Direct answer
An AI agent can gather approved context, choose among allowed tools, transform or compare information, prepare decisions, update records, create tasks, send approved communications, and monitor follow-through. Every capability should be limited by job, identity, data, tool, action, amount, time, cost, and escalation rules.
Action-scope planner
Move one proposed job up the action ladder
Minimum control package
Decision criteria
This scope keeps a person responsible for the final business action.
Capability ladder
Each step outward needs stronger evidence and control
| Level | Example | Primary control |
|---|---|---|
| Read | Retrieve approved account and policy information | Identity, source, and field-level access |
| Prepare | Draft a brief, task, response, or transaction | Evidence display and human review |
| Recommend | Choose a route or next action | Decision criteria, confidence, and exception rules |
| Write | Update a CRM field or create a project task | Scoped credentials, validation, idempotency, and rollback |
| Send | Communicate or trigger an external action | Authorization, identity, rate limits, complete audit, and recovery |
What you will decide
Capability is useful only inside a job contract
- Define the business outcome before choosing tools.
- Give the agent only the sources and actions needed for that outcome.
- Separate preparing a decision from authorizing it.
- Require the system to return evidence and uncertainty with consequential work.
- Preserve a complete trace of tool use, changes, errors, and escalation.
Good jobs
Agents fit bounded work with a variable middle
The start and finish should be clear even when the steps vary. An agent can decide which approved source to search, which tool to use next, or which missing input to request, while remaining inside the same job.
| Job | Agent contribution | Boundary |
|---|---|---|
| Research brief | Search approved sources, compare evidence, and structure findings | Cite sources and stop when evidence is insufficient |
| Queue resolution | Investigate routine cases and complete approved fixes | Escalate novel, sensitive, or high-impact cases |
| Sales preparation | Gather account context and prepare a meeting brief | Do not invent facts or contact the buyer without authority |
| Document intake | Read, validate, request missing items, and update status | Do not make the consequential eligibility decision |
| Internal coordination | Create tasks, gather updates, and summarize blockers | Do not change priorities or commitments without an owner |
Poor jobs
Do not give an agent ambiguity plus broad authority
- An open-ended goal with no measurable completion condition.
- A job that depends on tacit expert judgment the system cannot verify.
- A decision that materially affects employment, safety, legal rights, credit, health, or finances without qualified oversight.
- Access to whole systems when a narrow read or write scope would work.
- Permission to send external communication without identity, policy, rate, and review controls.
- A process with no owner available to review errors and improve it.
Execution evidence
A useful agent should leave a business-readable trace
Received
Record the job, requesting identity, time, and starting inputs.
Retrieved
Record which approved records and source versions were used.
Decided
Record the policy, confidence, and reason for the selected next step.
Acted
Record every tool call, field change, message, and external response.
Escalated
Package the uncertainty, attempted steps, evidence, and required decision for a person.
Completed
Record the outcome, validation, cost, duration, and any human correction.
Success
Measure completion quality and operating burden together
- Correct completion rate
- Unnecessary-action rate
- Escalation precision and completeness
- Human correction time
- Tool and integration failure rate
- Cost and latency per completed job
- Customer or employee outcome
- Near-misses, policy violations, and rollback events
The value point
After this page, you should be able to decide:
Which action level creates enough value and remains controllable for the proposed job.Your working output should be an action ladder, capability map, good-job filter, poor-fit warning list, execution trace, and control package.
Questions business leaders ask
Frequently asked questions
Can an AI agent use our CRM and email?+
Yes, when integrations and account policies allow it. Use a dedicated identity, minimum permissions, approved fields and actions, rate limits, logs, and human approval for sensitive communication.
Can an AI agent make decisions?+
It can make bounded operational selections or recommendations under policy. Consequential decisions should remain accountable to qualified people and applicable organizational and legal requirements.
Can an agent work without supervision?+
It can complete low-impact routine work within tested limits, but production agents still need monitoring, escalation, ownership, incident response, and periodic evaluation.
What is the best first agent use case?+
Choose a frequent internal job with clear completion, narrow tools, low-consequence actions, abundant test examples, and fast expert feedback.
Research anchors
Primary and authoritative sources
- NIST AI Risk Management Framework↗
- NIST AI RMF Playbook: Map↗
- NIST AI RMF Playbook: Measure↗
- NIST AI RMF Playbook: Manage↗
- CISA Zero Trust Maturity Model↗
Examples and planning ranges are clearly labeled. Source terms, provider behavior, and regulations can change; verify current requirements for your organization and jurisdiction.
Prepared and reviewed by the Future Made Useful systems editorial team. Material guidance reviewed July 16, 2026.