What your AI agent should never send without you
Should an AI agent email clients on its own? What it can do alone, what it should never send without you, and how a one-person AI agency approves one version.
A web designer asks her agent to "follow up with the florist about the launch date". It's late, she's tired, and the agent is connected to her email. In the morning she finds it did exactly that. The email is polite and clear. It also says the site will launch "this Friday", which was her private target, not something she'd promised. The florist has already told her staff.
Nothing went badly wrong. But a promise went out that she didn't make, in her name, to a client. That's the line this post is about, for anyone using AI agents for client work.
An AI agent should not send anything to a client, the public or anyone's money without you approving that exact version first. Let it research, draft, build and check as much as you like. When something is about to leave your computer with your name on it, the final yes is yours.
Should an AI agent email clients on its own?
No, and not because agents write badly. They often write well. The problem is that every message to a client carries promises: dates, prices, what's included, what you'll do next. The agent doesn't know which of your thoughts are commitments and which are hopes. It can't know that the florist's Friday was a hope.
So split the work in two:
- The agent drafts. It has the brief, the history and the facts. Let it write the email, the quote, the reply.
- You approve, then it sends. You read the draft, change what needs changing, and approve that version.
You keep the speed of the agent's drafting, and you keep your word. How to review your agent's work before a client sees it covers the same idea for websites.
What should an AI agent never send without you?
A simple test: does it leave your computer and reach a client, the public or someone's money? If yes, it waits for you.
| Never without your approval | Why |
|---|---|
| Emails and messages to clients | They carry promises, dates and tone |
| Quotes, prices and scopes | They're commitments you'll be held to |
| Invoices and payment links | They ask someone for money |
| Publishing a website or a change | The public sees it immediately |
| Replies to reviews | They're public and permanent |
| Social posts | Same as above, with your name on them |
| Domain, DNS or hosting changes | They can take a client's site or email offline |
| Calls or texts to a client's customers | They speak for the client, and rules apply |
| Deleting anything | It may not come back |
And the work it can do on its own, because it stays with you:
- Researching a business before a pitch.
- Drafting any of the above.
- Building and changing a site in a preview.
- Checking links, forms and pages.
- Summarising a thread or a call.
- Tidying your own notes and to-do list.
The agent can work hard on the left column. It just can't press send.
What does approving one exact version mean?
It means your yes applies to one specific draft, going to one specific place, and nothing else. If the draft changes after you approve it, even by one line, it comes back to you.
That sounds strict. It's there to stop a quiet problem. You approve an email, then ask the agent to "just add the invoice link", and the version that goes out isn't the one you read. Or you approve the site for the client's review, and a later fix goes live with it. Approving the exact version closes that gap. Approving one exact version explains the idea in a few paragraphs.
How do you set this up with your agent?
Two layers: what you tell the agent, and what the tools let it do.
Tell it the rule. Put it in the instructions your agent reads at the start of every session: "Draft messages to clients, never send them. Show me the draft and wait." Put your client facts there too, so drafts start from the right dates and prices; giving your AI agent a client brief it won't forget shows how.
Make the tools enforce it. Instructions shape what an agent tries to do. They don't change what it's allowed to do. Claude Code, for example, has permission settings with allow, ask and deny rules, and asks before actions such as running commands or editing files unless you've allowed them. Use those settings so that anything that sends or publishes asks you first.
Connections matter here too. When your agent connects to your email or other programs through MCP (a standard way to connect AI programs to other programs), the MCP specification's security principles say users must explicitly consent to and understand operations, and that hosts must get explicit consent before using any tool. That's the standard's intent. Whether a particular connected program waits for you depends on that program and your settings, so check each one. What MCP changes for agency work and what MCP means cover the basics.
What if a message is urgent?
Urgent is exactly when a wrong message costs most. A client's site is down, they're anxious, and a reply that promises "fixed within the hour" is tempting to send. If it isn't fixed in the hour, you've made a bad morning worse.
So keep the rule, and keep the first message short. Ask the agent for a short draft that says what you know and when you'll next update them: "We've seen the problem and we're on it. Next update by 11." It takes a moment to read and approve, and it promises only what you can keep.
Doesn't approving everything slow you down?
It adds one read before each send. That's the whole cost. The agent still researches, drafts and checks; you're reading finished work, not writing it.
Compare that with the cost of one wrong message: a date you now have to walk back, a price you'll be held to, a review reply that stays public. For a one-person agency, where your word is most of your reputation, the read is cheap.
A few habits make it faster:
- Batch approvals. Look at drafts twice a day rather than every time one appears.
- Ask for a one-line summary with each draft. "Confirms Friday launch, asks for final photos." You'll spot the wrong promise in the summary.
- Keep a short list of phrases you never use. "Guarantee", "by tomorrow", "free". Ask the agent to flag any draft that contains them.
- Approve in the same place every time. So nothing slips through a side door.
What about the florist?
In the version with approval, the agent drafts the same polite email. She reads it in the morning, sees "this Friday", changes it to "the week of the 30th, once you've approved the final pages", and approves that version. It goes out. The florist plans around a date that's real.
The agent did the same work. The difference is who said yes.
Where Volant fits
In Volant, anything that's sent or published waits for your approval. Your agent drafts; you read and approve the exact version before it goes. The approvals page shows how that works for messages, quotes, invoices and websites.