← Blog

Safe delegation starts with the workflow

Restrictions matter, but they cannot make an unclear job clear. Good agent governance starts with designing the work itself.

September 23, 20262 min readAgent Anything
governancedelegationai agentsworkflow designsecurity

AI agent governance is not only a security feature or a permissions system. It is also a discipline of workflow design. The more thought you put into the delegation before the agent begins, the more safely the agent can operate on your behalf after it does.

Most conversations about AI agent safety begin with restrictions, such as limiting the tools, limiting the data, requiring approval, and blocking dangerous actions. Those controls matter to us, but they are only part of the work. An agent can have narrow permissions and still operate inside a poorly designed workflow. It can be given ambiguous instructions, asked to interpret untrusted material, or left to decide where analysis ends and authority begins. Technical guardrails can reduce the consequences, but they cannot make an unclear job clear to the agent. Good AI governance starts earlier, with designing the work itself.

Some information an AI agent encounters is instruction and some is context that the agent should inspect, compare, summarize, or evaluate. Those two types of information should not be interchangeable. A document being analyzed should not be able to redirect the AI into another task. A message being reviewed should not be able to grant the agent new authority. Untrusted content should remain informational, even when it contains language that looks like an instruction. Establishing that distinction is a workflow decision long before it is implemented as a technical control.

Agents are useful because they can exercise judgment. They can notice inconsistencies, connect information across sources, and reach conclusions that were not written into a rigid decision tree. That does not mean every conclusion should automatically become an action. A well-designed workflow makes the boundary explicit. The agent may investigate broadly, but it cannot send, sign, publish, purchase, delete, or approve unless that authority was granted separately. Analysis and action are different permissions because they carry different consequences. Separating them gives the agent room to think without also giving it room to act beyond its role.

Keeping a person involved does not require asking them to redo the agent's work. The person can instead govern the boundary by deciding what enters the workflow, what question is being asked, what sources may be consulted, what authority is available, and what requires final review. That is a better use of human judgment than manually performing every specialized step. The agent handles the work it is good at, while the person remains responsible for the shape and consequences of the delegation.

This is also why the safest agent is not necessarily the one with the fewest capabilities. An agent constrained so tightly that it cannot use judgment is often not useful enough to justify having it. The better goal is bounded freedom. When the role is clear, untrusted context has a defined place, authority is explicit, and consequential actions have an appropriate decision point, the agent can operate with much more independence inside those boundaries. Technical controls then enforce a thoughtful design instead of trying to compensate for the absence of one.

Get in touch

Want to talk through how this applies to your organization?

Request access