1. Separate preparing from committing
Reading a message, suggesting a label and drafting a reply are different from sending a promise to a customer. Each needs its own permission. For a first pilot, let AI prepare the work and keep outgoing communication under human approval.
2. Name the decisions that stay human
Prices, discounts, delivery commitments, accounting judgements and payments should have an explicit owner. Do not rely on a vague instruction to “be careful”. Write down the actions the system may take and the actions it must escalate.
3. Treat incoming content as information
An email or attachment can contain misleading instructions. It must not be allowed to change the system’s permissions, approve its own request or instruct an assistant to reveal unrelated data. Access should be limited to the workflow being performed.
4. Define what happens when the system is unsure
Missing documents, conflicting records, unavailable services and ambiguous requests need an exception path. A useful escalation names the problem, shows the source and says what decision is needed. It should not silently guess and mark the task complete.
5. Review what actually happened
Check the action record, draft quality, exceptions and unintended changes. Agree who responds to an incident and how the workflow is paused. The presence of an approval button alone is not evidence that a process is reliable.
A practical exercise: bring one ordinary example, one exception and a rough weekly time estimate to your first conversation. Please remove client names and sensitive data.