11 Oct 2026

AI Agents, Tools and Human Handover: Controlling Business Actions

Define AI workflow authority, tool access, untrusted sources, approvals, action verification, staff transfer and operational controls.

AI Agents, Tools and Human Handover: Controlling Business Actions

An AI agent can interpret information and use connected tools, but the business must define what it is allowed to do and how the result will be verified. Reading a customer message, proposing a response and changing a booking are separate responsibilities. Give each an explicit boundary.

This guide covers tool access, untrusted material and human handover. It helps a business assess an assistant by its actual behaviour and controls rather than the confidence of its conversation.

Choose the simplest suitable workflow

A predefined workflow follows agreed steps. An agent can select steps or tools dynamically within its implementation. Compare those approaches against the task's uncertainty and the need for flexible decisions. A predictable classification or routing task may not need broad autonomy.

Describe the user need, supported requests and excluded actions. Start with representative examples and identify where ordinary software rules are sufficient. Additional model-directed steps should have a practical reason and measurable value.

Define each tool's authority

List the operation, accessible records, required inputs and possible effect for each connected tool. Separate read access from write access and limit the scope to the task. A general credential can allow more than the assistant's visible interface suggests.

Enforce permissions through the execution component and underlying service. A prompt instructing the model to read only does not establish a read-only boundary if its tool can still perform writes. Test that restricted actions fail even when requested through an unexpected path.

Keep source material separate from instructions

An email, retrieved document or website can contain text that asks the agent to ignore its rules or disclose other information. Treat that text as untrusted content rather than authority. The fact that an authorised user asked the assistant to read a file does not grant permission for every instruction within it.

Review how external information enters prompts, memory and tool parameters. Limit unnecessary capabilities and validate proposed operations before execution. Keep required access checks outside the model's interpretation of the source.

Distinguish information retrieval from completion

A tool may retrieve availability or a customer record without completing a booking or update. Define the acknowledgement that proves the requested action happened. The assistant's final response should reflect the actual result, including uncertainty or pending review.

Verify important details with the authoritative system. Avoid presenting a generated explanation or proposed action as a saved record. Preserve safe references that allow staff to reconcile the conversation with the operation performed.

Prepare the context deliberately

Supply relevant, approved information with clear scope and freshness. More material is not automatically better: contradictory or irrelevant documents can obscure the required facts. Keep public knowledge separate from private operational records and enforce source permissions.

Include instructions for missing or conflicting evidence. A no-answer route should cover unsupported requests, unavailable sources and unresolved ambiguity, not only utterances that fail to match a topic. Assign ownership for reviewing recurring gaps.

Make human review an enforceable step

Where an action requires approval, hold the operation until the authorised decision is recorded. A model deciding when to ask for review can be unreliable and should not be the sole enforcement of a required restriction. Define who can approve, what they see and what expires if the context changes.

Test approval refusal, delay and stale requests. Prevent an earlier approval from authorising a materially different operation. Keep the decision tied to the concrete action and record the outcome without exposing unnecessary personal information.

Build the handover beyond an escalation message

A message saying contact support is different from a transfer to a connected staff channel. Define the destination, opening hours, context passed and acknowledgement that someone receives the request. For voice channels, verify the actual speech, keypad and transfer behaviour where required.

Offer an understandable alternative when transfer is unavailable. Tell the customer whether they are speaking to automation or a person and whether their request has been saved. Test the receiving team's ability to continue without asking for all the same information again.

Monitor, stop and review the workflow

  • Record safe references for the request, tool calls and outcomes.
  • Review which trace inputs or outputs contain sensitive information.
  • Verify the supported stop control for the actual execution type.
  • Test disallowed actions, malicious source instructions and failed tools.
  • Check the saved environment state alongside the conversation.

Our requirements guide helps define those acceptance checks. Giraffe Digital's digital strategy service can connect the agent's scope with staff responsibilities and a practical operating model.

AI & Automation