Reading and writing are different products

An assistant that looks things up carries the risk of a wrong answer. One that updates your CRM, sends messages, or books time carries the risk of a wrong action, which is not recoverable by rephrasing.

Start with read, then draft, then write

Look things up, then prepare an action for approval, then perform it. Each stage earns the next, and most of the value arrives at the second — the reason copilots suit most businesses better than agents.

Wrong answers are embarrassing. Wrong actions are on the record.

Give it its own account

Never let an AI teammate act through a person’s credentials. It needs its own identity with its own permissions so that its actions are attributable and its access can be revoked without disrupting anyone — basic production hygiene that is routinely skipped here.

Scope permissions to the job description

Grant exactly what the defined role requires and nothing else. Every extra permission is a possible action you did not intend, and this is the point where what it may see and do becomes concrete rather than theoretical.

Make destructive actions impossible, not discouraged

Deletion, cancellation, refunds, and anything irreversible should be structurally unavailable rather than prohibited by instruction. A prompt is a request; a permission is a rule.

Log every action with its reason

What it did, on what basis, and which version of its instructions was in force. That record is what makes an incident explicable and is the same requirement as explaining a decision after the fact.