Trail map
Detailed content
🔑 The five keys
Think of the agent as a new employee: what it reads, what it changes and sends, what it waits for your yes on, where the log is, and who shuts it off. Leave with the agent’s form filled out.
Give the agent only the access the task requires, as you would with a new hire. Renata was going to connect four tools and ended up with two.
Every additional access point means more potential damage. The reminder works the same way without the card reader.
The least access possible, piece by piece; trust that is earned.
The first key: what the agent can see to do the task—and only that. One folder, one tab, one calendar.
What it reads may contain customer data and outside text with hidden instructions.
Scope, customer data, what it needs to read × what it doesn’t need to read.
The second key: what it can change inside the house and what it can send outside, written with “only” and “just.”
Internal changes can usually be reversed. A message that reached the customer can't.
Change, send, power level, narrow written scope.
The third key stays with you: the agent stops, shows you what it’s going to do, and waits for a “yes” before acting.
Three types of actions have no undo button. The gate is mandatory for them.
Approval, gate, money, deletion, publication.
Where to check what the agent did, with the date and time, and who can make it stop in one minute—like Júlia in Marcos’s office.
When something goes wrong, without a record, no one knows what to fix, and without a button, the error keeps happening.
Log, shutdown button, second person, one-minute test.
A ready-to-use template — the AGENT SHEET — with the five lines, the owner, and what's off-limits, plus Renata's sheet as an example.
The worksheet determines the agent’s scope before it exists, and comes back in the course’s final spreadsheet.
Agent profile, owner, out of scope, review.
🧯 Three rules and real cases
Start with read-only, ask for a draft, and have a person handle money, deletion, and publishing. Three cases from our projects and the house rules block to paste into the agent.
During the first few weeks, the agent only reads and reports what it would do. Then it drafts. Only after that does it take small actions.
It's the only way to see how it thinks without paying for its mistakes.
Read-only mode, report, phases, "did it get it right?".
A sending rule that requires the agent to show the text, recipients, and channel, then wait for your "yes." The clinic promotion with and without the lock.
In the draft, the "R$ 19" that should have been "R$ 190" is corrected before it reaches 312 patients.
Draft, lock, fixed instruction, silence isn’t “yes.”
The rule that never changes: these three actions always wait for a person, with a designated person for each type.
The danger comes in through requests that seem small, like “clean up the duplicates.”
No undo, back door, who approves, remove access.
It happened on one of our projects: an agent used a paid service without asking. Turning off the computer didn’t bring the credit back.
What leaves your computer stays on the other side. Money controls come first, not later.
On the other side, the charge is made, approval comes first.
A tool without a memory limit froze the server twice; a "stop everything with this name" command brought down the terminal itself.
With no money involved, both stopped working. A cap and narrow scope prevent that.
Limit, narrow scope, broad target, boomerang effect.
A ready-to-use block of fixed rules to paste into the agent's instructions: a key isn't permission, draft, approval, scope, cap, uncertainty, and logging.
A rule written once applies to every request — and the three-part test shows whether the agent follows it.
House rules, explicit authorization, API, three-part test.