Start with the work, not the model
An agent becomes useful when it has a clearly framed job. That framing includes the trigger, the context it can access, the actions it may take, and the condition that marks the work complete.
Beginning with a broad promise to “automate the process” usually hides the decisions that matter. A narrow workflow makes permissions, evaluation, and failure handling concrete.
Treat tools as permissions
Every system an agent can call expands what it can do and what can go wrong. Tool access should be explicit, least-privileged, and observable. Read access and write access deserve different review paths.
The strongest early use cases often prepare work rather than finalize it: gathering context, drafting a response, classifying a request, or recommending the next action.
Design the human handoff
A handoff is part of the product, not an exception to it. Define when the agent should stop, what context it should pass forward, and how a person can inspect what happened.
That creates a system teams can supervise and improve—one that provides leverage without pretending uncertainty has disappeared.

