through the setup flow again (Configure App and Connect for OAuth services, or Enter Credential for API key services). Disconnecting does not affect your agent's other integrations or its core functionality.
OAuth integrations (Gmail, Calendar, Drive, Outlook, Teams, GitHub, LinkedIn) use an authorization flow where you sign in to the service and grant specific permissions to your agent. You first enter your OAuth app credentials (Client ID and Client Secret from your developer console), then click Connect to authorize via a popup. API key integrations (Browserbase, PagerDuty, CRM webhooks, ElevenLabs) use a single key or token that you paste directly. Both types are stored securely in your dedicated Key Vault.
Yes. Under the BYO model, you create your own Google Cloud project and Microsoft Entra app for your agent's integrations. This ensures your agent uses your own OAuth credentials, your tokens are never shared with other subscribers, and you maintain full control over permissions and scopes. StableState provides documentation for setting up each integration.
Contact us at contact@stablestateit.com for any questions, issues, or feature requests. Business tier subscribers receive priority support with a 4-hour response SLA. You can also visit https://www.stablestateit.com for general information and our contact form.
StableState commits to 99.5% uptime for the platform infrastructure. This excludes upstream provider outages (Anthropic, Google, Microsoft, Browserbase) and client-side credential failures. If uptime falls below the commitment, eligible subscribers receive service credits. Details are in the Terms of Service.
At launch: Telegram and Custom Webhook. For Telegram, you create a bot via @BotFather, paste the token during setup, and verify your identity by sending /start to the bot. Your chat ID is locked into your agent so only you can interact with it. For Custom Webhook, you provide a REST API endpoint where your agent POSTs responses. Additional channels (Slack, Discord, WhatsApp, Microsoft Teams messaging) are on the roadmap.
Still have questions?
Contact us at contact@stablestateit.com
Visit https://www.stablestateit.com for general inquiries and our contact form.
