Five stages. First, bounding it: which process, what the measure of success is, and whether the step can be undone. Second, data and context — an agent is only as good as what it can see, and this is usually where it emerges that some of the necessary knowledge isn’t written down anywhere. Third, architecture and model selection. Fourth, the guardrails: permissions, approval points, fallback logic and an evaluation set. And only fifth, integration and deployment.
An agent never goes into production deciding things straight away. First it runs in shadow mode: it proposes, a person decides, and we compare the two. Only once the agreement rate is high enough and the failure modes are known do we give it authority to act — and even then within narrow bounds at first, on small amounts or low-risk cases.
When choosing a partner, ask what happens when the agent is wrong. If the answer doesn’t contain the words “log”, “approval” and “rollback”, no guardrails have been designed. And ask how it will be measured — without an evaluation set, every claim about an agent’s quality is an opinion.