AI agents
AI agents that take bounded actions, with a person in charge
An agent is a model allowed to take steps: look something up, draft, file a ticket, or update a record. We build agents for bounded jobs, with the tools and approvals written in ordinary code so the model cannot grant itself more power.
- Task design
- Tool layer
- Supervision
- Evaluation

A small loop beats an open-ended employee
Agents fail when the goal is vague and the tools are powerful. We define the task, the maximum number of steps, the systems they may call, and which actions require a person. “Run the company” is not a specification. “Prepare the renewal brief from these three records and wait” is.
Safety of the action
The dangerous part of an agent is not the paragraph it writes. It is the side effect. Payments, deletions, and messages to customers are gated. Every tool call is logged with the inputs that mattered, so a bad run can be explained.
A task runner with limits
The agent may
- Take one kind of task
- Use the tools you list
- Leave an audit of each step
The agent may not
- Spend or approve on its own
- Invent a tool
- Continue after a person has taken over
What changes an agent
The tools
Read, draft, and write are different powers. Write needs a confirmation that matches the risk.
The stop
A low-confidence step should wait. Silence is not success.
The log
Someone has to be able to see what the agent read and what it changed.
What an agent brief needs
- 01
The task
One kind of work, not a general assistant.
- 02
The tools
Read, draft, or write. Write needs a confirmation.
- 03
The stop
When it should wait for a person.
- 04
The log
Who will read what it did.
Marks an agent is bounded
- 01
It can stop
The agent has a condition that ends the run, including “ask a person”.
- 02
Tools are listed
It can call only the actions that were allowed, not whatever the model suggests.
- 03
Money waits
A payment, a message to a customer, or a delete needs a person.
- 04
A run replays
What it read and what it did can be inspected after the fact.
What we build
Task design
A written job, success check, and stop conditions.
Tool layer
Functions the agent may call, each with authorization outside the prompt.
Supervision
Queues for approval, and a kill switch when a run misbehaves.
Evaluation
Scripted tasks that must keep passing after you change the model.
How an engagement runs
- 01
Shadow the task
Watch a person do it and list the systems they touch.
- 02
Automate the read path first
Gather and draft before you allow writes.
- 03
Allow one write with approval
Expand only after the logs are trustworthy.
Related reading
Questions we hear
What is an AI agent?
A system that uses a model to decide a sequence of steps and then calls tools to carry them out. The guide What is an AI agent covers the idea and the limits.
Can an agent talk to customers?
That is usually a chatbot or assistant with a narrower brief. An agent that messages customers without a template and a policy is a reputational risk we will not ship.
Will agents replace our team?
They remove repetitive preparation and lookup. Accountability for the outcome stays with a person you name. We design for that, not for an unmanned department.


