Intermediate level8 min readTo learn at another level, choose it before you start the course.

After this lesson you canDecide whether a task is safe to hand to an agent, and set the access, approvals, limits and logs it needs.

The short answerLetting an agent act for you is a risk decision: weigh what it can reach, how easily its actions can be undone and how you will notice mistakes. Least access, approval for high-impact actions, spending limits and logs make most everyday uses reasonable.

In simple words

  • Rate the access: which data and accounts can the agent reach?
  • Rate the actions: can they be undone, and what does a mistake cost?
  • Control: least access, approval for high-impact steps, spending limits.
  • Notice: logs, alerts and regular checks of what it did.
Check an agent before you let it actIllustration
What can the agent do?
What protects you?

Risk: High

It can do things that are hard to undo without asking you first.

  • Make it ask you before it pays, deletes or sends in your name.
  • Set a spending limit on the card or wallet it uses.
  • Choose an agent that shows a log of every step, and check the first runs.
A simple guide built on OWASP’s advice and OpenAI’s guide to agents, not a security audit. Tick what the agent can do and what protects you; the advice changes with your answers.

Words to know

Irreversible action
A step that cannot be undone, such as paying or sending a message.
Read-only access
Permission to look at data, but not to change, delete or send it.
Log
A record of every step an agent took, so you can check its work.

Map what it can reach

List every account, file and tool the agent will use. Private data plus text from strangers plus a way to send data out is the mix that makes prompt injection dangerous.

Prefer narrow, read-only access, such as one folder instead of your whole drive. Remove access when the task is done.

Sort actions by how easily they are undone

Reading and drafting are easy to undo. Sending, paying, deleting and posting are not. OpenAI’s guide says sensitive, irreversible or high-stakes actions should involve a person until the agent proves reliable.

A practical rule: let the agent prepare everything, and keep the final click for yourself when money, messages or deletions are involved.

Make mistakes visible

Choose agents that show a log of every step and tool call. Check the first runs closely, then sample later ones, and set alerts for payments or new contacts.

Set hard limits: a spending cap, a maximum number of steps and a time limit. They stop a confused agent before it does much damage.

At work, rules apply

In the EU, businesses must help staff who use AI for them understand it well enough to use it safely; this duty is called AI literacy. Since August 2, 2026, AI systems that talk with people must tell them they are talking to an AI, unless that is obvious.

In the US, calls with AI-generated voices need the called person’s prior consent under federal robocall rules. California also bans bots that pretend to be human to sell things or influence votes, and a company there cannot defend itself in court by saying its AI acted on its own.

Try it yourself

Pick a task you might give an agent, and tick what it could do in the checklist. Then tick what protects you, and read how the risk and the advice change.

Check yourself

  1. Your agent handles supplier invoices. Following OpenAI’s guide, which step should wait for a person?

  2. An agent needs to sort the files in one project folder. What access should it get?

  3. Overnight, your agent kept retrying a failing booking site hundreds of times. Which setting would have stopped it?

Back to the path

Sources

This lesson was generated by AI systems under the editorial rules of Silicon AI News and checked against the sources it lists. The live parts come from our checked stories, trackers, model comparison and rules checker.