Who it is for
For people who want to put real permissions, guardrails, and monitoring around their agents — so they get the work without the runaway risk or runaway bill.
Set the permissions, guardrails, and monitoring that let agents work for you without going rogue or running up the bill.

Agents rarely "go rogue" on their own. They do exactly what loose permissions and missing controls allow — as the widely reported PocketOS database deletion showed. You'll learn to diagnose the three control gaps behind most agent failures: over-broad access, unbounded actions, and zero visibility.
You'll walk away with an agent register, risk tiers, permission specs, a guardrail checklist, a spend model, a monitoring dashboard, and an incident plan. Seven working artifacts, not seven theories.
For people who want to put real permissions, guardrails, and monitoring around their agents — so they get the work without the runaway risk or runaway bill.
You connected an agent to your support inbox to draft replies, and to ship fast you handed it the same API token your team uses. Now it has full read and write across every mailbox, the power to send, archive, and delete, and access to the billing records linked from each ticket.
You scoped your support agent to read and draft email but never send. You'll see why "good" isn't the end of the story.
For fifty-one minutes before the circuit breaker tripped at 2:14 a.m., your agent retried the same failed API call — same error, same tool, slightly different arguments each time, every attempt logged to a file nobody was watching. The breaker stopped the spend; the blind spot didn't.
Fifty-one minutes. The monitoring worked — the trust score slid, an alert fired, an owner saw it. What you do in the next ninety seconds sets the bill.
You'll be tempted to fix agent risk in the prompt — telling it to "be careful," "never delete anything," "always confirm first." Treat that as a hint, not a control. An instruction the agent can ignore, misread, or be talked out of through prompt injection is no guardrail at all.
Take "respond to customer emails." If the agent drafts a reply that a support rep reads and sends, it's Tier 1 — the human is the send button, and a bad draft costs nothing but a glance. Let that same agent auto-send without review and it jumps to Tier 3.
Standing privilege stays invisible until you go looking, and this worksheet is the exercise that finds it. Run it on every Tier 2 and Tier 3 agent now, then on a recurring cadence — agent name, tier, and the access each one actually holds.
Take the inbox agent from the opening and see its access before and after least privilege — written in a spec format you can paste straight into a ticket for engineering. Before: one shared team token with full mailbox read/write, billing scopes, and wildcard reach. After: scoped tight.

EPUB, PDF, and HTML are included so the book can work on an e-reader, as a designed copy, or as a searchable desk reference.
For e-readers and reading apps.
The designed edition with diagrams and layouts intact.
Searchable, copy-pasteable, and practical as a reference.
Yes. You get the complete edition, including the chapter sequence and internal materials described on this page.
EPUB, PDF, and HTML are included so you can read on an e-reader, keep a designed copy, or use the searchable browser version.
Because this is an instant digital download, broad change-of-mind refunds are not offered after the files have been accessed. Refund requests are reviewed within 7 days for duplicate purchases, accidental purchases before access, access failures we cannot fix, wrong files, corrupted files, or pages that materially misdescribe the book.