What an Agent Should Never Be Allowed to Do Without Asking

What an Agent Should Never Be Allowed to Do Without Asking - editorial illustration

As agents earn trust through a track record of good work, it is tempting to widen what they can do unsupervised. Some actions should stay gated permanently, independent of the track record.

Sending anything to an external contact

A draft is internal. A sent message is external and, once sent, cannot be un-sent. This line should never move, no matter how good the agent's drafts have been. A person approves before anything crosses that line, every time.

Stating a number that will appear in a client-facing document

Fee figures, projections, or any quantitative claim about a prospect needs a named person confirming the source before it is used. The cost of a wrong number in a proposal is disproportionate to the time saved by skipping the check.

Asserting a fact about a specific relationship

Claims like we have not worked with this prospect before, or this contact previously declined a similar pitch, touch institutional memory that lives in a firm's own CRM, not in a model's general knowledge. These claims need to be checked against the firm's actual history before they appear anywhere.

The underlying principle

The pattern across all three is the same: actions that are irreversible, or that assert something specific about a real relationship or a real number, keep a permanent human gate. Actions that are reversible and low-stakes, drafting, formatting, initial research, are reasonable candidates to run with less supervision over time.

A short note on documenting exceptions

If a team ever grants a one-time exception to a permanent gate, for a genuinely unusual, low-risk situation, write down why, who approved it, and what made it different from the general rule. An undocumented exception has a way of quietly becoming the new normal within a few months, which defeats the purpose of having a permanent gate in the first place.

Keeping the list visible, not just written down

A permanent-gate list buried in a policy document nobody rereads provides little practical protection. Posting it somewhere the team actually sees during the relevant workflow, inside the tool itself, on the approval checklist, in the weekly scorecard review, keeps it operative rather than theoretical, which matters more than how thorough the list is on paper.

A short note on revisiting this list after a near miss

The most productive moment to review this list is right after a near miss, a mistake that almost reached a client but was caught in time, while the specifics are still fresh and the argument for tightening a rule is easiest to make convincingly to the rest of the team.

A short note on communicating the approval framework to a new client

A prospective client asking how AI fits into a firm's process generally responds well to a short, specific answer describing exactly where the approval gates sit, rather than either an overly technical explanation or a vague reassurance. Being able to describe the process in two or three plain sentences is itself a sign the process is well designed, since an overcomplicated answer often reflects an overcomplicated, and less reliable, underlying process.

It is worth rehearsing that short answer before a client actually asks, rather than improvising it in the moment. A firm that has to think hard about how to explain its own review process has usually not thought hard enough about the process itself.

A final word on trust building over time

Trust in an agentic system should be earned incrementally and specifically, expanding what runs with less supervision only for the exact task categories that have built a real track record, rather than as a general, across-the-board loosening once a tool has performed well a few times. Specific, task-by-task trust is more resilient than blanket trust, because a failure in one category does not have to force a rethink of everything else the system does well.

How this list should evolve

This is not meant to be exhaustive, and teams should expect to add to it as they encounter their own specific near-misses. The underlying test for whether a new action belongs on the permanent-gate list is simple: if this went wrong, could it be quietly fixed, or would a real person outside the firm have already seen it? Anything in the second category belongs on the list, regardless of how reliable the agent performing it has become.

Key takeaways

  • Sending anything externally should always require a named person's approval.
  • Numbers that will appear in a client-facing document need a sourced, human-confirmed check.
  • Claims about a specific relationship require checking the firm's own CRM, not a model's memory.
  • Irreversible or relationship-specific actions keep a permanent gate; reversible, low-stakes ones can loosen over time.

Questions, answered

What is the short answer on What an Agent Should Never Be Allowed to Do Without Asking?

A short, practical list of the actions that should always require a named person's sign-off, regardless of how reliable the agent has proven to be.

What are the key takeaways?

Sending anything externally should always require a named person's approval. Numbers that will appear in a client-facing document need a sourced, human-confirmed check. Claims about a specific relationship require checking the firm's own CRM, not a model's memory. Irreversible or relationship-specific actions keep a permanent gate; reversible, low-stakes ones can loosen over time.

How does VIPMarketing approach agents & approval?

In VIPMarketing, outreach lands as drafts in your own inbox or LinkedIn and proposals need a named approver's sign-off. Nothing is sent without a person approving it.