Your AI writes a perfectly decent customer email. You fix one sentence, hit Send, and think: why am I still doing the clicking?
Because that click is where your business agrees to whatever the email says.
You can spend all afternoon comparing AI models and never decide what yours is allowed to do. An AI agent is an assistant that can use connected tools to take actions. Give it a Send button and you've delegated more than writing.
Start with drafts you actually review
My default for customer-facing work: let it draft, and have a person send. Review the facts, the recipient, any attachments, and especially the promises. A friendly sentence about a refund is still a refund promise.
Give it one job to start. Draft replies to opening-hours questions using your approved business information. Leave complaints, discounts, booking changes, and anything outside that job for a person.
Keep the source information read-only and put the drafts in a separate review area. You don't need to grant sending permission to find out whether the writing saves you time. If your tool bundles drafting and sending access, use a separate writing workspace and copy the reviewed reply yourself.
Draft-only still deserves a privacy check. Whatever you hand over is data the service processes. Check its retention and training policies before feeding it customer information. Start with public business facts, not your entire inbox.
Give it fewer keys
“Never delete anything” is an instruction. Removing delete permission is a restriction. Use both, but don't confuse them.
OWASP, a nonprofit security organization, recommends limiting an agent's tools and permissions to what its job requires, with authorization enforced outside the AI. In ordinary terms: the connected system needs to block forbidden actions even when the AI asks for them.
Don't connect it with your owner login just because setup is easier. Use a separate, restricted account where the service supports one. An assistant sorting inquiries has no business changing your billing details.
Reading access needs limits, too. A folder or email label isn't a security boundary unless the integration actually enforces it. Ask the vendor to show that the assistant cannot open records outside its assigned work. If access can't be narrowed, give it selected copies instead.
Incoming emails also need to stay in their place. OpenAI's safety guidance describes how malicious text can try to override an AI's instructions, including attempts to leak private data. That's called prompt injection. A customer's message is material to respond to; it doesn't get to rewrite your rules or authorize access to somebody else's records.
Make approval mean something
Keep a human in front of actions that spend money, change bookings, delete records, publish under your name, or make commitments to customers. OWASP explicitly recommends human approval before high-impact actions.
The approval screen should show the exact action. For an email, that means the recipient, subject, full message, and attachments. For a booking change, show the old booking and the proposed replacement. “Handle this customer?” tells you almost nothing.
Approval should apply only to what you reviewed. Change the recipient or rewrite the message afterward? Ask again. Name who is allowed to approve, and keep that control separate from the assistant. It shouldn't be able to approve its own work.
No answer means wait. A timeout must never turn into permission. “I assumed you were busy” is a lousy reason to issue a refund.
If your software can't enforce a pause before the action, leave that action disconnected. Have the person do it manually after reviewing the draft.
Let boring work run, but make failures visible
There is room for work without a click every time. Suggesting inquiry labels or creating internal notes is a better starting point than sending customer replies, provided the source data stays intact and the changes are easy to undo. Test against human-reviewed results before widening the job.
And if the task follows fixed rules, use ordinary automation. Sending your approved appointment reminder at a fixed time doesn't require an AI to improvise.
For anything you do delegate, require a history showing what it attempted, what actually succeeded, and who approved it. OWASP recommends logging, monitoring, and rate limits to limit damage. You still need permission controls. A log records the mistake after it's happened.
Choose limits on daily actions and spending, and name the person who gets failure alerts. Make sure that person can pause the workflow and revoke its access.
Require a stop when essential information is missing or a tool fails. If an approved send times out, check the mail system before retrying. “Unknown” is a real status. Don't let the assistant turn it into a cheerful “Done!” or a second email.
The delegation checklist
Before connecting an agent to your business, fill this out. Bring it to whoever is setting the thing up.
- Job: What single task does it handle? What gets handed to a person?
- Data: Which messages or records can it read? What stays out, and how is that boundary enforced?
- Permissions: Can it draft, edit, send, publish, delete, or spend? List each separately.
- Approval: Who approves consequential actions? Do they see the exact details, and does a change require fresh approval?
- Limits: What are the action and spending caps? Which recipients or destinations are allowed?
- Failures: Where are attempts, approvals, and confirmed results recorded? Who gets notified when work stalls?
- Stop: Who can pause it, revoke access, and fix or undo a bad action?
- Test: What happens with missing information, a misleading email, withheld approval, or a disconnected account?
Ask for a demonstration where the assistant tries to send without approval and gets blocked. Watch it happen before connecting your real inbox.