Running AI safely
The Four Things I Let AI Do Without Asking Me
I let AI run parts of 3 companies. For a while it asked permission before every single thing it did, so I stopped reading the questions and started hitting yes. Now the work is split four ways: what AI does on its own, what it drafts and I approve, what it can only suggest, and what it's never allowed to touch.
The whole thing in fifteen seconds
- If AI asks permission for every little thing, you stop reading the questions. That's worse than no gate at all.
- Sort every job by one question: how bad is it if this goes wrong once and I can't undo it?
- Four groups: go ahead · show me first · just tell me · never.
- Writing the rule down isn't enough. If you've already broken it once, you need something that won't let you.
01
The mistake I made first
I gave it one setting. Ask me before anything.
Sounds careful. It isn't. Asking permission to read a file is not safety, it is friction, and friction is exactly what makes people stop looking. I never turned the gate off. I did the worse thing and left it on while I stopped reading it, so there was a gate on my screen and I had quietly started trusting it to catch things.
The fix was not a stricter rule. It was four groups instead of one.
02
The one question that sorts everything
Not "is this important." Not "is this risky." Those are feelings, and they move with your mood and with how your morning went.
What would it cost me if this went wrong once?
The question every job gets asked
That sorts on how hard something is to undo, which is the thing that actually matters. A wrong research summary costs ten minutes. A wrong email to a client costs the client. Same software, same confidence in its own answer, wildly different mornings.
03
The four groups
I can drop a new job into the right one in about five seconds, and so can anybody I explain them to, which is the only reason they've survived contact with a real week.
Sorted by what one mistake costs
The rubric I run three companies on
04
Three placements people argue with me about
Sending
Reading is free. Sending never is. Not a post, not a DM, not a reply to an email I've already read twice. Drafting is go-ahead. Sending is show-me-first. Permanently, and that one line has saved me twice.
Numbers
Numbers are not text. An unattended weekly report of mine once led with a red alert that a folder was 43% over capacity at 286 files. The real count was six. It also invented a scheduled job that does not exist and a meeting attendee who'd never accepted. I tried telling it more firmly. Twice. What finally worked was measuring the numbers first and giving it nothing to type them with.
Identity
Signing up as somebody else is never allowed. Not for a client, not to save an hour, not when they've handed me the password themselves and asked me to. I sign up as me and add them, or they sign up and add me. I don't type another person's identity into a form. Ever, for any reason, no matter how much faster it would be.
05
A rule is a wish until something enforces it
Here's the part that took me longest to accept.
I'd written the same rule down twice and broken it twice. The third time I stopped writing it down and built something that would not let me. A rule you've already broken once needs a mechanism, not a reminder, and the number of times you've written it down is a decent measure of how badly it's failing.
It runs the other way too. Go-ahead only works if you'd actually find out when it breaks, and that's a much bigger if than it sounds, because the thing that tells you it broke is also software.
Three of my own alarms told me everything was fine for three months. All three were reading from parsers that had quietly died months earlier, and one of them had never created its log file at all, not once, since the day I built it back in May and walked away satisfied. It printed "total misses: 0" every single week. I read that zero as proof it worked.
The rule
A sensor reading zero is not a green light. It might mean nothing is wrong. It might mean nothing is watching. Those look identical on a dashboard and they are opposite situations.
06
What I don't know
I don't know where this line sits in two years. Some of what I keep at show-me-first today is there because I haven't yet found a way to check the output automatically, not because a person genuinely has to look at it. If that check becomes possible, the work moves down a level and I'll move it.
What I'm confident about is the direction. The list of things a person must do stays short. It never gets shorter by accident.
07
So which one are you
Most people run everything at one setting. Either everything asks, so nothing gets done, or nothing asks, so nobody finds out.
Do this today
Write your never list
- Three or four things that never happen without you. A list, not a policy.
- Written somewhere another person on your team can actually read it.
- Anything that moves money, signs, sends on your behalf, or can't be taken back.
- Then check what you already have running unsupervised, and when its alarm last fired.
If you cannot remember one firing, you do not have an alarm. You've got a light that's always green.
Questions we get
How much should I let AI do without approving it first?
What should AI never be allowed to do?
Is it safe to let AI send emails for me?
Why did my automation say it succeeded when nothing happened?
How do I stop AI from making up numbers in reports?
Let's Build Your AiOS.
Book a call and you get your own version of this rubric: what runs unsupervised, what waits for you, and what never happens without you.
Book a callBlueprint → Build → Partner · Denver + remote