← All briefings

Before You Let an AI Agent Send, Approve, or Spend: Build These Four Controls

AI agents are moving from suggesting work to approving, sending, changing, and spending.

The Operator Signal


AI agents are moving from suggesting work to approving, sending, changing, and spending.


That creates a practical question for every owner-operator:


How much authority should an AI system receive before it has proved that it can handle the work safely?


Recent product updates point toward the same operating model:


1. Keep sensitive information outside the agent’s reach.

2. Separate recommendations from binding approvals.

3. Retain enough activity history to investigate abnormal behavior.

4. Put a hard ceiling on financial exposure.


The decision is not whether to automate everything or nothing. It is whether to give each workflow the smallest useful combination of data access, permissions, and budget.


For most small and midsize businesses, the right starting point is a draft-only agent. It may collect approved information, classify a request, and prepare a response. A person remains responsible for sending the message, changing a record, promising a price, moving money, or approving consequential work.


That may sound cautious. It is also the fastest way to learn where an agent is dependable without placing the whole business inside the test.


What Changed


1. GitHub added content exclusions to more agentic surfaces


Event: On September 2, GitHub announced that content-exclusion policies now apply to the GitHub Copilot app and Copilot CLI for Business and Enterprise customers. Administrators can designate files that Copilot should not use as context.


Verification status: Confirmed product update. GitHub’s changelog and documentation both describe the feature. The documentation also identifies important limitations.


Excluded files are not supposed to inform Copilot responses, inline suggestions, or code reviews. However, GitHub warns that semantic information may still arrive indirectly through an integrated development environment. Content exclusions also do not currently apply to symbolic links or repositories on remote filesystems. Support varies by product surface, and exclusions are not supported in some editor agent modes.


Why it matters: “The agent cannot see this” is stronger than “we instructed the agent not to mention this.”


That distinction applies beyond software development. A business assistant preparing customer follow-up should not receive payroll records, unrelated customer folders, complete accounting exports, personal mailboxes, or master credential files merely because those sources are technically available.


Prompt instructions are behavioral guidance. Access controls determine what information can enter the workflow at all.


Act / Watch / Ignore: ACT


Create an explicit exclusion list before connecting an AI tool to shared drives, email, a CRM, project folders, or an internal knowledge base. Then test the exclusions through every interface employees will actually use.


Do not assume that a restriction configured in one application automatically follows the data into every plugin, agent mode, connector, copied document, or linked folder.




2. GitHub now lets administrators authorize AI approval of pull requests


Event: On September 1, GitHub placed Copilot pull-request approvals in public preview. Copilot can provide a nonbinding assessment by default. Administrators may separately enable it to submit an approval that counts toward a repository’s required-approval rule.


The authority can be controlled at enterprise, organization, and repository levels. Repository administrators can also restrict the file paths Copilot may approve. If the underlying work changes after approval, GitHub dismisses the approval and requires a new review.


Verification status: Confirmed public-preview feature. It is not enabled by default and remains subject to change.


Why it matters: The consequential part is not that AI can review work. AI systems have been producing recommendations for some time. The important change is that an administrator can allow the AI’s judgment to satisfy a formal control.


This distinction appears throughout ordinary business operations:


Drafting a customer response versus sending it

Recommending a refund versus issuing it

Flagging an invoice versus approving payment

Suggesting a schedule change versus notifying customers

Preparing a quote versus committing the company to its terms

Identifying a record correction versus overwriting the source system


GitHub’s structure offers a useful governance pattern: start with a visible assessment, keep binding approval off by default, scope any later authority narrowly, and invalidate the approval if the underlying work changes.


Act / Watch / Ignore: WATCH, THEN ACT SELECTIVELY


Use AI recommendations now where they help a person review faster. Delay approval authority until the workflow has a stable test set, clear ownership, reliable logs, and a defined rollback process.


If approval authority is eventually enabled, restrict it to low-risk categories. An agent might approve standardized internal formatting or tagging while remaining unable to approve payments, contracts, pricing, customer-facing commitments, permission changes, or deletions.




3. Anthropic proposed customer-controlled monitoring for sensitive agent activity


Event: On September 1, Anthropic announced Enterprise Frontier Safeguards, or EFS. The company says the forthcoming system will combine zero-data-retention privacy with automated misuse monitoring by storing relevant activity data in cloud infrastructure controlled by the customer.


Anthropic says customers will be able to use their own storage, encryption keys, access policies, and audit logging. Automated systems would analyze a rolling window of activity and route significant flags to the customer. The customer’s authorized personnel—not Anthropic employees—would perform any required human review.


Verification status: Confirmed announcement; availability remains pending. Anthropic says EFS will roll out in phases beginning later in the fall. Its performance and operational fit cannot yet be independently confirmed from this announcement.


Anthropic also makes a broader company claim: detecting sophisticated misuse may require correlating activity across sessions and accounts rather than evaluating each interaction in isolation.


Why it matters: Privacy and monitoring are sometimes treated as opposites. Operationally, businesses often need both.


Deleting every trace immediately can make it difficult to answer:


Which agent accessed a record?

Under whose authority did it act?

Did one unusual request become a pattern?

Were credentials or permissions abused?

What information reached the model?

Who reviewed the alert?

What changed after the incident?


Keeping every transcript forever is not the answer either. Logs may contain confidential customer information, employee data, legal material, security details, or commercial plans.


The useful design principle is controlled, purpose-limited retention: keep only what is needed for audit and incident response, store it in an approved location, restrict who may review it, and delete it according to a written schedule.


Act / Watch / Ignore: ACT ON THE PRINCIPLE; WATCH THE PRODUCT


Do not wait for a particular enterprise platform before improving logs. For each agent, record the request, data sources used, proposed action, approval decision, final action, timestamp, and responsible identity.


Avoid logging secrets or full sensitive documents when an identifier, hash, classification, or redacted excerpt will serve the audit purpose.




4. Google introduced harder financial boundaries for agent workloads


Event: On August 26, Google Cloud announced additional billing options and cost controls for Gemini Enterprise agent workloads.


Google says customers can use project-level monthly spend caps, automated alerts, anomaly detection, centralized reporting, and configurable overages. When a project reaches its cap, agent API calls can pause without taking down unrelated production infrastructure. Google also announced pay-as-you-go options, pooled quotas, savings plans, and future discounted execution for workloads that can wait.


Verification status: Confirmed Google product announcement. Some capabilities are available now, while others are limited to selected customers, rolling out, or labeled “coming soon.” The savings and performance descriptions are Google’s claims and depend on workload and contract terms.


Why it matters: An agent may create an open-ended cost loop even when every individual call is inexpensive.


Examples include:


Reprocessing the same inbox repeatedly

Retrying a failed integration without a limit

Researching more sources than the decision requires

Generating long drafts that no one reads

Calling multiple models for a low-value task

Running continuously when a daily batch would be sufficient

Triggering one automated workflow from another


Traditional subscription budgeting is not enough when usage changes with task length, retries, tools, retrieved documents, and model selection.


Every production agent therefore needs two budgets:


A financial budget, such as a maximum daily or monthly cost

A work budget, such as maximum records, retries, tool calls, or minutes per run


A spend cap without an operational stop condition may merely pause a broken process after wasting the full allocation.


Act / Watch / Ignore: ACT


Set caps before volume testing. Track cost per completed, human-accepted outcome—not merely cost per model call.


Treat any unexplained usage spike as an operational incident until the cause is understood.


The Business Problem This Creates


Many businesses do not have one clean workflow. They have a chain of informal decisions distributed across inboxes, spreadsheets, software permissions, and employee judgment.


Consider a new sales inquiry:


1. A message arrives through a form, email, or social channel.

2. Someone determines whether it is legitimate.

3. The business checks service area, availability, customer history, and pricing rules.

4. A response is written.

5. A promise is made about timing, scope, or cost.

6. The lead is assigned and follow-up begins.

7. Notes are stored for the next person.


An AI agent may improve several steps. But connecting it to the entire chain at once combines different kinds of risk:


Privacy risk: It may retrieve information unrelated to the lead.

Accuracy risk: It may misunderstand a request or use an outdated policy.

Authority risk: It may send language that commits the business.

Security risk: A malicious message may attempt to manipulate its instructions.

Financial risk: It may consume resources through excessive research or repeated processing.

Management risk: No one may know whether the agent, an employee, or an integration made the final decision.


The solution is not a longer prompt. It is workflow separation.


A well-controlled system distinguishes between:


Data the agent may retrieve

Data the agent must never retrieve

Recommendations the agent may prepare

Actions only a person may approve

Low-risk actions the agent may eventually perform

Events that suspend automation immediately


The same boundaries should apply whether the tool is called a copilot, assistant, workflow, bot, or agent.


Workflow to Test


A two-week, draft-only lead-response experiment


Choose one inbound channel and one narrow type of inquiry. Do not begin with complaints, emergencies, regulated advice, custom contracts, or high-value quotes.


Input


Provide only:


The prospect’s submitted name and contact details

The original inquiry

A current list of approved services

Public service-area information

Approved business hours

A reviewed FAQ

A standard response style

The minimum CRM context needed to detect an existing relationship


Exclude unrelated customer histories, full mailboxes, payment data, employee records, internal financials, credentials, private notes, and documents that have not been approved as source material.


AI task


Ask the system to:


1. Classify the inquiry as relevant, uncertain, spam, or out of scope.

2. Identify missing information.

3. Retrieve supporting language only from the approved knowledge set.

4. Draft a response.

5. Cite the policy, FAQ entry, or source passage it used.

6. Flag any request involving price exceptions, legal terms, refunds, safety, sensitive data, or firm scheduling.


The agent does not send anything.


Human approval


A designated employee reviews:


Whether the classification is correct

Whether the cited source supports the draft

Whether the response makes an unauthorized promise

Whether private information was unnecessarily included

Whether the inquiry contains suspicious instructions or attachments

Whether the CRM note is accurate and appropriate


The person edits as needed and sends through the normal business account.


Success measure


Measure:


Percentage of drafts accepted without factual correction

Median review time compared with the prior process

Percentage of inquiries correctly routed

Number of unauthorized claims or promises

Number of privacy or permission violations

Cost per approved draft

Follow-up completion rate


A faster draft is not a successful outcome if employees must recheck every fact from the beginning.


Stop condition


Pause the experiment immediately if the agent:


Exposes restricted information

Sends or changes records without approval

Invents a price, policy, availability, or commitment

Fails the same critical scenario twice

Follows instructions embedded in an untrusted message instead of the approved workflow

Exceeds its daily work or cost limit

Produces logs that are insufficient to reconstruct what happened


After a stop, preserve the relevant audit record, revoke unnecessary access, identify the failure path, and retest before resuming.


Who should use it


This test fits businesses with repeatable inbound inquiries, a reviewed service definition, and an employee who already owns lead response.


Who should not use it


Do not use this design as-is for medical, legal, financial, crisis, emergency, employment, or safety-critical decisions. It is also a poor fit for businesses whose prices, policies, or service areas are not documented accurately. In those cases, fix the source material before automating the response.


What Must Stay Private or Human-Approved


Keep these data categories restricted


Passwords, API keys, recovery codes, and private encryption keys

Payment-card and banking information

Government identifiers and identity documents

Health, employment, disciplinary, and background-check records

Private customer communications unrelated to the active task

Complete accounting or payroll exports

Legal advice and privileged material

Security architecture, incident details, and vulnerability information

Confidential pricing logic, contract terms, and negotiation notes

Personal files or mailboxes that are not business records

Any data collected without a defined business need and retention policy


Where access is necessary, use the smallest relevant record rather than the full system.


Keep these permissions narrow


An agent should not inherit an owner’s administrator account. Give it a distinct identity with:


Read-only access by default

Access limited to named folders, records, or fields

Short-lived credentials where supported

No ability to create new users or permissions

No unrestricted export capability

No deletion rights during initial testing

No access to production and test systems through the same credential

Logs that identify actions as AI-assisted or AI-initiated


Review permissions whenever the workflow changes. An agent approved for one task should not quietly accumulate authority as new integrations are added.


Require a person for consequential commitments


Human approval should remain mandatory for:


Sending quotes with nonstandard prices

Signing or accepting contracts

Issuing refunds, credits, or payments

Changing bank, payroll, or tax information

Hiring, firing, discipline, or compensation decisions

Publishing public claims

Responding to threats, complaints, or legal notices

Changing permissions or security settings

Deleting business records

Contacting a customer about a sensitive matter

Overriding a budget or automation stop condition


An approval is meaningful only if the reviewer can see the source information, proposed action, reason, and likely consequence.


One Operator Decision


Implement a permissions-and-approval register before giving any AI agent a new connection.


For each workflow, record:


Business owner

Approved purpose

Permitted data sources

Excluded data

Allowed tools

Maximum authority

Required human approvals

Financial and work budgets

Log location

Retention period

Stop conditions

Credential owner

Date of the next review


If those fields cannot be completed, keep the agent in draft-only mode.


This register can begin as a one-page document. Its value comes from forcing a precise answer to the question that matters: What could this agent actually do if it misunderstood the task, received a malicious instruction, or used every permission available to it?


Repurposing Hooks


Podcast opening question:

When does an AI assistant stop being a productivity tool and become an employee-like operator that needs formal limits?


YouTube hook:

Before connecting AI to your inbox, CRM, or billing system, set four controls: exclusions, approval boundaries, audit logs, and a hard budget.


Three quotable takeaways:


“A prompt tells an agent how to behave; a permission determines what it can actually do.”

“Measure AI cost per approved business outcome, not per model call.”

“The safest first agent prepares the decision without owning the consequence.”


Source Index


AnthropicSeptember 1, 2026 - Announced customer-controlled storage, automated monitoring, customer-managed review, and a phased future rollout for Enterprise Frontier Safeguards.

GitHub ChangelogSeptember 2, 2026 - Confirmed that Copilot app and CLI now respect administrator-configured content exclusions for eligible business plans.

GitHub DocsAccessed September 3, 2026 - Documented what exclusions cover, which product surfaces support them, and limitations involving indirect semantic context, symbolic links, remote filesystems, and certain agent modes.

GitHub ChangelogSeptember 1, 2026 - Confirmed public-preview AI approval authority, default-off configuration, file-path scoping, and dismissal of approval after new changes.

Michael Gerstenhaber and Pravir Gupta, Google CloudAugust 26, 2026 - Announced project spend caps, anomaly alerts, overage controls, consolidated reporting, and additional billing models for agent workloads.

From news to practical action

Find the first workflow worth improving.

Tell Bizamate where work gets stuck. We will help identify a practical first workflow, the knowledge it needs, and what should remain human-approved.

Request a Workflow AssessmentStart with one workflow and one clear next step.