How much power should you give an AI agent?
AI agents get useful when they can access your actual work.
Your inbox.
Your calendar.
Your files.
Your CRM.
Your money.
But every new permission changes what happens when the agent gets something wrong.
Build an Executive AI Agent and see its blast radius.
CONNECTED TO
Executive Assistant
PURPOSE — Help an executive prepare for meetings, manage communications, coordinate their calendar, and keep internal systems updated.
Give your agent context
Read inbox
Agent can search and summarize email.
Read calendar
Agent can see meetings, attendees, locations, and descriptions.
Search company documents
Agent can retrieve files across approved folders.
Read internal conversations
Agent can search approved Slack channels.
Read customer records
Agent can view accounts, contacts, opportunities, and notes.
Let your agent take action
Changing the world is another.
Draft Email
Agent can write email drafts for the executive.
Send Email
Agent can send messages without approval.
Create Calendar Events
Agent can schedule meetings.
Cancel Meetings
Agent can cancel existing meetings.
Update CRM
Agent can modify customer records and opportunities.
Send Slack Messages
Agent can communicate internally as the executive.
Give your agent a credit card
Would you?
Make purchases
Allow agent to purchase approved goods and services.
- RREAD(solid thin)
- WWRITE(solid arrow)
- XEXTERNAL ACTION(dashed arrow)
- $MONEY(double stroke)
- ACCESS
- 2 systems
- AUTONOMY
- 1 / 10
- REVERSIBILITY
- High
- BLAST RADIUS
- Low
Looks useful.
- RREAD(solid thin)
- WWRITE(solid arrow)
- XEXTERNAL ACTION(dashed arrow)
- $MONEY(double stroke)
- ACCESS
- 2 systems
- AUTONOMY
- 1 / 10
- REVERSIBILITY
- High
- BLAST RADIUS
- Low
Would I ship this agent?
Yes, with monitoring.
Your agent currently combines:
- — 2 systems of access
- — 0 write permissions
- — 0 external actions
- — no financial authority
- — no approval gates
That combination determines how far a single incorrect interpretation can travel.
- DATA EXPOSURELOW
The agent can read 2 sources of context.
- ACTION AUTHORITYLOW
The agent cannot change anything yet.
- REVERSIBILITYHIGH
Nothing the agent does today is hard to undo.
- FINANCIAL AUTHORITYNONE
The agent has no spending authority.
- FAILURE PROPAGATIONLOW
A mistake stays close to where it started.
Don't ask, “Can the AI do this?”
Ask:
- 01What does it need to see?
- 02What should it be allowed to change?
- 03Which actions are reversible?
- 04Where should a human approve?
- 05What happens when it's wrong?
The goal isn't zero autonomy.
The goal is bounded autonomy.
Give AI enough authority to remove friction without giving one mistake unlimited consequences.
Same question, different authority
Switching the agent changes its systems, its permissions, and the way one bad Tuesday plays out.
This is how I think about AI systems before we build them.
Office Hours with Chanel
THINK CLEARLY. BUILD SAFELY. SHIP LIKE A SENIOR ENGINEER.
If you're deciding how much access an AI agent should have, evaluating an internal AI proposal, or figuring out where humans should stay in the loop, that's exactly what we can work through together.