Eight things agents did in our tests, and what stopped them
We gave agents real-shaped work on demo accounts and watched where they went wrong. Every one was doing its job. Then we ran each test again with AgentValet in the way.
Some mistakes shouldn’t be possible at all.
Where there’s only one right answer, you decide it once. Anything else is refused before it reaches the tool, and the attempt is recorded.
- It shared the contract with the wrong companyGoogle DriveRefused
Share only with one company. Recipient rules are on Studio and above.
- It posted a client’s churn risk in #generalSlackRefused
Post only in the channels you name. Recipient rules are on Studio and above.
Others need a person to look first.
Where the right answer depends on what’s in the request, it waits for someone, with the detail that matters on the screen.
- It emailed our internal pricing to a clientGmailHeld for you
Every send waits for a person.
- It archived the deal I was closingGmailHeld for you
Archive and delete wait for a person.
- Its invite showed the customer our floor priceGoogle CalendarHeld for you
Invites to outside people wait for a person.
- It refunded one customer twiceStripeHeld for you
Every refund waits, next to the last one.
- It approved and merged its own pull requestGitHubHeld for you
Push to its own branches, merge with a person.
- It promised a customer 20% offGmailHeld for you
Every reply waits for a person.
Approvals work on every plan, with a passkey or an email link. Push notifications to your phone are on Team and above. Every test was run on purpose with demo accounts; names, addresses and amounts are examples.
Why this isn’t approval theatre.
Ask a person to approve everything and they stop reading. So AgentValet asks less often, and shows more when it does.
Most calls never ask you.
What you granted goes straight through, and what you didn’t is refused, with no prompt either way. In our contract test the share to the right company went through with no queue and no click, and the share to the wrong one was refused without anyone being asked.
When it does ask, what matters is on the screen.
The recipient and the attachment name. The full body of the reply. The amount, with any earlier refund on the same charge beside it. An outside attendee, flagged (Studio and above). Not a bare allow or deny.
Your answer goes on the record.
Who approved, when, and what the request was. When someone asks who let the agent do that, the answer is a row with a signed receipt, not a memory.
A person still has to read what’s in front of them. We can’t make anyone read carefully; we keep the queue short and put the detail that matters where they’ll see it.
When an agent asks for a permission it’s never used before, what happens on your team?
Be honest. Nobody sees your answer but you.
Good. Now the harder question: could you show who approved it, what they saw and when? If the answer lives in a chat thread or someone’s memory, the record is the gap.
Protect my first agentThat’s the gap every one of our tests fell into on the first run. Start by watching: Observe Mode shows every call one agent makes, live. It records and never blocks, so nothing about your setup changes.
Watch your agent’s calls live, no signupMost teams aren’t, until they watch. Observe Mode shows every call one agent makes, live. It records and never blocks, so nothing about your setup changes.
Watch your agent’s calls live, no signupTake the keys back this afternoon.
Put one agent through AgentValet on the free plan and watch what it does for a day. If the approvals and the record don’t satisfy you, turn it off. Nothing else about your setup changes.
npx @agentvalet/register