All posts
Operational Intelligence28 August 2026

The best AI agents ask before they act

Dark graphic of a wide network of small pale nodes joined by faint connecting lines, a scattering of them highlighted in coral, with one node picked out in a coral-outlined card, beside the words "Autonomy is earned".

Full autonomy is the headline feature everyone wants until an agent sends the wrong email to the wrong client. Approval-based agents look slower on a demo and win on the only metric that matters: whether the business keeps using them in month three.

There is a particular kind of silence that follows an AI agent doing exactly what it was told.

It sent the follow-up. It sent it to the client who had emailed that morning to say a family member had died. Nothing in the instruction was wrong, and nothing in the system was broken. The agent had a rule about dormant threads and it applied that rule faithfully, because that is what rules do.

Most conversations about agent autonomy treat moments like that as edge cases to be engineered away. They are not edge cases. They are the ordinary texture of running a business, and they are the reason the autonomy question is not really a technical question at all.

Autonomy is not the thing being bought

The pitch for fully autonomous agents is intuitive. Work goes in, work comes out, nobody touches it. Every step a human takes is friction, and friction is what software is for.

That logic holds right up until you ask who carries the consequence. In a large organisation an agent's mistake lands in a queue, gets caught by a process, and becomes a line in a quarterly review. In a twelve-person business it lands on a named client relationship that took four years to build, and the person who has to make the phone call is usually the person who approved the tool.

So the thing being bought was never autonomy. It was leverage without exposure. Those get bundled together in most product marketing, and they come apart the first time an agent is confidently wrong in front of a customer.

The failure mode is abandonment, not disaster

The interesting part is what happens next, because it is rarely dramatic.

Almost nobody rips out an agent after one bad send. What happens instead is quieter. Someone starts checking the agent's output before it goes anywhere. Then someone starts checking the output of the checks. Within a few weeks the agent is doing the same work as before and a human is doing all of it again alongside, and the honest description of the system is that it costs more than it saves.

That is the real failure mode for AI in smaller businesses, and it is almost never reported as failure. It gets recorded as a pilot that did not quite land, or a tool that was not the right fit. The agent kept working perfectly. It just stopped being trusted, and an untrusted agent is a second copy of a job.

Approval is where trust gets built, not where it gets tested

Put an approval step in front of the same agent and something different happens.

The agent monitors. It connects a LinkedIn reply to an email thread to a note in the CRM, works out that these three things are one relationship rather than three, drafts what should happen next, and stops. A person reads a draft that took four seconds to produce, spends fifteen seconds on it, and either sends it or does not.

The fifteen seconds are not friction. They are the mechanism by which a business finds out whether the agent is any good, on real work, at a survivable cost of being wrong. And they are self-liquidating: after two hundred approvals where the answer was obviously yes, teams start widening what the agent handles alone, because they have evidence rather than a vendor's assurance.

This is the direction the trust runs that most autonomy pitches get backwards. Autonomy is not the setting you begin with and defend. It is the thing an agent earns, one category of work at a time.

A working line between the two

The useful question is not how autonomous an agent should be. It is which specific actions it should take without asking, and the answer follows a fairly clean rule: an agent can act alone when the action is reversible and internal, and should ask when it is irreversible or external.

Reading, monitoring, structuring, summarising, tagging, linking records, drafting, flagging, queuing, preparing a report nobody has read yet: all reversible, all internal, all fine to run unattended. If the agent gets one wrong, someone deletes it and the world is unchanged.

Sending, replying, posting, committing to a date, quoting a price, updating a record other people will rely on, escalating to a client: irreversible or external, or both. These are the actions where being wrong costs something that cannot be un-spent, and they are worth a human glance.

Drawn that way, the boundary is not a compromise between speed and safety. Nearly all of the volume, the reading and connecting and drafting that consumes the working day, sits on the unattended side. What stays behind an approval is the small set of moments where judgement was always the point.

What this looks like in practice

Kritmatta's agents are built on this shape deliberately. They watch across email, CRM, LinkedIn, messaging and internal documents, resolve the same person or company or opportunity showing up in different places into one connected piece of work, and queue the next action for a human to approve. The intelligence runs continuously. The commitment stays with a person.

More than 60 per cent of registered users have an active agent running within 24 hours of signing up, and the approval step is part of why. Nobody has to bet a client relationship on a tool they configured that morning, which makes the first agent a small decision rather than a large one.

The question worth asking a vendor

If you are evaluating agents, the autonomy slider is not the thing to look at. Ask three things instead.

What does this agent do without asking me, stated as a list of specific actions rather than a capability. What happens when it is wrong, and who finds out first. And can I move an action from the approval queue to unattended once I trust it, or is the boundary something the vendor decided on my behalf.

A product that can answer those clearly has thought about being lived with. A product that answers by describing how autonomous it is has thought about being demonstrated.

The agents that survive contact with a real business are rarely the most independent ones. They are the ones that knew which four seconds of work were theirs, and which fifteen seconds were not.

Want to see it in action?

Book a quick call and we'll show you how Kritmatta works for your team.