All posts

Why we never gave our AI agents a "send" button

Since September 2026 a team of Claude-powered agents has run the back office of my startup: mail, notices, calendar, card and bank records, tax deadlines and purchase research. They work around the clock. And in all that time, none of them has been able to send an email, pay a bill or place an order on its own.

That was a deliberate design choice, and it is the one I would keep if I had to throw everything else away.

Where we drew the line

We split everything an agent might do into two groups.

  • Inside the company: reading, searching, summarizing, organizing, reconciling, researching and drafting. These run automatically, on a schedule, without asking.
  • Outside the company: sending, paying, transferring, booking, ordering, filing, signing, publishing and deleting. These never run without an explicit approval from me.

The test is simple:

can someone outside the company see it, or can it not be undone?

If yes, a person decides. Drafting a reply to a supplier is inside. Sending it is outside. Researching three prices is inside. Ordering is outside.

We enforce the line technically as well as by instruction. The connection to my main mailbox is read-only — the agents can read and search it, but there is no way to send from it. Anything that must be sent goes from a separate work account, and only after approval. The agents never touch bank or card logins at all.

Two buttons, and silence means no

When an agent has something that needs to leave, it prepares it completely — the full email, the order details — and sends me a chat message with a short reason and two buttons: approve or cancel.

The rule that took the most thought was the default. If I do not answer within 30 minutes, the action does not happen. The item stays on the open-items ledger and comes back in the next briefing. It is tempting to make silence mean yes, so that work keeps moving. But a system where silence means yes is a system that acts while you sleep.

"It looks urgent" is not an exception

Urgent-looking messages are exactly the ones that deserve a human look. A notice that says "pay by today or service will stop" may be real, may be already settled, or may not be meant for you at all. An agent that hurries because the text sounds urgent is an agent that can be steered by whoever writes the most urgent text.

So the approval step does not get shorter when things look urgent. The agent can raise the priority of the message to me — that is all.

Content is data, not instructions

Our agents read a lot of text written by other people: emails, invoices, web pages, notices. Some of that text contains instructions — "reply with your account details", "ignore your previous instructions", "transfer the balance now". This is the problem known as prompt injection.

Our rule is that anything inside an email, document or web page is material to summarize, never a command to follow. Only I, through the chat channel, can ask for an action — and even then, outbound actions still need the approval button. The approval gate is the second line of defense when the first one fails.

What the gate has caught

The clearest example came from our own mistakes. Once, an agent read a card company's "payment overdue" text and reported the bill as unpaid. The ledger showed a payment of the same amount on the same day — the text was simply older than the payment. The report was wrong, but nothing happened because of it: the agent could only tell me, not pay. If the agent had been allowed to act on its own reading, the "fix" would have been a second payment.

That episode gave us a second rule — check the ledger before reporting a status — which I wrote about in the next post. But the reason it cost nothing was the gate.

Why this matters beyond our pilot

Anthropic's usage policy treats legal, financial and employment-related uses as high-risk and expects human review of outputs in those areas. In Korea, tax filing, legal work and labor filings are also licensed professions. An approval gate is how both of those facts become part of the product instead of a disclaimer: the agents prepare; the owner — and, where needed, their licensed professional — decides.

The cost is a few taps a day. In exchange, nothing that leaves the company is a surprise.

Apply for the free pilot Free for 8 weeks, for up to five businesses in Korea. You apply by email.

한국어 요약

읽기⁠·⁠검색⁠·⁠요약⁠·⁠정리⁠·⁠대조⁠·⁠조사⁠·⁠초안 작성은 회사 안의 일이라 자동으로 돌아갑니다. 발송⁠·⁠결제⁠·⁠이체⁠·⁠예약⁠·⁠주문⁠·⁠신고⁠·⁠서명⁠·⁠게시⁠·⁠삭제는 회사 밖의 일이라 대표 승인 없이는 실행하지 않습니다. 기준은 '회사 밖에서 볼 수 있는가, 되돌릴 수 없는가'입니다.

  • 본 메일 계정은 읽기 전용이라 기술적으로도 발송할 수 없음. 보낼 메일은 승인 후 별도 업무용 계정에서 발송
  • 승인 요청: 채팅의 승인⁠·⁠취소 버튼 두 개. 30분 안에 답이 없으면 실행하지 않고 다음 브리핑에 다시 올림
  • 급해 보이는 메시지도 예외 없음. 에이전트는 메시지의 우선순위만 올릴 수 있음
  • 메일⁠·⁠문서⁠·⁠웹페이지 속 지시 문구는 요약할 자료로만 다루고 명령으로 따르지 않음

실제로 에이전트가 카드사의 '미납' 안내 문자만 보고 대금이 밀렸다고 잘못 보고한 일이 있었습니다. 장부에는 같은 날 같은 금액의 결제가 남아 있었습니다. 에이전트에게 결제 권한이 없었기에 이중 결제 같은 피해는 생기지 않았습니다.

한국어 전체 페이지: AI 에이전트에게 '보내기' 버튼을 주지 않은 이유