Note · AI Implementation Strategies

Giving an AI agent authority to answer clients:what I hand over and what I keep

David He, FounderOctober 7, 20265 min read

My agent sends the messages I never edit and holds anything about money or contracts. How 548 of my own approvals set that line.

My AI agent now sends the kinds of messages my own approval history says I never change, and it holds anything about money or commitments for me. Here is how I decided where that line sits, and the if-then playbook that keeps it there.

Responsibility without authority

On Tuesday the person running Launchpad, the Greenville startup program I'm in, told our cohort that you can't expect somebody to take responsibility for a job unless you're willing to give them the authority to get it done. And when someone still gets it wrong, the first questions are about you: did I communicate that well, and did I give proper instruction?

For months I'd done exactly that on one job my AI agents do. In the rest of my work they already have that authority. They write code, research, and run long tasks without me watching. But with my emails and texts to clients and vendors, they only draft. The models are cautious by default, and I'd added a written rule that every message needs my approval twice: once on the draft, and again before it's sent.

I knew I could loosen it. I didn't trust them enough. One wrong reply could commit me to a contract or put off a client I couldn't afford to lose.

62% went out without a single edit

Last week my agent went through my session logs. Between June and October I approved 548 messages it drafted for me. 338 of them, 62%, went out exactly as first written.

The split by kind was the useful part:

  • Simple acknowledgments and thanks: 32 of 37 sent unchanged (86%).
  • Scheduling and time confirmations: 39 of 50 (78%).
  • Money, pricing and contracts: 34 of 72 (47%).
  • Public posts: 8 of 25 (32%).

When I did change a draft, the most common reason was a fact only I knew (41 times). Next came a fact that was invented or wrong (24), then tone (19). Those are the things an approval step exists to catch.

One more finding. All 10 execution errors in that period happened after I had already said yes: a duplicate send, a missing attachment, a message that never left, a wrong channel. My second approval wasn't where the safety came from. Checking at the moment of sending mattered more.

So I rewrote the rule: the agent sends the kinds I never change, and I keep the rest.

A playbook of if-then rules

Tuesday's line pushed me further. Replying was one thing. I also wanted the agent to take the actions I would take, without handing over the decisions that matter. That afternoon I asked my agent how to let it act as well as reply, and it suggested a playbook.

A playbook is a short list of rules, each written as: when this happens, do this, and check it worked this way. A few of mine:

  • If a client says thanks, reply.
  • If they ask about price, hold it for me.
  • If it's anything sensitive, say the message arrived, then wait for me.
  • Anything else: hold it for me.

Two things keep it inside the lines. I read every rule before the loop starts and move anything I'm unsure about to the hold side. And my standing limits beat any rule: money, credentials, deletes, live systems and deploys stay with me, whatever a row says.

What it looks like in practice

I call the skill reply-loop. Once I approve the playbook, it checks the conversation on a schedule I pick, anywhere from every 10 minutes to once an hour. Messages that are safe, and that I would have sent unchanged, get answered without me. For anything sensitive it can still confirm it got the message, then it waits for me to make the call.

On Tuesday evening a client asked whether her app could get a home-screen icon. The loop found the answer in her code and replied on its own. Later that evening she asked how to pay me, and it held that one for me.

Four loops are running now, on four projects, and nothing stops me from running ten. I don't switch between them. I check back later and read what they did. They help most on work with a lot of back and forth.

Where the second brain comes in

How does an agent know what I'd say? My second brain, one of the tools I've been building: a searchable place with my notes, emails, call transcripts and decisions. Before that loop replied, it had the transcript of our call and my notes on what I'd agreed to. It's the same store my agent used to catch a payment I hadn't billed.

I think every person and every business needs one. It doesn't mean handing the agent all control. I still decide where its authority ends, and the second brain gives it a clear picture of my goals, preferences and intentions inside that line.

It still makes mistakes now and then. I think it makes far fewer than a person would in the same spot, especially one without the context. And when software acts for your business, what it says and does is yours to answer for. I wrote more about that in who answers when an AI agent acts for you.

If you want to try it

You can try this without my setup. Here's what I did: I counted which messages I approve without changes, handed those over first, and kept anything about money or commitments for myself.

It's early, and so far the results have been great. I'll write an update once it has run longer.

What's something you were afraid to delegate to AI, and glad you did?

More notesnewest first

Working on something like this?

Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.