AI Agent Safety Checklist: What to Check Before an Agent Touches Accounts, Data, or Money
Giving an AI agent access to your accounts is exciting until something goes wrong and a mistake costs you money or a customer. I am not here to scare you off. I am here to give you a practical AI agent safety checklist that I run through before any agent touches accounts, data, or money in my own company. I have seven AI employees running real work every day, and this list is the reason I can hand them responsibility and still sleep at night.
Start with least privilege
The first rule is that an agent gets only the access it needs for the specific task, and absolutely nothing more. A content agent does not need your bank logins. A support agent does not need admin rights on your infrastructure. If a task can be done with read-only access, give it read-only access. This is the single most effective safety measure on the list, and it costs you nothing to implement.
- Read-only access wherever possible
- No shared passwords with full account rights
- Separate accounts or scoped keys per agent
Put a human gate on money and irreversible actions
I have a hard rule that no AI agent can move money or delete things on its own, no matter how well it has performed. The agent can prepare the transfer, build the invoice, draft the reply, and double check the numbers. But the final click that spends money or destroys data always goes through me. That split between prepare and approve is what keeps an honest mistake from ever becoming an expensive one.
Review the exact prompts and scripts
An AI agent is only as safe as the instructions it follows, and the truth is that a small wording slip can cause a big problem. Before I let any agent work on real data, I read every prompt and script out loud, line by line. I look for accidental instructions that could cause it to email the wrong person, share internal numbers, or take an action I did not intend. I refuse to deploy anything I do not fully understand, because a script I cannot explain is a risk I should not run.
Set up logging and a kill switch
Every agent I run logs what it did, when, and to which account. If something looks off, the log tells me exactly what happened instead of leaving me to guess at the cause. I also keep a kill switch, a way to pause the agent instantly the moment I see a problem. Both seem like obvious things, yet many people skip them completely and only add them after a problem has already happened. Add them up front, it takes minutes.
Never put secrets in the instructions
This one matters more than people think and it is often overlooked. I never paste real passwords, API keys, or customer details into the agent's instructions, because those instructions end up stored and repeated in logs and other tools. Where I need credentials, I use environment variables and scoped keys that stay out of the visible script. It is a small habit that prevents a large leak, and it has saved me more than once.
Test on fake data first
Before an agent touches anything real, I run it on dummy accounts with fake data. I let it generate a fake invoice, reply to a test email, and fill a test spreadsheet with made up numbers. If it does something wrong there, nothing is lost and nobody is upset. Only after the dry run passes cleanly do I point it at real work. That dry run catches most of the mistakes before they can ever matter.
Start small and build trust over time
The safest rollout is a gradual one. Give a new agent one low-stakes task, watch it closely for a full week, and read its logs. If it performs cleanly, give it a slightly larger task. Each win earns a little more access, and each mistake stays cheap because it happened at a small scale. This slow ramp is how I went from one cautious agent to a full seven employee team without a costly surprise.
Start with one low-risk task, apply this checklist, and add access only as the agent earns your trust. My starter kit includes a copy of this safety setup so you do not have to build it from scratch. And the full system I use to run seven agents safely is in the book.
The goal is not to avoid AI agents, it is to give them guardrails so they help you without surprising you. Run the checklist, gate the money, and log everything, then let them work. You will get the speed of an AI employee along with the peace of mind that nothing irreversible happens behind your back. That combination is what makes AI employees worth running at all.
Set it up the right way
The book walks through the full system: 4 files, the org chart, the failure modes, and a 30-day blueprint. $29, plain English, 30-day refund.
Get the book, $29