07 · At design time
Write the limits in business units, before anybody has to pull the plug.
The fix is not a smaller agent. It is a mandate stated in the units the business signs for — approvals, value, refunds, records — with a limit, a margin, a hard maximum, and the name of whoever stops it. Then each limit sits beside the thing that actually enforces it, because a limit written in the prompt is a hope, not a control.
Business parameterOperating limitHeadroom, flaggedHard maximum
Credit approvals per hour20to 2530: agent stops
Value approved per day£200,000to £220,000£250,000: agent stops
Approvals between midnight and six0queued for a personany: agent stops
Customer records read per sessionthe applicantlinked accounts50: session ends
The numbers are invented for the example. They are not recommendations: the right ones are the business’s, and choosing them is the point. What is not invented is the shape. A limit the agent can exceed a little, with the excess seen by a named person; a maximum it cannot exceed, enforced by something outside the agent’s own grant; and a stop that lapses its licence to operate until somebody renews it. Who can pull the plug is the other half: the stop exists only if someone is named, reachable and quicker than the agent.
This is what an Agent Behaviour Policy writes down for one agent in one deployment: what it can reach, what it was authorised to do, the gap, and what stands in the way of each capability. It is best written while the pilot is still a pilot, because that is when the gap is cheapest to close. Agents are good at helping write it: the thirteen free prompts have the agent list its own reach before anybody decides what its mandate should be.