Write the Table Before the Agent
Anthropic’s new threat report is easy to file under security.
That is too narrow.
The useful lesson for normal companies is simpler: the agent needs a boundary before it needs a bigger model.
Not a policy deck. Not a committee name. Not a vague promise that humans stay in the loop.
A table.
What can it read?
What can it change?
What needs approval?
What gets logged?
That sounds almost too plain. Good. Plain is where control starts.
Most teams are not failing because they lack an AI principle statement. They are failing because nobody can answer the practical questions after access is granted. Can the support agent see customer records? Can it edit them? Can it draft a refund? Can it issue one? Who checks the log on Friday?
Those are not technical footnotes. Those are the workflow.
Agents inherit whatever mess already exists: shared accounts, old tokens, broad permissions, weird spreadsheet exports, tools nobody has audited in a year. Then they move faster inside it.
So slow the first step down.
Before the agent touches a live system, write the table. Put a name next to it. Review it after the first week of use.
If the table is hard to fill out, that is the warning.
The agent is not ready.
Neither is the workflow.