Every demo of an AI assistant shows the same thing: fluent, tireless, doing. It drafts the email, sends the reply, updates the file, books the meeting. The audience leans in. Then someone in operations asks the only question that matters: what happens when it is wrong?
We build AI employees for small businesses, and the design problem is not making the AI capable. The models are capable. The problem is drawing the line between what the system may do on its own and what it must ask about first — and making that line visible to a person who does not read changelogs.
The rule we ship with is simple to state: the AI acts freely where a mistake is recoverable, and asks before anything consequential. Consequential means it leaves the business, spends its money, or changes its records. Sending mail. Moving files. Anything a customer would notice. Inside that boundary the AI works unsupervised; at the boundary it stops, states what it is about to do and why, and waits.
That pause is not a limitation bolted on for safety theatre. It is the feature. An assistant you have to watch is not an assistant; an assistant that never asks is a liability wearing a friendly voice. The pause is what lets an owner hand over the inbox at all.
Two details do most of the work in practice.
First, the ask has to be small. If the approval prompt reads like a contract, people approve without reading, and the gate is decorative. We hold it to a sentence of intent — what the system is about to do, to whom, and what made it decide — because that is the amount of context a busy person will actually weigh.
Second, every action gets an audit record, whether it was approved or done freely. Not a log file somebody might grep one day: a readable trail of what the system did, when, and on whose say-so. When something looks wrong next Tuesday, the question "what did the assistant touch?" has to take ten seconds to answer. The trail is also how trust compounds — the second month of running an AI employee is calmer than the first, because the record was there when something needed checking.
The same discipline shows up where AI answers the phone. Our receptionist product answers every call in a natural voice, and its greeting says plainly that the call is answered by an AI. That sentence costs nothing in fluency and buys the one thing a caller owed: the truth about who they are talking to.
If you are thinking about putting an AI to work inside a business, resist asking how much it can do. Ask where it stops. The answer to that question is the product.
- #ai-agents
- #approvals
- #audit-trails