
The ads are everywhere this year: hire an AI employee. It answers your email at 3am, books your appointments, chases your invoices, posts to social, never calls in sick. Some of that is real. But the word "employee" is doing a lot of work in that sentence, and it's the wrong word. What you're actually setting up is an assistant that can act — and an assistant that can act is only as safe as the keys you hand it.
What an AI agent for a small business actually is
Strip away the marketing and an agent is three things: a model that decides what to do next, a set of tools it's allowed to use, and a schedule or trigger that sets it going. The model is the part everyone talks about. The tools are the part that matters. An agent that can read your inbox is a summariser. An agent that can send from your inbox is a representative of your business, speaking in your name, at any hour, to anyone.
We made the same point about the models themselves in the harness matters more than the model: what surrounds the intelligence decides what it can do, and what it can break. With agents that's doubly true, because the harness now includes your accounts.
An employee earns access over months. An agent gets it the moment you paste in a password. Decide what it can touch before you decide what it should do.
Sort the work by what happens when it's wrong
The useful question isn't "can an agent do this?" Most things, it can. The question is what happens on the day it does it wrong, because that day comes. We sort every task into three piles.
Hand it over. Work where a mistake is cheap and easy to spot: summarising the morning's email, drafting replies you'll read before sending, sorting receipts, pulling last week's numbers into a report, turning a voice memo into a to-do list. The agent reads, drafts and organises. Nothing leaves the building without you.
Hand it over with a check. Work where a mistake reaches a customer or your books: sending an email, confirming a booking, publishing a post, updating a price. The agent can do nearly all of it — gather, draft, fill in — and stop one step short. A person looks, then presses the button. That one step is the whole difference between an assistant and a liability, and it costs seconds.
Keep it. Anything that moves money, signs you up for something, deletes records, or changes who has access to what. An agent may prepare the paperwork. It should not hold the pen. Not because it will certainly get it wrong, but because when it does, there's no undo.
The permissions that make the difference
Most of the risk in "AI employees" comes from lazy access, not bad models. A few rules cover most of it.
Give it its own account. Never your login. A separate account with its own permissions can be limited, watched and switched off without locking you out of your own business.
Give it the least it needs. Read-only where reading is the job. Drafts, not sends. One folder, not the whole drive. If a tool only offers all-or-nothing access, that's a reason to choose a different tool.
Make it leave a trail. Every action it takes should be written down somewhere a person can read. If you can't answer "what did it do last Tuesday?", you don't have an assistant; you have a rumour.
Make silence loud. The failure people don't plan for isn't the agent doing something wrong. It's the agent quietly doing nothing for a week. Every scheduled job should report that it ran, and someone should hear about it when it doesn't.
How this blog runs
We hold ourselves to the same rules, and this blog is the clearest example we have. Topics are proposed from what we're reading and what readers engaged with, and a person approves or rejects every one. After that, scheduled passes draft each approved post, paint its cover and check both against written rules — voice, length, links, and a look at the art for stray lettering or the wrong palette — then stage it as an unpublished draft. On the scheduled day, a separate pass publishes it. Social posts built from it are written to the same rules, pass the same checks, and go out on a schedule. Every run reports in, and a watchdog emails us when a run is missing or fails.
Notice where the person sits. Not at every step — that would defeat the point — but where judgement matters most: deciding what we write about, and writing the rules every post and caption has to pass before it can go out under our name. Everything between is delegated, logged and checked. That's what we mean by an assistant with keys. It's early for all of this, and we change the rules when a run teaches us something; we'd be lying if we said the pattern was finished.
Where to start
Pick one recurring job that eats an afternoon a week and sits squarely in the first pile. Give an assistant read access and a drafts folder, and nothing else. Run it for a month. You'll learn more about what to trust it with from that month than from any demo. We wrote about picking that first job in how to use AI in your business like a power user.
If you'd rather know which jobs in your business belong in which pile before you hand anyone the keys, that's what our THINQ Diagnostic is for: ten days mapping how the work actually moves, what it costs to run it that way, and the three things worth fixing first.


