AI Agents / Intermediate

Keep Your Agents in Check

Set the permissions, guardrails, and monitoring that let agents work for you without going rogue or running up the bill.

8 chaptersEPUB + PDF + HTMLIntermediate guide pricingDRM-free files
Keep Your Agents in Check book cover
The problem

It starts with the situation you're actually in.

Agents rarely "go rogue" on their own. They do exactly what loose permissions and missing controls allow — as the widely reported PocketOS database deletion showed. You'll learn to diagnose the three control gaps behind most agent failures: over-broad access, unbounded actions, and zero visibility.

You'll walk away with an agent register, risk tiers, permission specs, a guardrail checklist, a spend model, a monitoring dashboard, and an incident plan. Seven working artifacts, not seven theories.

Who it is for

For people who want to put real permissions, guardrails, and monitoring around their agents — so they get the work without the runaway risk or runaway bill.

Outcomes

What you'll be able to do.

The privilege you forgot you granted

You connected an agent to your support inbox to draft replies, and to ship fast you handed it the same API token your team uses. Now it has full read and write across every mailbox, the power to send, archive, and delete, and access to the billing records linked from each ticket.

The door was locked. The agent was already inside.

You scoped your support agent to read and draft email but never send. You'll see why "good" isn't the end of the story.

You govern at the speed you can see

For fifty-one minutes before the circuit breaker tripped at 2:14 a.m., your agent retried the same failed API call — same error, same tool, slightly different arguments each time, every attempt logged to a file nobody was watching. The breaker stopped the spend; the blind spot didn't.

The first ninety seconds decide the cost

Fifty-one minutes. The monitoring worked — the trust score slid, an alert fired, an owner saw it. What you do in the next ninety seconds sets the bill.

Inside the book

A closer look at the work inside.

Control the system, not the model

You'll be tempted to fix agent risk in the prompt — telling it to "be careful," "never delete anything," "always confirm first." Treat that as a hint, not a control. An instruction the agent can ignore, misread, or be talked out of through prompt injection is no guardrail at all.

The same task, two different tiers

Take "respond to customer emails." If the agent drafts a reply that a support rep reads and sends, it's Tier 1 — the human is the send button, and a bad draft costs nothing but a glance. Let that same agent auto-send without review and it jumps to Tier 3.

Run an access review

Standing privilege stays invisible until you go looking, and this worksheet is the exercise that finds it. Run it on every Tier 2 and Tier 3 agent now, then on a recurring cadence — agent name, tier, and the access each one actually holds.

When a permission spec is ready to ship

  • The agent is bound to an RBAC role, not a human's personal token.
  • Every credential is scoped by action and resource, with no wildcards.
  • Tokens are short-lived with an expiry, not permanent.
  • Each tool has an explicit allow list; irreversible actions are on a deny list.
  • Every remaining permission maps to a written task the agent performs.
  • A named owner and a next-review date are attached.

Worked example: re-scoping the support drafter

Take the inbox agent from the opening and see its access before and after least privilege — written in a spec format you can paste straight into a ticket for engineering. Before: one shared team token with full mailbox read/write, billing scopes, and wildcard reach. After: scoped tight.

Keep Your Agents in Check visual framework
Control the system, not the modelInside the book
Visual preview

A diagram you can keep open while you work.

Table of contents

8 chapters, built to be read in order.

01

Why Good Agents Go Bad

02

Inventory and Risk-Tier Every Agent

03

Set Permissions With Least Privilege

04

Build Guardrails Agents Can't Talk Their Way Around

05

Cap the Spend Before It Caps You

06

Monitor, Log, and Score Trust

07

Respond When an Agent Crosses the Line

08

Your Agent Governance Operating System

156
Pages
12,840
Words
33
Exercises, checklists & tools
8
Chapters
Formats

Three formats. One purchase.

EPUB, PDF, and HTML are included so the book can work on an e-reader, as a designed copy, or as a searchable desk reference.

EPUB

For e-readers and reading apps.

PDF

The designed edition with diagrams and layouts intact.

HTML

Searchable, copy-pasteable, and practical as a reference.

Complete guide

Keep Your Agents in Check

$9.99
Intermediate guide pricing
  • EPUB + PDF + HTML included in one purchase
  • 8 chapters from the complete guide
  • DRM-free files for your own devices
  • 7-day refund review for duplicate purchases, access issues, wrong files, or materially defective downloads
Add to cart - $9.99
Secure checkout / instant download / tax handled at checkout
Before you buy

Questions, answered.

Does this include the full book?

Yes. You get the complete edition, including the chapter sequence and internal materials described on this page.

Which formats are included?

EPUB, PDF, and HTML are included so you can read on an e-reader, keep a designed copy, or use the searchable browser version.

What is the refund policy?

Because this is an instant digital download, broad change-of-mind refunds are not offered after the files have been accessed. Refund requests are reviewed within 7 days for duplicate purchases, accidental purchases before access, access failures we cannot fix, wrong files, corrupted files, or pages that materially misdescribe the book.