Trail map
Detailed content
🤖 Responding isn’t acting
Assistant, agent, tool, and access: the course vocabulary and the difference that changes how big a mistake can be.
An assistant is an AI chat that responds with text. An agent is the same chat with tools: it sends, changes, deletes, and pays on its own.
Without this distinction, you treat an agent as casually as you treat a chat—and there’s no one in the middle to check its work.
Language model, assistant, agent, real world.
Email, calendar, spreadsheet, WhatsApp, and payments: what the agent can use after you grant access through a connector.
The cost of an error grows with the tool. A wrong message is annoying; a wrong payment can’t be undone.
Access, connector, acting in your name, cost of an error.
The agent works in loops: receives the request, plans, uses a tool, checks the result, and decides what to do next.
Every turn is an action you didn’t see. Without a record, you only see the end—after it has already happened.
Cycle, loop, independent decision-making, visibility.
The same error has three destinations: it stays on screen (assistant), stays in a draft (agent with approval), or goes out into the world (agent without approval).
Some actions can’t be undone. For those, control needs to come first.
What happens to an error, a draft, or an irreversible action.
A table of every AI tool you use and what it can read, change, and send—put together with help from an AI chat.
Lots of people clicked "allow" and forgot. You can't control what you don't know exists.
Inventory, permissions, connected apps, "verify".
The course’s thesis: the more the agent does on its own, the tighter the limits—and you decide.
She organizes the five tracks: pain, control, hidden risks, and results, one after another.
Limits, human decisions, the trail ladder, agent profile.
⚖️ More capable, more limits
The same ability that helps can also attack. Signs that an agent has too much freedom, and the agent you’ll build throughout the course.
The ability to find security flaws can be used to defend and to attack. The agent that organizes your inbox can also delete it.
What determines which side it’s on isn’t the AI; it’s the limits you set and who controls the agent.
Same strength, defense, damage, limit.
Better models, tools for taking action, and one-click connectors arrived together. Anyone can connect an agent in minutes, on their phone.
Easy to turn on; control still takes work. It’s the step almost everyone skips.
Model, tool, one-click connector, who connects it.
An access ladder: first read-only, then write drafts, then send with approval. Money, deletion, and publishing are never done alone.
No one hands over the bank password on the first day. The agent carries out a misunderstood request with the same confidence as a correctly understood one.
Read-only, draft, approval, access earned over time.
Six warning signs side by side: access to everything, sends without showing you, no one knows how to turn it off, no history, no owner, no spending cap.
An agent with too little oversight works well until the day it makes a mistake. The signs show up beforehand, if you look.
Access to everything, logging, an off switch, an owner.
A ready-to-use prompt that asks the AI chat for the five worst-case scenarios for the agent you're planning, how much each would cost, and whether they can be undone.
Putting a cost in reais turns vague fear into a decision: it shows where to require approval before turning it on.
Worst-case scenario, cost, whether it can be undone, the right limit.
A fill-in template: task in one sentence, tools, what it does on its own, who uses it, and who owns it.
The same agent returns in every track and gains a layer in each one: pain, controls, safety, and results.
One agent, one-sentence task, owner, and a card that comes back.