Giving an AI agent access to your inbox or booking calendar tells it where it's allowed to go. It doesn't tell it what to actually do once it's there. Guardrails are the second, separate step — the rules that keep an agent from quoting the wrong price, promising something you can't deliver, or handling a situation it was never built for. Here are five to put in place before any agent talks to a customer without you watching.
A guardrail is a rule that limits what an AI agent is allowed to decide on its own, separate from what systems it can access. Five worth setting up before an agent handles anything customer-facing: cap what it can offer or spend without approval, restrict which topics it can discuss unsupervised, make "I don't know, let me check" an acceptable answer instead of a guess, build in specific triggers that hand a conversation to a person, and test the failure cases on purpose before go-live rather than discovering them from an actual customer. Access controls decide where an agent can go. Guardrails decide what it does when it gets there — and most of the embarrassing AI stories you've read about came from skipping the second one.
If you've already thought about AI agent security, you've probably thought about access: which inbox it can read, which calendar it can book into, whether it can see your customer list. That's the right first question. But it's not the only one, and answering it doesn't finish the job. An agent can have exactly the right, narrowly scoped access — say, your booking calendar and nothing else — and still make a call you'd never have made yourself: double-booking a slot to be helpful, promising a same-day appointment your team can't actually deliver, or replying to a frustrated customer in a tone that makes things worse instead of better. None of that requires broader access. It requires a decision the agent made on its own, inside the access it already had.
That gap between "what it can reach" and "what it's allowed to decide" is exactly what guardrails are for. And it's not a small-business-only concern — it's showing up at the highest level of enterprise AI spending, too. Gartner, the research and advisory firm, predicted in a June 2025 press release that over 40% of agentic AI projects will be canceled by 2027, citing escalating costs, unclear business value, and inadequate risk controls as the leading causes.1 Big companies with dedicated AI teams are hitting this same wall. A small business without one has even more reason to build the rails in before turning an agent loose, not after something goes wrong.
None of these require you to understand how the underlying AI model works. They're business rules, stated in plain language, that get applied to whatever the agent decides before it acts.
Decide, in dollars, what an agent is never allowed to give away on its own — a discount over $50, a refund over $100, a free add-on, whatever number actually matters to your margins. Below that number, it can act. Above it, it drafts the offer and waits for your okay. This single rule prevents the most common and most expensive agent mistake: an agent trying to be helpful by offering something nobody would have approved if they'd been asked first.
An agent handling appointment scheduling doesn't need an opinion on a competitor's pricing, a medical or legal question, or a complaint that's heading toward a threat of legal action. Give it a short, explicit list of topics that are always off-limits for an unsupervised reply — the agent should recognize the topic and hand it to a person instead of improvising an answer. This is called a guardrail, in the plain sense of the word: not a permission setting, but a rule about acceptable behavior that applies even within permissions the agent already has.
AI models are built to produce a confident-sounding answer, even when the honest answer is "I'm not sure." Left alone, an agent will often guess rather than admit it doesn't know — which is fine when it's guessing about your store hours, and a real problem when it's guessing about a warranty policy or a medical restriction. Explicitly tell the agent, and confirm with whoever set it up, that saying "let me get you the exact answer from a person" is a correct, complete response, not a failure. That one instruction closes off a large share of the confidently-wrong-answer problem before it starts.
Take the free 2-minute readiness assessment
"Use good judgment" isn't a guardrail an AI agent can actually follow — it's not specific enough to act on. Instead, list concrete triggers that always hand the conversation to a person: the words "cancel," "lawyer," or "refund my whole order," three unanswered follow-ups in a row from the same customer, or any message that reads as angry rather than neutral. Specific triggers are testable. Vague instructions aren't.
Before an agent goes live, run it through the scenarios you're worried about — a customer trying to get a bigger discount than allowed, a question outside its topic list, an angry message — and check that the guardrails actually catch them. Don't wait for a live customer to discover the gap for you. This is the same instinct as testing a new hire on a few hard cases before their first solo shift; it costs you twenty minutes and saves you a genuinely bad conversation with a real customer later.
Picture a small landscaping company using an agent to answer inbound quote requests by text. Without guardrails, a customer asks for a discount to match a competitor's quote, and the agent — trying to close the job — agrees to knock $150 off a $600 job, a margin call nobody signed off on. With a $50 no-approval cap in place, the same conversation goes differently: the agent tells the customer it will check with the owner and get back to them within the hour, drafts the discount request, and a person approves or adjusts it before anything is promised. The customer still gets a fast reply. The business doesn't quietly lose margin on every job where someone happens to ask.
It's a fair worry — if every decision needs a human, what did the agent actually save you? The honest answer is that guardrails are narrow by design. A well-set-up agent still handles the large majority of routine cases entirely on its own; the caps and triggers only pull in a person for the specific situations — real money, real risk, real ambiguity — where you'd want that anyway. As one small business owner might put it, describing a realistic but illustrative scenario: "I was worried the discount cap would slow everything down. In practice it catches maybe one conversation in twenty. The other nineteen go through without me touching them, and the one it flags is always one I'm glad I saw before it went out." The goal isn't zero autonomy. It's autonomy with a backstop in exactly the places that matter.
Every agent we set up ships with these guardrails configured before it ever talks to a customer — spending caps, topic restrictions, and escalation triggers written in plain language you approve, not buried in a settings file you'd need a developer to read. That matters for trust, but it also matters for how fast a business is willing to expand what it automates: owners who can see exactly where the rails are tend to hand over a second workflow within weeks, because the first one never produced a surprise. Owners who can't see the rails tend to stay nervous about the one agent they already have, which caps how much time — and revenue — the system ever ends up recovering.
We back this with a real guarantee, not a vague promise: try Unmanually for 60 days, and if it isn't the right fit, whatever's left of your prepaid balance converts to account credit. That's not a cash refund on usage you've already consumed, since that reflects real infrastructure cost already spent, but it does mean you're not taking on a new kind of risk and a financial one at the same time.
Not ready to set up an agent yet? That's completely fine — leave your email on our presale waitlist and we'll let you know as soon as our guardrail and escalation-trigger tools are live for new customers, including founding-member presale pricing before it opens to everyone else this October.
1. Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by 2027," press release, June 25, 2025 (cites escalating costs, unclear business value, and inadequate risk controls as the leading causes of cancellation).
The full pillar guide this article belongs to.
The access-control side of this same problem — what an agent can reach in the first place.
The oversight patterns that pair naturally with guardrails.
Once it's safely guardrailed, here's how to tell if it's actually paying for itself.
Start here if you're not yet sure what you'd even be setting rules for.
A guardrail is a rule that limits what an AI agent is allowed to do on its own, separate from what it has permission to access. Access controls decide which systems an agent can touch, like your calendar or your inbox. Guardrails decide what it's allowed to do once it's in there — for example, it can access your pricing system, but a guardrail says it can never offer a discount over $50 without a person signing off first.
Yes. Limited access controls what the agent can reach, not what it decides to do within that reach. An agent scoped only to your booking calendar can still double-book a slot, promise a same-day appointment you can't deliver, or word a reply in a way that upsets a customer — none of which requires broader access to go wrong. Guardrails are the rules that catch those mistakes regardless of how narrow the access already is.
Take our free 2-minute readiness assessment — it walks through what to automate first at your business, and where you'd want a guardrail from day one.
Take the 2-min readiness assessment