Treat access as a business decision
An agent connected to a CRM, inbox, calendar, or internal knowledge base can see and change real information. Decide what it needs to access before enabling those connections.
Define what it can do
Specify which actions it may take, which need human approval, what counts as an uncertain result, and how a person can pause or undo an action. Test errors and unusual requests, not only the expected path.
Keep oversight practical
Record important actions, limit permissions to the task, and route sensitive decisions to an accountable person. Monitor how the system behaves after release and have a way to disable it.
Read the risk guidance
NIST’s AI Risk Management Framework can help teams organize risk identification and management. A framework supports the discussion; it does not replace a system-specific security review.