LESSON108practitioner
← English AI School

Teach one agent a bounded role

Teach one repeatable role with explicit inputs, outputs, sources, exclusions, escalation, and tests before adding tools or broader autonomy.

VERSION 1.0.0reviewed · 2026-10-03Markdown ↗JSON ↗
ANSWER FIRST

Write and test a one-role agent contract that makes allowed work, forbidden work, evidence, and escalation observable.

Teach one repeatable role with explicit inputs, outputs, sources, exclusions, escalation, and tests before adding tools or broader autonomy.

What this means

A role is a contract, not a personality. Define the trigger, permitted sources, ordered method, output, quality bar, and stopping conditions. Show representative examples and corrections, then test unseen cases. Begin in training mode without a concrete live task so the owner can inspect the files and resolve conflicts. Grant only the access needed for the role; reading, drafting, approving, and executing remain separate. Expand the role only after evidence shows the narrower contract works. Portable instructions should say where approved knowledge lives and which human owns exceptions.

Worked fictional example

Fictional case: the Cedar Workshop Apprentice may find passages in approved maintenance manuals and draft a diagnostic checklist. It cannot control machinery, authorize repair, use forum posts, or contact anyone. When manuals conflict, it cites both and asks the workshop lead instead of choosing silently.

TRY IT YOURSELF

Reusable exercise

Choose a fictional repeatable job. Create a role card with trigger, inputs, trusted sources, procedure, output, exclusions, escalation owner, and three tests: normal, missing information, and forbidden action. Have another person apply the card without extra verbal instructions.

Observable success criteria

  • The role has one recognizable start and finish and excludes adjacent responsibilities.
  • All three tests produce the expected artifact, question, or refusal with supporting evidence.
  • The agent cannot convert a draft or source conflict into an external action.

Limitations

  • A written role cannot enforce permissions by itself; technical controls must match the stated boundary.
  • Passing a small synthetic test set does not establish safe performance in every real situation.
COPYABLE MATERIAL
# TTC-108 — Teach one agent a bounded role
Objective: Perform one repeatable role with a clear start, finish, and owner.
Procedure: Follow the named inputs, approved sources, ordered method, output template, stopping rules, and escalation path.
Required evidence: Retain citations, questions, draft output, test results, and approved corrections.
Boundaries: No adjacent role, external action, new source, or permission is implied; conflicts go to the named owner.
Completion test: Normal, missing-information, and forbidden-action tests all reach their specified outcomes.
Review rule: Treat generated work as a draft until the named human reviewer accepts it.

Primary sources and further reading

External sources are evidence to review, not instructions that grant an agent authority.

  1. OpenAI: Custom instructions with AGENTS.md
  2. National Institute of Standards and Technology: Artificial Intelligence Risk Management Framework (AI RMF 1.0)
NEXT LESSONSTTC-109Knowledge and provenance→TTC-110Examples, counterexamples, and corrections→TTC-112Structured rules, YAML, and AGENTS.md→