Set a spending cap
Many AI services charge by usage: each question, each agent turn, each file it reads costs a little credit. An agent working on its own can make hundreds of turns in one night.
Without a cap, you find out how much you spent when the bill arrives. With a cap, you know the worst case before it happens.
How to read the diagram: the two lines start out the same—the same agent is stuck repeating the task. The blue bell is the email alert at halfway to the limit: time to take a look. The amber line stays flat at the dashed line because the account stops accepting charges; the red one only stops when someone wakes up.
✗ No ceiling
- ✗AI account linked to the main credit card, with no monthly limit.
- ✗No usage alerts configured.
- ✗Marcos left an agent checking documents overnight; a faulty file made it try again, and again.
✓ With a limit
- ✓Monthly limit set in the account dashboard ("spending limit," "budget").
- ✓Email alert at 50% and 80% of the limit.
- ✓A virtual card just for AI, with a low limit. Marcos's loss stopped there.
💡 Can’t find where to set a limit?
Use a fixed monthly plan or create a virtual card in your bank's app just for AI services, with a limit of, for example, twice what you expect to spend. This solves the same problem without relying on the service dashboard.
monthly limit
at 50% and 80%
only for AI
known in advance
Set a resource cap and stop the loop
Money isn’t the only thing an agent uses up. It uses time, attempts, sent messages, and computer memory. A loop without an end, it consumes all of this at the same time.
It happened on one of our projects: a tool running without a memory limit froze the entire server—and without a ceiling, it froze again on the next attempt. The fix was one line: a limit. Every agent needs its own.
| Limit | Example for Renata’s clinic | When it hits the limit… |
|---|---|---|
| ⏱️ Maximum time | confirming the appointment takes no more than 10 minutes | stops and tells you what's missing |
| 🔁 Attempts | no more than 3 attempts per patient | mark it "not confirmed" and move on |
| ✉ Sends | no more than 40 messages per day | stops everything and asks for approval |
| 💾 Memory / machine | limit set by whoever installed it | the system stops only the agent, not the server |
What to look for in the table: the last column. A good limit doesn’t just stop the agent: it says what to do when it stops—notify you, mark the task as pending, ask for approval. Stopping silently is almost as bad as not stopping.
Paste into the agent's fixed instructions. Adjust the numbers inside < > for your task.
REGRA: LIMITES DE ESFORÇO 1. Cada tarefa tem no máximo <10> minutos. Passou disso, pare e me diga o que concluiu e o que falta. 2. Se uma mesma ação falhar <3> vezes seguidas, não tente de novo. Registre o erro e me avise. 3. Nunca envie mais de <40> mensagens por dia. Chegou no limite, pare e peça aprovação. 4. Se perceber que está repetindo os mesmos passos sem avançar, pare. Repetição sem progresso é sinal de loop. 5. Ao parar por qualquer limite, escreva: qual limite, onde parou e o que sugere.
repeat without making progress
per task
few and limited
never silent
Isolate the agent
Limiting what the agent can do is one part. The other is limiting where it can do. An isolated agent works in a walled-off space: if it makes a mistake or is tricked, the damage stays inside.
You don’t have to set this up alone. You need to know what to ask: "Does the agent run in isolation? In which folder? What’s excluded?".
🆕 New here? What is a “sandbox”?
Sandbox (in English, sandbox) is a closed-off space where the agent can make changes freely without reaching the rest of the computer — like a sandbox where a child can play without making a mess in the house. A common way to set this up is called container (container): a "box" with only the files and programs the agent needs. The simplest version is a limited folder: the agent can see only one folder, and nothing outside it.
How to read the diagram: The dashed amber fence is the agent’s limit. Inside is only what the task requires—notice that the schedule is a copy. The red line shows the agent trying to reach the key file: it hits the fence. The four gray boxes outside are on the same computer, but the agent can’t see them.
Basic level: separate account and folder
The agent uses an email account of its own and can see only one folder. Anyone can do this.
Intermediate level: separate computer or user account
A system user account just for the agent, or an old dedicated machine, with no login to the bank or your personal accounts.
Technical level: container
Set up by whoever installs it. You ask and check: "what's included?", "what's excluded?", "who turns it off?".
walled-off space
box with the minimum
the simplest isolation
instead of the original
Understand the LGPD in one page
The LGPD (General Data Protection Law) explains how a company can use people’s data. It applies equally whether a customer spreadsheet is read by an employee or an AI agent. You’re still responsible.
This is not legal advice. It’s the minimum a business owner needs to keep in mind before connecting an agent to customer data.
| The idea behind the law | In plain language | In practice, with the agent |
|---|---|---|
| Personal data | everything that identifies someone: name, phone number, CPF, email | Renata’s entire schedule is personal data |
| Sensitive data | health, religion, biometrics, racial origin, among others — extra care required | "had this procedure" is health data |
| Legal basis | an accepted reason to use the data: consent, contract, legal obligation… | a reminder about a scheduled appointment fits into service; sending a promotion requires consent |
| Purpose | use only for what was agreed | a phone number given to confirm an appointment doesn’t become a marketing list |
| Need | use as little as possible | the reminder agent doesn’t need the CPF (topic 5) |
| Data subject rights | the person can ask to see, correct, or delete their data | you need to know where the agent stored copies |
What to look for in the table: the right-hand column. Almost every safeguard comes down to a simple question: "Why does the agent need this?" and "Where does it store it?" If you can’t answer, it’s not time to turn it on yet.
⚠️ Attention: health is sensitive data
Clinics, medical offices, gyms, and salons that record allergies or treatments handle sensitive data. Pasting that history into any AI chat "just to summarize it" is the kind of carelessness the law penalizes. When in doubt, talk to whoever handles the legal side of your business before turning on the agent.
identifies someone
health and related matters
accepted reason
only what was agreed
Show the agent only what it needs
Two techniques solve most of it: minimize (remove the columns the task doesn't use) and anonymize (replace the name with a code). The agent does the same work; anything leaked is worth much less.
Do this before before the data reaches the agent, in your spreadsheet. Asking the AI to "anonymize" data you already pasted into the chat won’t help: they’re already there.
✗ What Renata was going to send
Nome: Ana Paula Souza CPF: 000.000.000-00 Telefone: (00) 90000-0000 Procedimento: peeling químico Alergia: ácido salicílico Faltou: 3 vezes
✓ What she sent
Código: P-014 Tipo de sessão: facial Faltou: 3 vezes
The question was “which patients miss appointments most often?” The code is enough to answer it. Only she has the table that links P-014 to a name.
Paste into the AI chat. Send only the column names from your spreadsheet — never the data. Replace what’s between < >.
Vou ligar um agente de IA a uma planilha de clientes e quero dar a ele o mínimo de dados. Tarefa do agente: <ex.: identificar quem mais falta às consultas e sugerir horários de lembrete>. Colunas da planilha (só os nomes, sem dados): <ex.: nome, CPF, telefone, e-mail, data de nascimento, procedimento, alergias, faltas, valor pago>. Para cada coluna, responda em uma tabela: coluna | a tarefa precisa? (sim/não) | se sim, dá para trocar por código ou faixa? | é dado sensível pela LGPD? Depois, me diga qual seria a planilha mínima para essa tarefa.
only the useful columns
name becomes code
stays with you
in the spreadsheet, not in chat
Close the four doors
Most problems with agents don’t come from a sophisticated attack. They come from four doors open: a secret in chat, an extension accepted without reading, an account without a limit, and too much customer data.
This checklist brings together what you saw in modules 4.2 and 4.3. Go through it for the agent you chose at the beginning of the course—it goes straight to the “security” section of the Trail 5 spreadsheet.
Copy this into a document. Mark [x] for what's already done and write the expected date for anything that's left.
AS QUATRO PORTAS — agente: <nome/tarefa do seu agente> data: <____> PORTA 1 · SEGREDOS [ ] Nenhuma senha, chave ou token colado em chat ou documento compartilhado. [ ] Regra "segredos" nas instruções do agente (módulo 4.2). [ ] Sei onde revogar cada chave: <lista>. PORTA 2 · EXTENSÕES [ ] Revisei extensões, plugins e apps conectados; removi o que não uso. [ ] Cada um que ficou: sei quem publicou e o que pede combina com o que faz. PORTA 3 · GASTO E ESFORÇO [ ] Teto mensal na conta: R$ <____>. Alerta em 50%: [ ] [ ] Cartão só para IA ou plano fixo: [ ] [ ] Regra "limites de esforço" nas instruções (tempo, tentativas, envios). [ ] O agente roda isolado: pasta/conta/contêiner <qual>. PORTA 4 · DADOS DE CLIENTES [ ] O agente toca dados de clientes? <sim/não>. Dado sensível? <sim/não> [ ] Planilha mínima: só as colunas que a tarefa usa; nomes trocados por código quando der. [ ] Sei onde o agente guarda cópias, para atender quem pedir para apagar. Porta que ainda está aberta: <____>. Quem fecha: <____>. Até: <____>.
💡 How Marcos used it
Marcos went through the checklist with Júlia, the office assistant, on a Friday afternoon. It took 25 minutes. They found two open doors: an AI account with no spending cap and a spreadsheet containing every client’s CPF that the agent didn’t even use. They closed both before leaving.
Quick test (optional): Renata wants an agent to find out which patients miss the most appointments. What should she give it?
outside the chat
only the verified ones
with a cap and guardrails
only the minimum
🎓 Module summary
Next track:
Track 5 — Own the outcome