
The moment an AI stops answering questions and starts touching real systems, the question changes. It is no longer "is the answer good". It is "who is responsible for what just happened".
These are ten gates we teach. They are not legal advice and they are not a compliance framework. They are practical checkpoints that keep a named human accountable while still letting the system do useful work.
Access, reading, drafting, money.
- Access scope. Decide in advance exactly which folders, mailboxes and systems the AI may reach, and write it down. Default to the smallest set that makes the job possible. Broad access granted "for now" is never revisited.
- Read before write. Every new connection starts read only. Let it run for a week and look at what it would have done. Write permission is a separate, later decision.
- Draft before send or publish. Anything leaving your organisation, an email, a post, a proposal, a reply to a client, is a draft until a person approves it. No exceptions for volume.
- Payments. No AI initiates, approves or modifies a payment. Preparing a payment file for human approval is fine. Executing one is not.
Deletion, secrets, personal data.
- Deletion. Deleting and overwriting are irreversible in a way that creating is not. Require explicit human confirmation for every destructive action, and keep backups that the AI cannot reach.
- Credentials and secrets. Keys, passwords and tokens never live in context files, prompts or notes the AI reads. If a secret has ever been pasted into a chat, treat it as compromised and rotate it.
- Personal and confidential data. Decide which categories may be processed at all, and by which provider. Client data, health data, employee data and anything under a confidentiality agreement each need a deliberate yes, recorded, not an accident.
“Automation moves the work. It does not move the responsibility.”
Commitments, bulk actions, rollback.
- Commitments and contracts. Prices, deadlines, guarantees and contractual terms are human decisions. An AI may draft them and may check them against your rules. It may not be the last signature.
- Bulk actions. One wrong action is a mistake. Four hundred wrong actions is an incident. Set a threshold above which anything repeated needs approval, and test on a small batch first.
- Rollback, log and review. Before you allow an action, know how to undo it, make sure it is logged with what was done and why, and review the log on a schedule. A gate nobody inspects is a gate that is already open.
Write these gates into your constitution file, in your own words, with your own thresholds. A rule that lives in a file the AI reads is a rule that gets applied. A rule that lives in somebody's head is a hope.
The free starter kit has a place for exactly this, and the Constitution layer explains why this file comes before everything else.
Granting full access on day one to see what it can do
The exploration phase is exactly when the system is least predictable. Start read only, widen deliberately, and write down each widening.

Entrepreneur from Latvia. Building FullDigital so people stay free in the age of AI. I write about what actually works in my own week, not what sounds good on a conference stage.
Connect on LinkedIn