Start from the action, not the AI
The useful question is not whether AI can be trusted. It is what happens if this specific action is wrong. Reading a record and drafting a reply carry almost no risk. Sending money or deleting data carries a lot. The same agent can be safe for one and not the other.
List every action the agent could take, then sort each one using three questions.
Three questions for every action
- Can it be undone? An update you can reverse is very different from an email already sent or a payment already made.
- What does a mistake cost? Consider money, a customer’s experience, a legal or contractual obligation, and your reputation.
- How often does the agent face something new? Routine, repetitive cases are safer to automate than situations that vary every time.
Level 1: the agent may act on its own
Actions that are easy to reverse, cheap if wrong and routine. Typical examples:
- Reading and summarizing documents, emails or records
- Classifying and routing incoming requests to the right queue
- Drafting replies, reports or updates for a person to use
- Flagging records that look incomplete or inconsistent
Even here, log every action so you can review what the agent did and spot patterns early.
Level 2: the agent prepares, a person approves
Actions that reach customers, change important records or commit the business. The agent does the work; a person clicks approve. Typical examples:
- Sending an email or message to a customer
- Updating prices, balances, inventory or contract details
- Creating invoices, orders or credits
- Closing, escalating or reassigning a customer case
Approval should be quick: show the person exactly what will happen and why, so reviewing takes seconds rather than redoing the work.
Level 3: the agent should not do it
Some actions should stay with people, however good the agent becomes:
- Moving money or issuing payments and refunds without a person
- Deleting data or changing access and permissions
- Decisions about hiring, credit, eligibility or anything with legal effect on a person
- Anything your contracts, policies or advisors say requires a human decision
For these, the agent can still help by gathering information and preparing a recommendation for the person who decides.
The safeguards that make it safe
Whichever level an action sits at, a well-built agent has the same foundations:
- A defined list of tools, so it can only take the actions you allowed
- The minimum access it needs, in accounts you control
- A log of every step and decision, kept where you can review it
- Limits on volume and value, so one bad run cannot do much damage
- A clear way for a person to stop it, correct it and take over
Move actions up a level slowly
Start an action at a stricter level than you think it needs. Review the log and the approvals for a few weeks. If a person approves the same kind of action every time without changes, that action may be ready to move to the level below. If approvals often change the draft, it is not.
That way trust is earned from your own results, not assumed from a demonstration.