Field note

AI agents

AI agents need boundaries, not just better prompts

Set access, action limits, approvals, and recovery paths before an agent touches business systems.

Treat access as a business decision

An agent connected to a CRM, inbox, calendar, or internal knowledge base can see and change real information. Decide what it needs to access before enabling those connections.

Define what it can do

Specify which actions it may take, which need human approval, what counts as an uncertain result, and how a person can pause or undo an action. Test errors and unusual requests, not only the expected path.

Keep oversight practical

Record important actions, limit permissions to the task, and route sensitive decisions to an accountable person. Monitor how the system behaves after release and have a way to disable it.

Read the risk guidance

NIST’s AI Risk Management Framework can help teams organize risk identification and management. A framework supports the discussion; it does not replace a system-specific security review.

Back to all Field Notes