The rule format
When the agent detects a trigger, it should route the task to a lane, attach required evidence, and follow a permitted action. That makes the rule testable instead of decorative.
Replace vague agent caution with explicit rules for when to interrupt, batch, draft, ask, block, or act. The rule set becomes the agent's attention contract.
Do not start with abstract priority. Start with what should happen next: interrupt immediately, batch for review, draft only, ask a clarifying question, refuse, or proceed autonomously.
When the agent detects a trigger, it should route the task to a lane, attach required evidence, and follow a permitted action. That makes the rule testable instead of decorative.
Money, account access, public commitment, sensitive relationship, deadline, or destructive action.
Immediate escalation, daily batch, policy update, autonomous action, draft-only, or block.
Source context, memory match, draft output, tool plan, confidence, and rollback path.
Start strict, review the misses, then grant autonomy only where repeated evidence supports it.
Write immediate escalation rules for money movement, account changes, public posting, security, sensitive contacts, and irreversible browser actions.
Route non-urgent judgment calls into a daily batch with context. This protects focus without hiding useful review work.
When the same class of item is approved repeatedly, define the autonomous version, its exceptions, and the rollback path.
A rule is not ready until another person could inspect an agent action and tell whether the rule was followed.
Describe observable conditions, not vibes like important or risky.
Each rule should route to one primary lane, with exceptions named separately.
Name the source, draft, memory, and tool context the agent must include.
Every rule should have a date for tightening, relaxing, or retiring it.
This guide synthesizes public AI governance guidance with practical personal-agent operations. It is workflow guidance, not legal advice.
Lifecycle guidance for governing, mapping, measuring, and managing AI risk.
Open sourceBackground on human-centered values, transparency, robustness, and accountability.
Open sourceApply urgency rules to text agents, computer-use cache, and agent-built websites.
Open SuperStart with five to eight hard-stop rules. Add batch and autonomy rules after you have reviewed real agent behavior.
Confidence can be one signal, but do not let it override consequence. A high-confidence account change may still require escalation.
Begin with text-message workflows because timing, tone, and relationship sensitivity expose rule gaps quickly.
Super helps personal operators build agent workflows across messaging, browser work, and repeatable tasks with clearer review boundaries.