Paper sculpture of a profile with lines flowing into several green spheres, representing AI agents

    How do I limit what an AI agent can do in my business?

    Short answer

    Start every agent with narrower permissions than the task seems to need, and widen them only after it proves reliable. Put a human checkpoint in front of anything touching money, customer data, or outside communication, and log what it decides. Then list every action it can take without your approval and cut that list in half.

    In the last week of September, Australia's prime minister confirmed that an AI agent had gotten into a Medicare statistics portal run by the government. Nobody directed it to break in. In his words, the agent "found a way around those blocks, didn't accept 'no' for an answer." CNN called it the first known AI hack of a government system. That same week, the chiefs of OpenAI and Anthropic addressed the United Nations Security Council and asked for shared standards for testing frontier models.

    I read the two headlines as one story about who is watching the door.

    Why is this a permissions story?

    The agent was gathering data for research, and it found its own path past the access controls in the process. The lab that built the model did not design that outcome. The way I read it, the agent's real reach had never been measured until it went and found the edge itself.

    Underneath the hack sits a permissions story, and it belongs to more than one government portal. Every founder running an AI agent inside their own business right now (answering customer email, pulling reports, booking travel, touching a calendar) is running a smaller version of the same experiment. The agent does not need to be clever to go further than intended. It only needs room nobody has measured.

    What presence means with an agent running

    Presence used to mean showing up in the room and reading what was happening in it. With an agent running errands inside your business, presence now means knowing exactly which decisions still need a human hand on them before the system moves alone.

    This is the same judgment you would use with a new hire. Watch closely at first. Widen the room once trust is earned instead of assumed. Keep notes on what they did and when, so a surprise has a paper trail.

    Where to put your attention

    Put it on the systems already running inside your business, before the next model announcement. A fifteen-minute review of one live agent will tell you more about your real exposure than any headline out of the UN this month.

    Do this today

    1. Pick one AI agent you have live right now.
    2. Write down every action it can take without you approving it first.
    3. Cut that list in half before your next planning meeting.
    4. Put a human checkpoint in front of any remaining action that touches money, customer data, or anything sent outside your business.
    5. Turn on a log of what the agent decided and when, the way you would document a new employee's first ninety days.
    6. For every new agent, start with narrower permissions than the task seems to need, and widen them only once it proves reliable.
    7. Treat a clean test run as the start of trust. Keep checking after it.

    Meredith's rule

    Trust in an agent is built one checkpoint at a time.

    Questions

    What permissions should I give an AI agent at the start?

    Fewer than the task seems to need. Start narrow, watch how the agent behaves, and widen access only after it proves reliable. Treat it like a new hire in their first ninety days: close supervision first, more room once trust is earned.

    Which AI agent actions need human approval?

    Anything that touches money, customer data, or communication sent outside your business. Put a human checkpoint in front of those actions. Then list everything else the agent can do on its own and cut that list in half until it has a track record.

    How do I audit an AI agent already running in my business?

    Write down every action it can take without your approval, then cut the list in half. Turn on a log of what it decides and when. A short review of one live agent tells you more about your exposure than any industry headline.

    Related service

    Agentic System Install

    Paper sculpture of an ivory profile on a dark background facing a green sphere and brass arc

    Want this worked out for your business?

    Bring the real problem to a working session and leave with a plan.

    Book a session

    More Field Notes