Before giving your agent more access, use this checklist
A seven-question checklist for reviewing an AI agent before giving it more permission.
Gradient Push / agent runtime control
Before giving your agent more access, use this checklist
A practical access review for teams about to let an AI agent touch more systems, records, messages, code, or workflows.
- What may it do without approval?
- What may it prepare but not execute?
- What may it never do?
- Which tool identity does each action use?
- Which actions require approval?
- Who can pause or revoke the permission?
- Which logs prove what happened?
Use this when access expands
The checklist is for the moment an agent moves from read-only or draft-only work into anything that can change a customer record, send a message, merge code, move money, alter infrastructure, or trigger a workflow outside its sandbox.
Pick one permission. Fill the checklist. If one answer is fuzzy, stop there and fix the boundary before adding more access.
Open the checklist destinationHigh-contrast link: https://www.gradientpush.com/agent-access-review-checklist/