Skip to main content

Pragmatic Rhino

AI & ACCOUNTABILITY

AI Agents in Business: Decide What They Can Do Before You Deploy

By Michael Schnapf · Published October 2, 2026 · 3 min read

An AI agent that drafts a customer response and an AI agent that sends it have different responsibilities. An agent that recommends a refund and one that issues it create different consequences. The same distinction applies to updating a customer record, changing a price, or approving a purchase.

I want those boundaries decided before an agent touches a live workflow. A capable system can create problems quickly when it has permissions that exceed the judgment built into the process.

The executive question is straightforward: which actions can this system take, under which conditions, and who remains accountable when it gets something wrong?

Divide the workflow by authority

I would map the workflow into three levels: gathering information, preparing a recommendation, and taking an action. Some steps can operate with little intervention. Others should remain subject to approval.

For example, an internal support agent might retrieve an approved policy and draft a response. A person reviews the draft before it reaches the customer. Later, after testing, a limited class of routine responses might qualify for automatic sending. A request involving a contract exception or a refund would still require a decision from someone with that authority.

This is a hypothetical workflow, not a promise that a particular product supports these controls. The chosen platform needs to demonstrate that it can enforce the boundaries, rather than merely describe them in a prompt.

Make permissions narrower than ambition

Start with the minimum data and tools required for the task. A system summarizing a support history does not automatically need the ability to edit the account, export all customer records, or change billing.

Separate the credentials and permissions for reading from those used for actions where the platform allows it. Define transaction limits, approved destinations, and the cases that must be escalated. Test whether duplicate requests or retries can trigger the same action twice.

Content retrieved from a document, email, or website should be treated as information to evaluate. It should not acquire the authority to rewrite the workflow's instructions or expand the agent's permissions. That becomes especially relevant when an agent handles material submitted by customers or outside parties.

Test the exceptions employees already know

The normal path is only part of the job. Ask the team for the cases that cause trouble: an ambiguous customer identity, a policy with two versions, a missing order, or an instruction that conflicts with an earlier approval.

A useful test includes what the agent should do when it lacks evidence. Escalating or declining to act can be the correct result. Do not measure success solely by the percentage of requests completed automatically.

Review the effect on the people handling exceptions. If the agent leaves the team with fewer requests but much more difficult ones, staffing and training assumptions may need to change.

Give the team a usable stop and recovery process

The workflow needs a named owner, a record of significant actions, and a practical way to stop it. Define who investigates a failure and how the team returns to the previous process.

For actions that can be reversed, test the reversal. For actions that cannot, make the approval threshold stronger. An audit log is helpful, but it does not restore a wrongly issued commitment or recover information that has already left the company.

I would review quality, escalation rate, rework, total handling time, and actual incidents together. A high automation rate with increasing cleanup is an operating warning.

Expand authority when the evidence supports it

The objective is a better business process. Start with an authority level that the company can supervise, collect evidence, and expand deliberately when the result justifies it.

For CEOs and portfolio operating teams, this is a management decision as much as a technical one. The company owns the customer relationship and the financial consequence. It should also own the rules under which the agent acts.

If an AI initiative needs executive ownership and clear decision rights, learn about fractional leadership.

CONTINUE THE CONVERSATION

What needs to move in your business?

I work with investors, CEOs and leadership teams on operating constraints, technology, AI and integration.