Tool Boundary
List every tool the agent can call and the exact actions each tool can take.
A no-login launch screen for one agent workflow that can call tools, read untrusted context, use memory, browse pages, edit files, or trigger customer-visible actions.
List every tool the agent can call and the exact actions each tool can take.
Confirm service accounts, delegated users, and API permissions are limited to the one workflow.
Treat pages, tickets, docs, comments, emails, and tool output as data, not instructions.
Require approval before sends, posts, charges, writes, deletes, external calls, or user-visible changes.
Define what can persist, who can change it, and how poisoned context is removed.
Keep browser automation away from account, payment, payout, tax, identity, and credential pages.
Check whether prompts, tool-call traces, endpoint names, schemas, or errors reveal private internals.
Write down what the agent must never do, plus the escalation path for uncertainty.
Make sure there is a fast disable switch, owner, and recovery plan before launch.
If two or more answers are unclear, pause and tighten the workflow before increasing autonomy.
Do not send secrets, credentials, API keys, session cookies, card or bank details, private payment pages, customer records, private handles, full names, full transaction IDs, or private dashboard screenshots.
The AI Agent Launch Pack includes the local app, safe-intake builder, checklist materials, templates, and fictional sample report. The optional 24-hour review is still limited to one workflow.