Design the permissions
For your own agent workflow, start by deciding which resources the system may read and which it may change. A research task may need read access without permission to send messages, change account settings or publish results. Assign those capabilities explicitly.
Keep sensitive credentials out of prompts and ordinary tool output. Use a separate working environment for repository or data changes. If an action affects a real user or production system, put the appropriate review step at that boundary.
Treat retrieved material as source material
Documents, web pages and repository text may contain instructions aimed at the agent. A retrieved sentence should not automatically acquire the authority of the person who assigned the task. Design your workflow so source content can inform an answer without silently expanding permissions.
Check tool arguments and destinations before consequential actions. Keep a record of actions so a reviewer can distinguish what the model proposed from what the system actually executed.
Define when to stop
Set a time or spending budget and an observable completion criterion. Stop and request review when the agent encounters missing permissions, contradictory evidence or an outcome that it cannot verify. Repeated attempts should not quietly turn into broader access.
For code, a completed task should include a reviewable diff and independent checks. For research, it should include supporting sources and unresolved questions. For long workflows, save intermediate state so interruption does not erase the record of what happened.
Evaluate control as well as capability
A strong result is only one part of adoption. Check whether the system stays within the assigned task and whether a person can inspect, correct and stop it. Our agent explainer connects these decisions to the planning and verification loop.