Agent permissions.
Set the boundaries.
An agent can prepare a draft, change a record or send a message. These carry different responsibilities. Define allowed actions, approval points and evidence of completion before connecting agents to business tools.
At a glance
- Separate preparing an output from changing a system.
- Approval should cover a specific action and its data.
- Check the result in the tool and how failures are handled.
Which actions are allowed?
Describe the process goal, data sources, tools and permissions. For each task, specify whether the agent may prepare it, execute it independently or execute it after approval. A shared harness coordinates knowledge, memory and steps, but should not automatically give every agent the same access.
Illustrative example: an agent gathers CRM information and drafts an offer. Reading specified records and preparing a draft are allowed. Changing a price, saving the offer and sending it to the customer have separate approval conditions.
What should a person see before approving?
Show the recipient, message or data change, tool and expected effect. “Continue” without that context does not establish permission to send an offer. If the recipient or operation scope changes after approval, the changed action needs a fresh decision.
Treat documents, websites and email as working material, not permission to expand access. An instruction hidden in that material can steer a model towards an unintended action. Tool restrictions and execution checks must operate beyond the prompt itself.
Did the action actually succeed?
After a write, read back the result or check the operation identifier in the system. Do not confuse a prepared draft with a sent email. If a tool does not respond, establish whether the write occurred before retrying; otherwise duplicates may result.
- Record the approved action and the system result without exposing secrets.
- Define which failures stop the process and who takes over.
- For irreversible actions, verify conditions beforehand; do not assume every change can be undone.
What should you test before expanding access?
Test a valid request, refusal, changed data, interruption after approval and a timeout after writing. Evaluate the whole workflow: information gathering, decision and confirmed outcome. Passing work to the next agent should preserve approval boundaries and execution status.
These checks show what can be automated and where human control remains necessary. Fit the scope to actual business work rather than starting with access to every system.
Sources and next step
These sources describe mechanisms and good practices. They do not confirm your company’s configuration or compliance. The examples in this guide are illustrative.
To apply these questions to your business, explore the related service. A description of your situation is enough for an initial discussion; do not send passwords or confidential data through the form.
Explore how we implement business AI