An AI answer can be ignored. An AI tool call can change the customer record, send the message, issue the refund, expose the file, or touch production before anyone understands what happened. This manual begins with that external side effect. It does not assume an autonomous workforce, an enterprise governance committee, or a security team. One small-business workflow and one risky verb are enough.
The book shows how to inventory actions instead of broad tools; separate user intent from authority; distinguish direct reversal from compensation; use dedicated identities and narrow credentials; keep secrets outside model context; place policy in the execution path; create durable proposal and approval states; build a machine-action approval matrix; show reviewers the exact payload and original evidence; prevent duplicate and stale writes; reconstruct disputed actions; test recovery; enforce volume, amount, recipient, data, failure, and cost limits; and stop the system through a control the agent cannot change.
It also addresses the cost of human review. The reader learns when to prohibit, keep execution manual, gate, sample, or monitor-and what evidence is required before reducing approval. A one-week controlled-release protocol moves one action through observation, read-only work, proposal, boundary tests, duplicate tests, recovery, kill-switch testing, and a small live slice. The finished result is not a declaration that the agent is trustworthy.
It is one bounded action with a narrow identity, an enforced permission, an exact proposal, a durable approval state, a single execution, a useful log, a tested recovery route, and a stop that works.
An AI answer can be ignored. An AI tool call can change the customer record, send the message, issue the refund, expose the file, or touch production before anyone understands what happened. This manual begins with that external side effect. It does not assume an autonomous workforce, an enterprise governance committee, or a security team. One small-business workflow and one risky verb are enough.
The book shows how to inventory actions instead of broad tools; separate user intent from authority; distinguish direct reversal from compensation; use dedicated identities and narrow credentials; keep secrets outside model context; place policy in the execution path; create durable proposal and approval states; build a machine-action approval matrix; show reviewers the exact payload and original evidence; prevent duplicate and stale writes; reconstruct disputed actions; test recovery; enforce volume, amount, recipient, data, failure, and cost limits; and stop the system through a control the agent cannot change.
It also addresses the cost of human review. The reader learns when to prohibit, keep execution manual, gate, sample, or monitor-and what evidence is required before reducing approval. A one-week controlled-release protocol moves one action through observation, read-only work, proposal, boundary tests, duplicate tests, recovery, kill-switch testing, and a small live slice. The finished result is not a declaration that the agent is trustworthy.
It is one bounded action with a narrow identity, an enforced permission, an exact proposal, a durable approval state, a single execution, a useful log, a tested recovery route, and a stop that works.