Agents That Take Actions, Not Just Answer
Once a model can send a message, spend money or change a file, a wrong answer stops being a wrong answer and becomes a wrong action. What the tool is allowed to reach sets how bad a mistake can get.
What a learner can do afterwards
- Separate what a model can do with text alone from what it can do with a tool attached to it
- Name an action that should need a person to confirm it, and say what makes it that kind of action
- Explain why limiting what an agent can reach matters more than trusting it to behave well
1 · Read
A model with no tools only writes words. You read the draft, you press send. Add a tool and the same model can send mail, spend money, or rewrite files on its own.
Some acts need a person to nod first. Sending mail to others, paying, deleting, and sharing private files are hard to undo and can harm people besides you. Drafting and searching cost little and undo fast.
A draft invite harms nobody while it sits unsent. The moment the agent itself sends it to two hundred guests with the wrong date, the error turns into missed visits and hurt hosts. Reach set the size of the harm.
Do not trust the agent to behave well. Shrink what it can reach: read-only files, capped spending, named inboxes, and a human nod for each outward act.
Words need review, acts need approval, so shrink what the agent can reach.
2 · Watch
Take it off screen
Where it sits
Where this leads
Jobs that lean on this skill. Follow one to see everything it is built on.
8 questions wait behind this lesson, each with its answer explained. Every answer feeds the sky: stars light as they are learned, and dim when it is time to come back.