Permission follows the task
Decide which sources the system may read and which actions it may take. Separate read access from write access, and avoid giving an agent broad permissions simply because an integration supports them.
Make human authority visible
Specify the decisions that remain with people. A high-impact action, conflicting instruction or low-confidence result can trigger a review queue instead of automatic execution.
Ground answers in approved evidence
For knowledge workflows, retrieve approved sources, respect access boundaries and show supporting references. If evidence is insufficient, the system should say so and offer an appropriate escalation.
Plan data handling before connecting systems
Identify the information being processed, approved providers, retention expectations and hosting requirements. These are project decisions, not assumptions or blanket promises of compliance.
Measure failures as well as success
Track incorrect answers, inappropriate actions, failed tool calls and escalations alongside speed and cost. An audit trail and recovery plan help the operational owner respond when something goes wrong.
