Work with your AI agent

What your AI agent should never send without you

Should an AI agent email clients on its own? What it can do alone, what it should never send without you, and how a one-person AI agency approves one version.

By Volant team

A web designer asks her agent to "follow up with the florist about the launch date". It's late, she's tired, and the agent is connected to her email. In the morning she finds it did exactly that. The email is polite and clear. It also says the site will launch "this Friday", which was her private target, not something she'd promised. The florist has already told her staff.

Nothing went badly wrong. But a promise went out that she didn't make, in her name, to a client. That's the line this post is about, for anyone using AI agents for client work.

An AI agent should not send anything to a client, the public or anyone's money without you approving that exact version first. Let it research, draft, build and check as much as you like. When something is about to leave your computer with your name on it, the final yes is yours.

Should an AI agent email clients on its own?

No, and not because agents write badly. They often write well. The problem is that every message to a client carries promises: dates, prices, what's included, what you'll do next. The agent doesn't know which of your thoughts are commitments and which are hopes. It can't know that the florist's Friday was a hope.

So split the work in two:

  • The agent drafts. It has the brief, the history and the facts. Let it write the email, the quote, the reply.
  • You approve, then it sends. You read the draft, change what needs changing, and approve that version.

You keep the speed of the agent's drafting, and you keep your word. How to review your agent's work before a client sees it covers the same idea for websites.

What should an AI agent never send without you?

A simple test: does it leave your computer and reach a client, the public or someone's money? If yes, it waits for you.

Never without your approval Why
Emails and messages to clients They carry promises, dates and tone
Quotes, prices and scopes They're commitments you'll be held to
Invoices and payment links They ask someone for money
Publishing a website or a change The public sees it immediately
Replies to reviews They're public and permanent
Social posts Same as above, with your name on them
Domain, DNS or hosting changes They can take a client's site or email offline
Calls or texts to a client's customers They speak for the client, and rules apply
Deleting anything It may not come back

And the work it can do on its own, because it stays with you:

  • Researching a business before a pitch.
  • Drafting any of the above.
  • Building and changing a site in a preview.
  • Checking links, forms and pages.
  • Summarising a thread or a call.
  • Tidying your own notes and to-do list.

The agent can work hard on the left column. It just can't press send.

What does approving one exact version mean?

It means your yes applies to one specific draft, going to one specific place, and nothing else. If the draft changes after you approve it, even by one line, it comes back to you.

That sounds strict. It's there to stop a quiet problem. You approve an email, then ask the agent to "just add the invoice link", and the version that goes out isn't the one you read. Or you approve the site for the client's review, and a later fix goes live with it. Approving the exact version closes that gap. Approving one exact version explains the idea in a few paragraphs.

How do you set this up with your agent?

Two layers: what you tell the agent, and what the tools let it do.

Tell it the rule. Put it in the instructions your agent reads at the start of every session: "Draft messages to clients, never send them. Show me the draft and wait." Put your client facts there too, so drafts start from the right dates and prices; giving your AI agent a client brief it won't forget shows how.

Make the tools enforce it. Instructions shape what an agent tries to do. They don't change what it's allowed to do. Claude Code, for example, has permission settings with allow, ask and deny rules, and asks before actions such as running commands or editing files unless you've allowed them. Use those settings so that anything that sends or publishes asks you first.

Connections matter here too. When your agent connects to your email or other programs through MCP (a standard way to connect AI programs to other programs), the MCP specification's security principles say users must explicitly consent to and understand operations, and that hosts must get explicit consent before using any tool. That's the standard's intent. Whether a particular connected program waits for you depends on that program and your settings, so check each one. What MCP changes for agency work and what MCP means cover the basics.

What if a message is urgent?

Urgent is exactly when a wrong message costs most. A client's site is down, they're anxious, and a reply that promises "fixed within the hour" is tempting to send. If it isn't fixed in the hour, you've made a bad morning worse.

So keep the rule, and keep the first message short. Ask the agent for a short draft that says what you know and when you'll next update them: "We've seen the problem and we're on it. Next update by 11." It takes a moment to read and approve, and it promises only what you can keep.

Doesn't approving everything slow you down?

It adds one read before each send. That's the whole cost. The agent still researches, drafts and checks; you're reading finished work, not writing it.

Compare that with the cost of one wrong message: a date you now have to walk back, a price you'll be held to, a review reply that stays public. For a one-person agency, where your word is most of your reputation, the read is cheap.

A few habits make it faster:

  1. Batch approvals. Look at drafts twice a day rather than every time one appears.
  2. Ask for a one-line summary with each draft. "Confirms Friday launch, asks for final photos." You'll spot the wrong promise in the summary.
  3. Keep a short list of phrases you never use. "Guarantee", "by tomorrow", "free". Ask the agent to flag any draft that contains them.
  4. Approve in the same place every time. So nothing slips through a side door.

What about the florist?

In the version with approval, the agent drafts the same polite email. She reads it in the morning, sees "this Friday", changes it to "the week of the 30th, once you've approved the final pages", and approves that version. It goes out. The florist plans around a date that's real.

The agent did the same work. The difference is who said yes.

Where Volant fits

In Volant, anything that's sent or published waits for your approval. Your agent drafts; you read and approve the exact version before it goes. The approvals page shows how that works for messages, quotes, invoices and websites.

Questions

Questions people ask

Should an AI agent email clients on its own?
No. Let it draft the email, then read and approve that exact version before it goes. Anything that reaches a client carries your name and your promises, so the final yes should be yours.
What can an AI agent do without my approval?
Work that stays on your side: research, drafting, building in a preview, checking, summarising and tidying your own notes. The line is anything that leaves your computer and reaches a client, the public or someone's money.
What does approving the exact version mean?
You approve one specific draft, going to one specific place. If the agent or anyone else changes it after you approved it, it comes back to you before it goes out.
Doesn't approving everything slow me down?
It adds a read before each send. The agent still does the drafting, so you're approving finished work rather than writing it. For a one-person agency, a wrong email or a wrong price costs far more time than the read.
Does MCP mean my agent can send email by itself?
Not by itself. MCP is a way to connect an agent to other programs. The MCP specification says hosts must get the user's explicit consent before using a tool, but whether a connected program waits for your approval depends on that program and your settings.

Start here

Try one ideaon your next client.

Every how-to here works with a simple notes file. Keep the ones that help, and let Volant keep track when you're ready.

For Mac and Windows. Works with Claude Code.

Join the waitlist