What should an AI agent stop and ask you about?
An agent should prepare the work, then stop at the point of no return. Sending, posting, publishing, submitting, deleting, paying, spending an advertising budget, or granting access cannot be taken back. The useful pattern is a pause right before that click, not a promise that it will be careful afterwards.
Which moves cannot be taken back?
Drafts are cheap. Delivery is not. A message sitting in a composer can be rewritten. The same text, once sent, sits in someone else's inbox. A post can be edited later, but the first version is already in feeds and screenshots. A form submitted to a registry, a file deleted from shared storage, or a permission granted to a colleague all leave a trail that a later apology does not erase.
Money has the same shape. A payment, a transfer, a trade, or an advertising spend is not a draft. Access is similar: once a person or a service can read a mailbox or a repository, you are relying on their later behaviour, not on a cancel button. The agent should treat these as a different class of work from research, outlines, and previews. It can assemble the packet. It should not press send on your behalf unless you have been shown the packet and have said yes.
Why pause right before the click rather than earlier?
Stopping too early wastes the agent's usefulness. You already know you wanted a reply drafted, a listing written, or a transfer prepared. The value is in the filled fields, the attached files, the chosen audience, and the exact amount. The pause belongs at the last reversible moment: the composed email, the staged post, the order ticket with limits visible, the delete list with names you can still uncheck.
A late pause also keeps the human decision small. You are not asked to approve a vague plan. You are asked to approve this recipient, this caption, this size, this stop, this daily loss cap. If the agent asks in the middle of drafting, you are guessing. If it asks when the click is the only remaining step, you are checking.
| Action class | What the agent should finish first | Where it should stop |
|---|---|---|
| Outbound messages | Recipient, body, attachments, tone | Before send |
| Publishing | Copy, media, network, timing | Before the live post |
| Money | Venue, size, stop, daily loss cap | Before any spend |
| Access and deletion | Who, what, and the blast radius | Before grant or delete |
When is βjust this onceβ the right default, and when is βalways on this siteβ?
Standing permission is a convenience for reversible chores: filing a note, refreshing a spreadsheet, fetching a calendar. It is a poor fit for anything that leaves your money, your name, or someone else's data in a new place. βJust this onceβ should be the default for send, post, pay, submit, delete, and grant. βAlways on this siteβ is only sane where a mistake is cheap and easy to reverse, and even then it should be easy to withdraw in a sentence.
Paying should never be pre-approved as a blank cheque. A size you have already named for a single trade is not the same as an open wallet. Copying another wallet's buys still needs a confirmation unless you have allowed that exact size in advance. Practice without money at risk is the place to learn a strategy. Live spend waits. Unusual claims against hardware earnings are held for review for the same reason: irreversible cash should not flow on a quiet assumption.
- Just this once
- Approve this packet, this recipient, this amount. The next similar action asks again.
- Always on this site
- Reuse a narrow habit on a cheap, reversible task. Withdraw it in plain words.
- Named size, not an open till
- A limit you set in advance is a fence, not a signature on every future payment.
- Practice first
- Run the same rules with no money at risk before anything settles.
Why does a record of every decision matter?
Memory without a decision log is only a diary of outcomes. You need the ask, the yes or no, the limits that were in force, and whether the agent paused. That record is how you correct a habit the system has learnt from your orders and stated preferences. It is also how you stop a follow, a strategy, or a robot job with a sentence and know that the stop did not wait in a queue.
Shared strategies should keep rules public while keeping exact parameters private, and pay a creator only from realised gains. Alpha claims should be scored against real prices at a fixed horizon rather than asserted. Robot work should leave a recording of the path taken next to the machine's own claim. Hire of another agent should be escrowed, paid on completion, and refunded if it fails, with a dispute window. None of that replaces the pause before the click. It makes the pause auditable. GROX is built so trading asks before it spends, staged social posts wait for approval, and a stop never waits β but a simpler drafts-only editor is the better choice if you never want an agent near send, pay, or access at all.
Common questions
What should an AI agent always ask before doing?
Anything you cannot undo: sending mail, posting or publishing, submitting a form, deleting shared files, paying, spending an advertising budget, or granting access. The agent should finish the draft, the ticket, or the permission list, then stop so you can read the exact packet before the irreversible step.
Should I let an agent pre-approve payments?
No. Paying should not be a standing blank permission. You can name a size, a stop, and a daily loss cap in advance so the agent knows the fence, and you can run the same strategy with no money at risk. Each live spend still waits for you unless that exact size was already allowed.
Is βalways on this siteβ ever reasonable?
Only for cheap, reversible chores such as filing notes or refreshing a sheet. Outbound speech, money, deletion, and access should stay on βjust this onceβ. A standing rule must be easy to pause, change, or stop in a sentence, and it should never cover an open till.
Why keep a log if I already clicked yes?
Because later you will need the ask, the limits, and the outcome, not a vague memory. Hits and misses should be counted against real prices. Jobs should leave a recording. Hires should escrow, pay on completion, and refund on failure. The log is how you correct what the agent learnt and how you prove a stop was honoured.