Agents
How to set permissions for AI agents in a business
By Julián Medina · Director of SourcingUp and creator of CommerceUp
Grant permissions according to the task and the consequences of each action. Reading information, preparing a change and applying it are separate capabilities. Each needs a clear scope and someone on the team responsible for it.
Separate the actions
An agent that reads the catalog does not need permission to change prices. One that drafts replies does not need every customer record. Define the actions and resources each task requires. Enforce those choices in the tools themselves, as well as describing them in instructions.
Place approval where it matters
For example, an agent could propose an updated product description for a person to publish. Repetitive, reversible actions may justify a different level of autonomy. The important points are that approval happens before a commitment is made and that the reviewer can see the entire proposed change.
Prepare for recovery
Record the action attempted, the tool response and the resulting state. Define how to suspend access and reverse or correct changes where possible. A tool failure should not trigger endless retries of an action that may already have succeeded. Revisit permissions whenever the process changes.
Put it into practice
- List allowed actions and resources.
- Separate reading, proposing and executing.
- Define who approves sensitive changes.
- Review logs and access when changing the task.
The thinking behind this guide
A guide by Julián Medina. The scenarios are illustrative, not measured customer outcomes. My work at SourcingUp.