Blast Radius
What is the worst thing one wrong step can do?
- Permissions
- Autonomy
- Human approval
- Reversibility
- AI safety
Interactive prototype
Open in a new tab →If the prototype doesn't load here, open it in a new tab.
The situation
An AI executive assistant starts read-only over a calendar. It's useful, so it gets email. Then files. Then the CRM. Then the ability to spend.
Each grant is individually reasonable. The combined surface is not.
The obvious answer
Give the agent broad access so it can be genuinely useful, then trust the model to behave.
The question underneath it
Every permission is a design decision about consequences, not convenience. Authority should be granted per action, and the cost of a mistake should stay bounded no matter how capable the model gets.
What I'm paying attention to
Reversibility
Drafting is undoable. Sending, paying, and deleting are not.
Audience
Internal mistakes are embarrassing; external ones are permanent.
Approval gates
The right question is which actions cross a human, not whether any do.
Scope of credentials
Read access to a folder is not read access to a drive.
Detection
Autonomy without logging is autonomy without accountability.
My take
More autonomy is not more sophisticated. The interesting systems live between "AI suggests" and "AI runs the company," and staying there is a deliberate engineering choice.
I prefer bounded autonomy: wide read, narrow write, explicit approval on anything irreversible.
Related writing
How Much Power Should You Give an AI Agent?
Substack essay — Coming Soon
Explore another experiment
The AI Draft
You have a limited AI budget. What actually deserves to get funded?
Enter The AI Draft →ArchitectureBuild / Buy / Bend
You need the capability. You don't necessarily need to build the software.
Make the Call →ReliabilityOne Bad Tuesday
Your AI system worked perfectly for three months. Then Tuesday happened.
Start Tuesday →Office Hours with Chanel
Working through a version of this in your own company?
Private AI office hours for leaders who need to turn messy AI ideas into clear strategy, useful workflows, or safe internal agents — with senior-engineer judgment in the room.