An agent should be safe because of what it structurally cannot do, not because of what it has been told not to do. Instructions are advice and they bend under unusual input. A capability that was never granted does not bend.
System
Internal agent operations platform
Scale
Five agents, daily production use
Role
Sole architect and engineer
Stack
Agent tooling / PostgreSQL / Access control
01
The challenge
Agents drafting real business correspondence against a live customer database. The feared failure was never a weak draft; it was an autonomous send.
02
The approach
Remove the capability instead of restraining it, mediate what remains through single audited doors, and default every state change to a rehearsal.
03
The result
Hundreds of drafts produced in daily use with no autonomous sends and no write incidents, and a straight answer to what if it does something stupid.
Fig. 08 — The only route to the outside world runs through a person
Hover any step to read what it doesTap any step to read what it does