Reading and writing are different products
An assistant that looks things up carries the risk of a wrong answer. One that updates your CRM, sends messages, or books time carries the risk of a wrong action, which is not recoverable by rephrasing.
Start with read, then draft, then write
Look things up, then prepare an action for approval, then perform it. Each stage earns the next, and most of the value arrives at the second — the reason copilots suit most businesses better than agents.
Wrong answers are embarrassing. Wrong actions are on the record.
Give it its own account
Never let an AI teammate act through a person’s credentials. It needs its own identity with its own permissions so that its actions are attributable and its access can be revoked without disrupting anyone — basic production hygiene that is routinely skipped here.
Scope permissions to the job description
Grant exactly what the defined role requires and nothing else. Every extra permission is a possible action you did not intend, and this is the point where what it may see and do becomes concrete rather than theoretical.
Make destructive actions impossible, not discouraged
Deletion, cancellation, refunds, and anything irreversible should be structurally unavailable rather than prohibited by instruction. A prompt is a request; a permission is a rule.
Log every action with its reason
What it did, on what basis, and which version of its instructions was in force. That record is what makes an incident explicable and is the same requirement as explaining a decision after the fact.