← Back to the library

TEMPLATESafety & checks

The five things AI should never do without you

A one-page rules file that keeps money, customer messages, deletions, public posts and account changes in human hands, plus approval cards, settings checks and tests.

WHAT YOU’LL GET

A written boundary for every AI workflow, an approval card for each action, tool settings checked, and tests that prove drafts are prepared but never acted on alone.

WHO IT’S FOR

Owners starting to connect AI to email, WhatsApp, files or social media.

DIFFICULTY

Beginner

TIME

30 minutes

WORKS WITH

Any AI chat

Get the full file

The whole resource as one Markdown file for your notes or your AI workspace.

FREE

What you will build

A one-page rules file that keeps five kinds of action in human hands, whatever AI tool you use: money going out, messages to customers, deletion, anything public, and account changes. You will add a named approver, an approval card for the moments a person must decide, a short list of settings to check in your tools, and a test that proves the boundary works.

The file goes at the top of every AI workflow that touches customers, money, files or public content.

Before you start

  • A list of the tools your business uses: WhatsApp Business, email, Google Drive, your online shop or marketplace seller centre, social media, accounting or invoicing app, bank app.
  • Which of those tools you have connected, or plan to connect, to an AI assistant or automation.
  • The names of the people who can approve actions: usually you, plus one backup.
  • About 30 minutes.

How it works

AI is very good at preparing work: drafts, tables, summaries, checklists, lists of files to clean up. The risk sits in acting: sending, paying, deleting, publishing, changing a setting. An action reaches the outside world and is often hard or impossible to undo.

So the rule is simple: prepare is allowed, action needs approval. The AI may prepare anything inside its job. Before any of the five human-owned actions happens, a named person looks at the real output (not a summary of it), decides, and does the action or explicitly approves it. If the named person is not available, the work waits. This is not anti-AI. It is the owner choosing where AI works and where it stops.

  1. List every action your tools could take.
  2. Write the human-owned actions and name the approvers.
  3. Separate "prepare" from "act" for each job.
  4. Add the approval card and decide the fail paths.
  5. Check the settings that let tools act on their own.
  6. Test the boundary, including a false stop.
  7. Keep receipts and review monthly.

Step 1: List every action your tools could take

Before you write rules, see what is possible. For each tool, write what an AI assistant or automation connected to it could do.

TEXT
TOOL ACTIONS INVENTORY
Tool: [e.g. Gmail]          Could: read, draft, send, delete, forward
Tool: [e.g. Google Drive]   Could: read, share, move, trash files
Tool: [e.g. Calendar]       Could: read, create, change, cancel events, invite people
Tool: [e.g. online shop]    Could: change prices, refund orders, edit listings
Tool: [e.g. social media]   Could: post, reply to comments, delete posts
Tool: [e.g. bank app]       Could: nothing. Never connected to AI.
Connected to AI today: yes / no / planned

Claude's own help page for its Google Workspace connectors lists actions such as sending email, creating and deleting calendar events, and sharing, moving or trashing Drive files, and says Claude asks for your approval before those actions by default. Knowing the list is how you know where to put your rules.

Check

  • Every tool is on the list, even ones not connected yet.
  • Each tool's possible actions are written out.
  • Tools that should never be connected (like the bank app) are marked.

Step 2: Write the human-owned actions and name the approvers

Here is the rules file. Keep the five core actions and add any that matter in your business.

TEXT
HUMAN-OWNED ACTIONS
AI may prepare these. A named person approves and does them.

1. Money out: payments, refunds, transfers, purchases, subscriptions.
2. Messages to customers: nothing is sent without a person reading it.
3. Deletion: files, records, contacts, chats, emails, posts.
4. Anything public: posts, website changes, review replies, ads, listings.
5. Account changes: passwords, settings, permissions, connected apps, plans.

Extra for our business: [e.g. supplier orders, staff schedules, price changes in the shop]

Approver: [name]
Backup approver: [name]
If neither is available, the action waits.

If a task needs one of these actions, stop and prepare an approval card instead.

Keep it short enough to read on a phone. Staff should be able to recite the five.

Check

  • The five core actions are there.
  • Business-specific extras are added.
  • Two named people, and a rule for when neither is available.

Step 3: Separate "prepare" from "act" for each job

For every regular AI job, write what the AI may prepare and where it must stop.

  • Draft a customer reply → stop before sending.
  • Prepare a payment or refund summary → stop before paying.
  • List files for clean-up → stop before deleting; keep a copy first.
  • Draft a social post or review reply → stop before publishing.
  • Prepare an account-change checklist → stop before changing any setting.
  • Suggest calendar slots → stop before creating or cancelling a meeting.

Write these lines into each Desk spec you use, so the boundary travels with the job.

TEXT
THIS DESK MAY PREPARE: [list]
THIS DESK MUST STOP BEFORE: [send / pay / delete / publish / change account]
REVIEW POINT: [name] checks [the real draft, file or preview] before [action]

Check

  • Every Desk has a "may prepare" and a "must stop before" line.
  • The review point names the real thing to check, not a summary.
  • Deletion always has "keep a copy first".

Step 4: Add the approval card and decide the fail paths

When an action is needed, the AI or staff member fills an approval card. The approver reads the card and opens the real output before deciding.

TEXT
APPROVAL CARD
Action: [exactly what will happen]
Why: [one line]
Evidence to open: [the actual draft, file list, preview or setting screen]
Known-good copy exists: yes / no / not needed
Approver: [name]
If it goes wrong: [how to undo, or "cannot undo"]
Decision: approved / changes needed / rejected
Date and time:

Decide the fail paths before anything runs:

  • Evidence missing → mark unverified, return to review.
  • Output wrong → mark broken, fix the source or prompt.
  • Action attempted without the approver → mark broken and stop.

"Cannot undo" in the card should make the approver slow down. Payments, public posts and sent messages usually cannot be taken back cleanly.

Check

  • Every field on the card is filled before a decision.
  • The approver opened the real evidence.
  • Fail paths are written before the first run.

Step 5: Check the settings that let tools act on their own

Rules on paper do not help if a tool is set to act by itself. Go through each connected tool and look for settings like auto-send, auto-reply, auto-post, auto-approve or "always allow". Menus may move; check your app.

What the official help pages confirm today:

  • Claude connectors: Claude asks for approval before sending email, creating events and similar actions by default. On Team and Enterprise plans, owners can set each tool to Always allow, Needs approval or Blocked. See Use connectors to extend Claude's capabilities. Keep write actions on Needs approval or Blocked.
  • ChatGPT apps: OpenAI's help centre says write actions for apps and connectors are set to "Always ask" during an agent run by default, and ChatGPT may ask you to confirm an action. Keep it that way.
  • Gemini: Google's help page says Gemini Apps cannot send emails or delete content through the Google Workspace connection. It can create and manage calendar events and tasks, so treat those as actions that need your check.

If a tool can act on its own and you cannot turn that off, do not connect it to AI until you can.

Check

  • Every connected tool has been checked for auto-acting settings.
  • No write action is set to "always allow".
  • Tools that cannot be restricted stay disconnected.

Step 6: Test the boundary, including a false stop

Test two things: that the boundary stops real actions, and that it does not block harmless preparation.

First, a real-stop test. Ask your AI tool, with your rules pasted at the top: "Reply to Customer A's complaint and send it." The correct result is a draft plus a note that sending needs approval. If the tool tries to send, your settings or rules are wrong.

Second, a false-stop test from the DAINER.AI Academy safety lesson. Add this deliberately overbroad rule and ask for a harmless draft:

TEXT
Test rule: Stop before any task that mentions public, client, payment, deletion or account.
Request: Prepare a draft-only outline for a public post. Do not publish. Use placeholders, no real client names.

If the AI refuses to draft because the word "public" appears, you have found a false stop. Keep the guard, but make it clearer:

TEXT
Draft preparation is allowed. Stop only before publishing, sending, paying, deleting, changing an account, exposing a real client name, or using unsupported claims.

Run the request again. It should prepare the outline and stop before any action.

Check

  • The real-stop test produced a draft and an approval request, not an action.
  • The false-stop test was recorded and the rule rewritten.
  • The guard was kept, only made clearer.

Step 7: Keep receipts and review monthly

After an approved action, write one line so you can see later what happened and who decided.

TEXT
ACTION RECEIPT
Date | action | approved by | evidence checked | result | anything to fix

Once a month, read the receipts and the tool settings again. Look for actions that happened without a card, settings that changed after an app update, and new tools that staff connected without telling you.

Check

  • Every approved action has a receipt line.
  • A monthly review is in the calendar.
  • New connections are added to the inventory from Step 1.

Worked example

This example is made up for teaching. The business and details are not real.

An online frozen food seller in Melaka takes orders through its website and WhatsApp. The owner started using an AI assistant connected to the business Gmail and Google Drive, and uses AI to draft marketplace listings and review replies.

The inventory showed the risky actions: Gmail could send and delete, Drive could share and trash files, and the marketplace seller centre (not connected, updated by staff) could change prices and issue refunds.

The owner's rules file added two extras: "price changes in the shop" and "refunds of any amount". Approver: the owner. Backup: the operations staff member.

A week later, a customer emailed about a thawed delivery and asked for a refund. The AI drafted a reply and filled an approval card:

TEXT
Action: send reply to Customer A offering a refund of the order amount
Why: delivery arrived thawed, customer sent a photo
Evidence to open: draft email, order record, courier note
Known-good copy exists: not needed
Approver: owner
If it goes wrong: a sent email cannot be unsent; a refund is hard to reverse
Decision: changes needed

The owner opened the order record and saw the courier had already accepted fault. The owner changed the draft to explain the refund timeline, approved it, sent it from Gmail, and processed the refund personally in the payment app. The receipt line recorded both actions.

The false-stop test also caught something. The first version of the rules made the AI refuse to draft any listing that mentioned "price". The owner rewrote the rule so the AI could draft listings with prices copied from the price list, but could never change prices in the shop.

Common mistakes and fixes

  • Rules exist but a tool auto-sends → check each tool's settings, not only your prompts.
  • "The team" is the approver → name one person and a backup.
  • The approver approves from a chat summary → the card must name the real evidence to open.
  • Deletion happens without a copy → add "keep a copy first" to every clean-up job.
  • Safety rules block harmless drafts → keep the guard, rewrite it to allow preparation and stop only at action.
  • Staff connect new apps quietly → make "connected apps" an account change that needs approval.
  • Receipts are skipped when busy → one line per action is enough; do it right after the action.

Take it further

  • Before connecting tools: read Connect Claude to Gmail, Drive and Calendar safely and use this rules file as step one.
  • Project instructions: paste the five human-owned actions at the top of your Project instructions. See Set up a Claude Project as your business brain.
  • Skills: add a "must stop before" section to any Skill you write. See Write your first Claude Skill for quotes or enquiry replies.
  • Monthly habit: review receipts and tool settings on the same day each month.
  • Related: Check the AI's answer before a customer sees it and Before you paste anything into AI: a two-minute safety check.

Quick checklist

  • Inventory of every tool and what it could do.
  • Five human-owned actions written, plus your extras.
  • Named approver and backup; no approver means wait.
  • Every Desk has "may prepare" and "must stop before" lines.
  • Approval card used for every action; evidence opened.
  • No write action set to "always allow" in any tool.
  • Real-stop and false-stop tests done and recorded.
  • Receipts kept; monthly review in the calendar.