See the same power on both sides
The newest AIs can already find security flaws in systems that experts hadn’t spotted. Defenders use this to fix the flaw. Attackers use it to break in. The ability is the same.
The same thing happens in your business, on a smaller scale. The agent that organizes your inbox in ten minutes is the same one that, given a misunderstood request, archives or deletes the whole inbox in ten minutes. What changes which side it lands on is who controls e what it’s allowed to do.
How to read the diagram: Notice that each line on the left has a counterpart on the right—it’s the same power used another way. The middle box doesn’t change. What determines which way the balance tips is written below the fulcrum: the limits.
✓ Renata's agent, used well
- ✓Reads the schedule and prepares tomorrow’s reminders.
- ✓Show the list and the text before sending.
- ✓Saves the front desk an hour a day.
✗ The same agent, unchecked
- ✗Understands “clear Friday’s calendar” as “cancel everything.”
- ✗Notifies the 14 patients about the cancellation without showing it to you first.
- ✗The receptionist spends Monday rescheduling appointments.
serves both sides
finds and fixes the flaw
at the same speed
pick a side
Understand why agents became capable now
Three things arrived at the same time. The models got better at planning multiple steps. They gained tools to act. And the connectors became a button: "connect to Gmail," "allow."
Before, connecting AI to your calendar required a programmer and weeks of work. Today, anyone can do it in minutes on their phone, without reading what they’re authorizing. The convenience is great. The care hasn’t caught up.
How to read the diagram: the three blue arrows are continuous and fast—they're what push the agent into your life. The arrow to "controls" is dashed and gray: that's the step almost everyone skips. This course is for that part on the right.
| What changed | Before | Now |
|---|---|---|
| 🧠 Model | answered a question | plans and executes multiple steps |
| 🧰 Tools | only text on the screen | email, calendar, spreadsheet, browser |
| 🔌 Connection | programmer, weeks | one button, minutes |
| 🙋 Who cares | the IT team | anyone in the office |
💡 Notice the last line
At Marcos's office, the first person to turn on an agent wasn't him: it was Júlia, the assistant, trying out an app on her phone. When anyone can turn one on, someone needs to know what's running — that's the inventory from module 1.1.
plans multiple steps
turning it on got easy
without a programmer
can wait
Apply the new employee rule
No one hands an employee the bank password on their first day. They start by observing, then work under supervision, and only gain autonomy once they show they get it right. Treat the agent the same way.
The difference is that a new employee is afraid of making a mistake. The agent isn’t. It carries out a misunderstood request with the same confidence as a correct one. That’s why access grows gradually, and each step is your decision.
🆕 New here? What is “approval”?
Approval is the moment when the agent stops, shows you what it’s about to do, and waits for your “go ahead.” Without it, a draft goes straight to sending. With it, the mistake appears on your screen before it reaches the customer. Approval is the cheapest control there is.
Week 1 · read-only
Renata’s agent reads the calendar and says who has an appointment tomorrow. It doesn’t write anything anywhere.
Week 2 · prepares a draft
Write the reminders, but don’t send them. The front desk reviews and sends them.
Month 1 · sends with approval
Show the list and the text; Renata approves with one tap; it sends and logs what it did.
Never on its own · money, deletion, publishing
Renata still handles billing, refunds, deleting accounts, or publishing for everyone, even after months of practice.
💡 Track 3 preview
This ladder becomes a method in module 3.1, with five keys: what it can read, what may change, what needs approval, where it goes record and who presses the shutdown button. For now, keep this idea in mind: access is earned, not handed over all at once.
the first step
writes, doesn't send
your "yes" up front
access is earned
Recognize the signs of an agent with too much freedom
An agent that's too loosely controlled won't tell you it's out of control. It works, saves time, everyone likes it — until the day it makes a mistake. The signs show up beforehand, if you look.
Compare the two columns with the agent you use or plan to use. Two or more items in the red column already mean you should stop.
✗ Too unconstrained
- ✗Has access to everything “so there are no permission errors.”
- ✗Sends, deletes, or pays without showing you first.
- ✗No one knows how to turn it off, or who can.
- ✗There’s no history of what it did yesterday.
- ✗No one owns it: "it was the system."
- ✗Runs overnight with no spending limit.
✓ Under control
- ✓Accesses only what the task needs.
- ✓Show the draft and wait for approval before anything goes out.
- ✓Has a power-off button anyone can find in 1 minute.
- ✓Keep a record: what it did, when, and for whom.
- ✓Has a named owner who reviews the errors.
- ✓Has spending and attempt limits.
⚠️ The most dangerous signal
“Nobody knows how to turn it off.” If the agent starts making mistakes one after another, every minute spent looking for the button is another minute of damage. Before turning it on, agree on who turns it off and how — and test it once.
Quick test (optional): Marcos’s WhatsApp bot replies to customers on its own, nobody knows where to see what it replied yesterday, but only Júlia knows how to turn it off. What’s the most urgent signal?
too many open doors
what it did yesterday
found in 1 minute
one name, not "the system"
Do the “what if it goes wrong?” test
Before turning on an agent, spend ten minutes imagining the worst. Not to give up, but to know where to set the limit. An AI chat is great for this—it thinks of scenarios you wouldn’t think of.
The test works best with numbers from your business: how many customers, how much each appointment is worth, how long it takes to fix things. Cost turns vague fear into a decision.
Paste into the AI chat you already use (ChatGPT, Claude, Gemini). Replace what's inside < >. Don't paste client names.
Vou ligar um agente de IA no meu negócio e quero pensar no pior antes. Meu negócio: <ex.: clínica de estética, 2 funcionárias, 300 pacientes ativas>. O que o agente vai fazer: <ex.: confirmar consultas e remarcar quem pedir>. Ferramentas que ele vai usar: <ex.: agenda, WhatsApp da clínica, planilha de pacientes>. O que ele pode fazer sozinho: <ex.: ler, escrever mensagens, remarcar>. Valor médio de um atendimento: <ex.: R$ 120>. Liste os 5 piores cenários realistas deste agente, do mais caro para o mais barato. Para cada um, escreva: 1. o que acontece, em uma frase; 2. quantas pessoas ou quanto dinheiro são atingidos; 3. quanto custaria em reais e em horas de trabalho para consertar; 4. se dá para desfazer ou não; 5. o limite que evitaria o problema (ex.: aprovação, só leitura, teto de envios). Use só os números que eu dei. Onde precisar estimar, escreva "estimativa". No fim, diga qual limite resolve o maior número de cenários.
| Renata's scenario | Cost | Can you undo it? | Limit |
|---|---|---|---|
| Cancels all the appointments for an entire day | 14 × R$ 120 = R$ 1.680 | in part | cancel only with approval |
| Send a reminder to someone who doesn’t have an appointment | 1 afternoon of apologies | no | show the list first |
| Reschedules two patients for the same time | 1 missed appointment | yes | change log |
What to look for in the table: The "Undo?" column matters more than the cost column. A cheap mistake that can’t be undone (a message that’s been read) needs more control than an expensive mistake that can be fixed.
Choose the agent you’ll take through the course
From here on, the course gets practical. Each track will ask you to apply what you’ve learned to a real agent — yours. It can be one that already exists or one you plan to connect.
Choose just one, small and tied to day-to-day work. If you’re not sure which one yet, write down your best guess: in Track 2, you’ll check whether it addresses the right pain, and you can change it.
How to read the diagram: the green card is what you fill out now. The blue line is its path through the course; at each colored stop, it gains a layer. The more concrete the card is today, the more useful each stop will be.
Copy this to your phone's Notes or to a document. Replace what's between < >. If you want, paste it into an AI chat and ask: "ask me one question at a time until this card is filled out."
MEU AGENTE Nome curto: <ex.: confirmador de consultas> Tarefa (uma frase): <ex.: confirmar as consultas do dia seguinte e anotar quem pediu para remarcar> Já existe ou vou ligar? <existe / vou ligar> Ferramentas que ele usa: <ex.: agenda, WhatsApp da clínica> O que ele pode fazer sozinho hoje: <ler / escrever rascunho / enviar / apagar / pagar> Quem usa no dia a dia: <ex.: recepção> Quem manda nele (dono): <seu nome> Pior cenário (do teste "e se der errado?"): <uma frase + custo> Data de hoje: <dd/mm/aaaa>
💡 Marcos’s card
“Document collector: reads each client’s outstanding items and prepares the WhatsApp message asking for what’s missing. I’ll connect it. Tools: outstanding-items spreadsheet, office WhatsApp. On its own: drafts only. User: Júlia. Owner: Marcos. Worst-case scenario: asking someone for a document they already submitted — annoyed client, half an hour on the phone.”
small and everyday
the entire task
from day one
across all tracks
🎓 Module summary
Next track:
Track 2 — Find the pain point · start with module 2.1, The 10× Question