An AI agent can prepare an email, reorganize a folder or help you shop online. But each task contains several different decisions. Writing a reply is different from sending it. Identifying duplicate files is different from deleting them. Comparing products is different from placing an order.
The useful question is therefore more specific than “Do I trust this AI?” It is: which actions should this agent be allowed to perform, on which resources, and under what conditions?
This guide proposes a practical starting policy for everyday delegation. The examples are editorial recommendations, not a description of permissions supported by every AI product.
Delegate individual actions, not entire accounts
An agent uses tools to work toward a goal, potentially choosing and adjusting its own sequence of steps. In its discussion of trustworthy agents, Anthropic explains that behavior depends on the model, its operating instructions, its tools and its environment.
For users, the implication is straightforward: a capable model does not compensate for an account with excessive permissions.
“Manage my inbox” leaves several questions unanswered. Can the agent read every conversation? Send replies? Forward attachments? Delete messages? Create forwarding rules?
Break the request into operations. An initial setup might allow the agent to summarize a selected set of messages and prepare replies, while keeping sending and mailbox settings outside its scope.
Our MCP explainer describes how assistants connect to external tools. A connection provides capabilities; you still need to understand which operations those capabilities permit.
A practical starting policy
Our suggested approach uses three levels: work the agent can perform within an agreed scope, actions requiring a preview and approval, and operations to keep outside routine delegation.
| Area | Allow within a defined scope | Review before execution | Keep outside routine delegation |
|---|---|---|---|
| Emails | Summarize selected threads and prepare drafts | Send replies, forward messages or add attachments | Change forwarding rules or account recovery settings |
| Files | Search approved folders and create working copies | Overwrite originals, move shared files or change sharing | Permanently delete large collections or alter backups |
| Purchases | Compare products and prepare a proposed basket | Place an order or accept a subscription | Change payment security or grant unrestricted spending |
These are starting boundaries, not universal rules. A repeatable, low-impact action may eventually qualify for limited automation. An unusual request involving sensitive information may require closer supervision even when it looks simple.
Emails: let the agent prepare, then inspect the commitment
Email assistance can save work before a message leaves your account. An agent could summarize an approved thread, identify unanswered questions and draft a response.
Sending introduces another consequence: someone else receives information or a commitment in your name.
Before approving an outgoing message, inspect the recipient address, CC and BCC fields, attachments and final wording. A display name alone is not enough to identify the destination.
Also check what the draft promises. A polite sentence can still commit you to a delivery date, accept a price or disclose something the recipient should not receive.
A useful instruction would be:
Read these three customer conversations and prepare a draft reply for each. Highlight missing information and any proposed commitment. Do not send, forward or attach files.
For recurring messages, limited automatic sending may be worth considering when the recipients, template and permitted content are fixed. Define exceptions that must stop the workflow, such as a new recipient, an unexpected attachment or a request to change payment details.
Files: make recovery part of the task
“Clean up this folder” is a poor instruction because “clean” could mean renaming, moving, compressing or deleting files.
Start with an inventory and a proposed change list. For example, ask the agent to group documents by topic and identify suspected duplicates without modifying the originals.
When editing is useful, our preferred starting pattern is to create a working copy in a designated output folder. This makes it easier to compare the result with the original before replacing anything.
Be particularly careful with shared folders. Moving a file may affect another person’s workflow. Changing its access settings may expose information even though the file itself remains intact.
Before approving a batch operation, review:
- The exact folder and files involved.
- The proposed action for each group.
- Whether originals will remain available.
- How you would recover from an incorrect change.
“Move to trash” and “permanently delete” should be separate permissions. If recovery depends on version history or backups, verify that those protections actually exist before relying on them.
Purchases: approve the complete transaction
An agent can help turn a vague shopping need into a comparison of suitable options. Our recommendation is to keep the final transaction separate from that research.
A product price is only one part of an order. Before approving payment, check the exact item and variant, quantity, seller, delivery address, shipping charges, currency and final total. Check whether the transaction includes recurring billing.
Consider this hypothetical request:
Find three compatible replacement cartridges for this printer. Compare the total delivered price and explain how you checked compatibility. Do not purchase or start a subscription.
Once you choose an option, the approval should refer to that specific order. If the seller, item or total changes before checkout, the agent should return for a new decision.
For routine replenishment, a narrow standing authorization could be more practical: approved products, approved sellers, a spending ceiling and a maximum order frequency. Only use this arrangement if the service can enforce those limits.
A small per-order limit is insufficient by itself. Repeated purchases can still create a large total.
Use permissions that enforce your instructions
Microsoft’s guidance on least privilege for AI agents recommends limiting access by resource, data and operation, with clear ownership and regular permission reviews.
Applied to everyday tasks, that could mean access to one project folder rather than an entire drive, or permission to create drafts without permission to send them.
A written instruction such as “never delete files” expresses your intent. It is not equivalent to removing the deletion capability from the connected account.
Before connecting a service, inspect the permissions it requests. If the available connector bundles broad access that you cannot narrow, consider supplying selected documents manually or choosing a more limited workflow.
The same principle applies to time. A one-off task should not automatically become a reason to leave extensive access enabled indefinitely.
Read access still deserves attention
Preventing modifications reduces some risks, but reading can still expose confidential information to the AI service or to an output destination.
Ask what information the agent needs for the task. A summary of one invoice does not necessarily require access to every document in your account.
For work material, use approved services and accounts. Inspect the product’s data handling and retention settings separately from its ability to edit or delete records.
Our article on delegating everyday tasks to Meta Muse through WhatsApp explores a related point: a familiar interface does not settle the questions of permissions and privacy.
External content must not become authorization
Agents may encounter instructions inside emails, documents or websites that conflict with the user’s request. This is the core problem behind prompt injection: material the agent should treat as content attempts to redirect its behavior.
Anthropic’s research on browser prompt injection describes defenses while explicitly acknowledging that browser agents are not immune.
Imagine an invoice containing a note telling the assistant to forward your customer list to a verification address. That note is part of the document being processed. It is not permission from you to disclose the list.
Our practical recommendation is to require a separate user decision whenever external content proposes a new recipient, additional access or an unrelated action. Avoid workflows in which a document can effectively approve its own instructions.
Make approvals specific enough to be useful
A confirmation button helps only when you can understand what it authorizes.
“Proceed?” is too vague for a consequential action. A useful preview should identify the operation, its target and the relevant consequences.
For example:
- Email: the final message, destination addresses and attachments.
- Files: the affected paths, proposed changes and recovery method.
- Purchase: the exact order, total cost and any recurring charge.
If material details change after approval, our suggested policy is to request approval again. Authorization to buy one item should not silently extend to a substitute from another seller.
Batch approvals can reduce interruptions when the actions are genuinely similar and the full list is visible. Avoid approving a loosely described category of future actions just to dismiss repeated prompts.
Require evidence that the action succeeded
A conversational “done” is not the same as a verified result.
For an email, inspect the sent message. For a file operation, inspect the resulting files or change log. For a purchase, look for the order confirmation and check its details.
Distinguish between preparation, attempted execution and confirmed completion. This is particularly useful after a timeout: an order may have succeeded even if the agent did not receive the confirmation.
Our recommendation is to check the underlying service before repeating an uncertain purchase or message send. Retrying blindly can duplicate the action.
Expand autonomy one task at a time
Start with a narrow workflow using information you are comfortable sharing. Observe whether the agent follows the scope, identifies ambiguity and reports failures clearly.
Then expand one permission at a time. Reliable performance at summarizing emails does not establish that the agent should change mailbox rules. Accurate product comparisons do not establish that unrestricted purchasing is appropriate.
The best delegation boundary is the one that removes useful work while keeping the consequences understandable. Give the agent enough room to complete a defined task, and keep a clear way to review, stop and recover from its actions.
Sources
- Anthropic — Trustworthy agents in practice
- Microsoft — Least privilege for AI agents: Identity, access, and tool binding
- Anthropic — Mitigating prompt injections in browser use
Sources checked on September 29, 2026. The delegation framework and examples are Demystia’s editorial recommendations. Available controls vary by product and integration.
