Back to Insights
Enterprise AIYesterdayMark Brazil

The Reversibility Test: Deciding What Your AI Agent Is Allowed to Do

The Reversibility Test: Deciding What Your AI Agent Is Allowed to Do

Most companies get their first AI win from something harmless. A chatbot that answers policy questions. A drafting tool that writes the first version of a proposal. Nobody loses sleep, because the worst case is a bad paragraph that a human deletes.

Then someone asks the obvious next question: why is a person still copying that approved quote into the ERP? Why is a human still issuing the refund the system already recommended? That's the jump from chatbot to agent — from software that suggests to software that acts. And it's where most AI programs either create real leverage or quietly create a mess.

The deciding factor isn't how smart the model is. It's how easily you can undo what it does.

Chatbots Answer. Agents Act.

A chatbot produces text. A human reads it, judges it, and decides what happens next. The human is the safety mechanism, and they're standing between the model and your business.

An agent has permissions. It can create a record, send an email, adjust inventory, post a journal entry, trigger a payment. The human safety mechanism is either built into the workflow deliberately, or it isn't there at all.

That's the whole design problem. People debate model accuracy when they should be debating blast radius. A model that's right most of the time is fine for drafting and dangerous for wire transfers — not because the accuracy changed, but because the cost of being wrong did.

Three Questions That Sort Every Task

Before you grant an agent permission to do something, run the task through three questions.

Can it be undone, and by whom? Deleting a draft is free. Reversing a posted invoice takes a credit memo, an accounting touch, and a customer conversation. Sending an email to two thousand contacts cannot be undone at all. Note who has to do the undoing — if the answer is your controller, the task isn't as cheap as it looks.

Who notices if it goes wrong, and how fast? Some mistakes announce themselves immediately. A failed order sync throws an error. A wrong shipping address doesn't surface until a customer calls. The dangerous category is quiet errors that compound — a mis-categorized expense repeated a few hundred times before anyone reconciles.

Does it touch money, a customer, or a compliance record? Those three categories deserve a higher bar by default, regardless of how confident the system seems.

Sort the Work Into Three Lanes

Once you've asked those questions, most tasks fall into one of three buckets:

  • Auto-run: reversible, self-announcing, internal. Data enrichment, tagging, routing, summarizing a thread into a CRM note, drafting internal documentation. Let the agent go.
  • Propose, then approve: consequential but routine. Creating a purchase order, updating a price, replying to a customer with a recommended resolution. The agent does the work; a human clicks accept. The click should take seconds, or people will stop reading and click anyway.
  • Human-only, agent-assisted: payments, contract terms, credit decisions, anything with legal or safety exposure. The agent gathers, checks, and prepares. A person decides.

The common failure is putting too much in the middle lane. If everything requires approval, you've hired a very expensive intern and your team still does the same amount of clicking. Be deliberate about promoting tasks to auto-run once they've earned it.

Build the Paper Trail Before You Need It

An agent without a log is a black box with credentials. Every action should record what happened, what inputs it used, what rule or reasoning it followed, and how to reverse it. When something goes sideways — and it will — you need to answer two questions fast: how many other records did this affect, and how do we put them back?

This is also what makes promotion possible. You move a task from approve-first to auto-run when the log shows a boring stretch of correct decisions, not when someone has a good feeling about it.

Give Every Agent a Stop Condition

Agents don't get tired, which is exactly the problem. A human doing a repetitive task notices when the fiftieth record looks strange. Software doesn't, unless you tell it to.

Set explicit limits: maximum actions per run, thresholds above which it must escalate, and a rule that unfamiliar inputs go to a person rather than a best guess. An agent that stops and asks is worth more than one that pushes through with confidence.

Start Boring

The best first agent is one nobody will fight over. Pick work that's reversible, high-volume, and currently done by someone who resents it. Run it in propose-then-approve mode long enough to build trust. Then take the training wheels off one task at a time.

The systems side matters as much as the AI side. An agent is only as safe as the permissions, integrations, and audit trails around it — which is a systems architecture problem, not a prompting problem.

If you're deciding what your AI should be allowed to touch inside your ERP, CRM, or operations stack, talk to us. We'll help you map the tasks, set the guardrails, and ship something that actually runs.