← All insights

Industry Insights · Her AI Logic

Your AI Has Rules. Who Enforces Them?

A written instruction is the start. The next question is what the system will actually allow.

By Michelle Rose4 min read

“Never send an email without my approval.”

That sounds like a clear boundary. But if your AI still has permission to send, who is enforcing it?

This is the question business owners should bring into conversations about AI agents. A convincing demonstration shows what an agent can do. A serious implementation discussion also asks what it cannot do, who can change that, and how you would find out if something went wrong.

The rule and the permission are separate decisions

An instruction describes the behavior you want. A permission determines the actions a connected tool makes available. Both matter.

Anthropic’s engineering team describes containment as enforcing boundaries around what an agent can reach and do. Its account also explains why model instructions and human approvals cannot carry the entire burden of protection. These are findings from its own products, not a guarantee about every agent platform. Read Anthropic’s explanation of containment.

For a business owner, the practical question is simple: if this agent only prepares drafts, why does it need the ability to send them?

Ask whoever configures the system to show you the answer in the actual connection settings. If the platform cannot separate drafting from sending, that limitation belongs in the decision about whether to use it.

Approval needs something worth reviewing

Consider an illustrative example: an agent prepares a follow-up for someone who asked about your services.

A useful approval request shows the recipient, the complete message, the source of any price or promise, and the action you are authorizing. “Approve follow-up?” leaves too much hidden.

The approval should apply to the message you reviewed. If the recipient or the offer changes afterward, the workflow should require another review. Ask your implementer how that works; do not assume an approval button provides that protection.

A person being in the process does not tell you whether that person has enough information to make a decision.

A small business still needs an owner

You do not need a committee to name who is responsible.

Someone should know which accounts are connected, which actions are allowed, and how to pause the workflow. Someone should review exceptions. In a small business, that may be the same person.

The gap appears when everyone assumes the software company, the consultant, or another team member is watching. Before a workflow starts, name its owner and agree on what gets reviewed.

Responsibility should also survive a handoff. If the person who built the workflow leaves, the business needs a usable record of its access, limits and recovery steps.

Test the boundary without involving real customers

Use a test account, invented customer details and an inbox you control. Ask the implementer to demonstrate what happens when a request exceeds the intended permission.

For a draft-only workflow, the useful evidence is a blocked sending action or the absence of a sending capability. A polite response saying “I cannot do that” tells you about that response; it does not prove the underlying permission is restricted.

Also test missing information. Does the workflow stop when it cannot find an approved price? Does it ask a person when a customer requests an exception? Record what happened, including any unexpected actions.

Passing a small test is evidence about those conditions. It is not a promise that every future situation will behave the same way.

Give more access only when the job calls for it

There are jobs where sending, updating records or booking appointments is the point. Keeping every agent in draft mode forever would defeat their purpose.

The decision is whether the added access is necessary for a defined job, whether mistakes can be detected and corrected, and whether someone owns the consequences.

Before you connect another account, ask: What useful work does this permission enable, and what becomes possible if the agent gets it wrong?

That is a stronger starting point than adding another sentence to the prompt.

For the earlier decision about whether you need another agent at all, read Before You Add Another AI Agent, Read This.

Choose one job for AI.

Get Your First AI Employee, a free five-email series about useful AI work, the decisions that still need you, and what to consider before you build.

Get the five emails

About Michelle Rose

Michelle Rose is the founder of Her AI Logic and an AI Workplace Orchestrator. She helps business owners and teams put AI to work on everyday tasks, decide when a person needs to step in, and check that the work gets done.

Meet Michelle