When To Let An Agent Act, And When To Only Draft
The interesting question about AI agents is no longer whether they can do a task. Increasingly they can. The question is which tasks you should let them finish on their own, and which ones they should only draft for you to send.
“Let the agent handle it” is not a policy. It is an abdication dressed up as efficiency, and it works right up until the agent sends the wrong invoice to the wrong client and there is no undo. You need a rule you can apply before you hand something over, not a feeling.
Here is a framework that fits on an index card. Three questions, one default.
Judge The Task On Reversibility, Blast Radius, And Sensitivity
Three properties decide how much autonomy a task can safely carry.
Reversibility. If the agent gets it wrong, can you undo it cheaply? Renaming a draft file is reversible. Sending an email is not, and neither is a payment or a public post.
Blast radius. If it goes wrong, how far does the damage reach? A mistake in your own scratch notes stays with you. A mistake in a message to a customer, a shared document, or a production system reaches other people who did not agree to the risk.
Sensitivity. Does the task touch confidential data, money, legal commitments, or someone’s reputation? A tweak to a to-do list is not sensitive. A reply to a regulator is.
Score a task low on all three and it is a fine candidate for autonomy. Score it high on any one and it belongs in draft-only. You do not need a spreadsheet; you need to actually ask the three questions instead of skipping them because the agent seems capable.
The public risk frameworks land in the same place. The NIST AI Risk Management Framework organizes AI risk management around context and consequence rather than raw capability, which is the same instinct: match oversight to what is at stake, not to what the tool can technically do.
Default To Draft-Only For Anything That Leaves The Building
Outbound communication is the clearest case, and the default there is draft-only.
An email, a client message, a public post, a contract reply: these are irreversible, they reach other people, and they carry your name. The agent can write a genuinely good first version and save you the blank-page problem. What it should not do is press send, because the cost of a bad send is borne by someone who never reviewed it.
Draft-only is not distrust of the model. It is matching the review to the stakes. You would not let a new hire email a customer unsupervised on day one either, and the reason is the same.
Before:
Auto-send the follow-up to the client once the agent drafts it, so nothing sits in my outbox.
After:
Have the agent draft the client follow-up and hold it for me. I read the diff, confirm the figures, and send it myself.
The second keeps the time savings of a drafted message and keeps the one step that catches a wrong number before a client sees it.
Let Agents Act Only On Low-Stakes Reversible Work
The flip side is real. Plenty of tasks score low on all three properties and there is no reason to babysit them.
Sorting your own inbox into folders. Drafting into a private notes file. Renaming and tagging files. Summarizing a document for your own reading. Preparing a list you will review before anything happens with it. These are reversible, contained, and not sensitive, and requiring your sign-off on each one just moves the tedium from doing the task to approving it.
The trap is scope creep. An agent trusted to file your notes gets quietly extended to file shared team notes, then to update the shared tracker, then to notify people when it does. Each step raised the blast radius and nobody re-ran the three questions. Re-run them whenever the task changes, not just when you first set it up.
Write The Rule Down So It Survives A Busy Week
A framework you keep in your head evaporates under deadline pressure, which is exactly when you are most tempted to let the agent send things unread. Put it somewhere the whole team can see it, and pair it with a review step for everything in the draft-only column.
A Wrivio Context for turning an agent draft into something you will actually send could say:
Rewrite this as a message I am about to send myself. Keep the register professional and direct. Keep every name, date, figure, amount, and commitment exactly as written. Do not add promises, deadlines, or numbers that are not already in the draft, and do not soften a specific commitment into a vague one.
Press Ctrl+Shift+Space, paste the agent’s draft, and check the diff before you send. Watch for invented deadlines and altered amounts, which are the edits that turn a helpful draft into a liability.
For the mechanics of that review step, and how much of it you can genuinely delegate, see how to review work an AI agent finished. And for a sober read on what agents can and cannot reliably do as of August 2026, we set expectations in the agentic AI reality check.
The one-line version: let agents act when a mistake is cheap and contained, keep them to drafting when it is not, and never let “capable” quietly become “unsupervised”.
Common Questions
Should I let an AI agent send emails for me?
Usually not without review, because email is irreversible, reaches other people, and carries your name, which is exactly the high-stakes profile that calls for draft-only; let the agent write the draft and send it yourself after checking the figures.
What tasks are safe to fully automate with an agent?
Tasks that are reversible, contained to you, and not sensitive: sorting your own inbox, drafting into private notes, renaming files, and summarizing documents for your own reading, where a mistake is cheap to undo and reaches nobody else.
How do I decide between acting and drafting?
Ask three questions before you hand the task over: can I cheaply undo a mistake, how far does the damage reach, and does it touch money, legal commitments, or reputation; a low answer on all three allows autonomy and a high answer on any one means draft-only.
Does draft-only defeat the point of an agent?
No, because most of the time saved is in producing the first version, not in pressing send; draft-only keeps the blank-page savings while preserving the one review step that catches a wrong number or a bad commitment.
Download Wrivio for Windows to turn an agent’s draft into a message you have actually checked before it leaves your machine.
Read Next
Building A Review Gate For Anything An Agent Writes
A repeatable review gate so agent output is never sent unread: a short checklist plus a word-level diff pass, and exactly what belongs on the list.
Drafting With Agents Without Losing Your Voice
Agents flatten prose toward a generic middle. How to keep your own voice with a stored style, a Wrivio Context, and a word-level diff pass.
How to Review Work an AI Agent Finished
Agents now return completed documents rather than suggestions. A review method for output that arrives looking finished, because formatting suppresses scrutiny.
Who Is Accountable When An AI Agent Acts For You
Accountability does not transfer to a tool when an agent acts on your behalf. How to frame ownership for teams, and why human review is an accountability control.
This article is filed underProductivity & Operations, which has 53 articles.