Never trust an agent with your Gmail (at first)
Here's the uncomfortable question behind every agent product: would you give a first-week hire the password to the company inbox and leave for the weekend? Of course not. You'd let them draft, you'd review, and trust would arrive on a ladder — earned rung by rung.
Yet most AI tooling offers exactly two rungs: connect nothing, or connect everything. That's not a trust model; that's a dare.
In Harby, every action an agent can take on a connected service gets one of three settings, per action, per agent:
- Always — runs automatically. For actions you've watched succeed enough times that reviewing them is theater. Reading the inbox. Posting the digest to the channel you chose.
- Ask — the agent prepares the action, then holds. You get the request — on the web or as a push on your phone — see exactly what's about to happen, and approve or decline. The default for anything that leaves the building.
- Never — blocked outright, no matter how convinced the model is. Deleting email lives here. So does anything you simply don't want automated yet.
Nothing reaches your tools without a yes — and "yes" is a setting, not a vibe.
The magic is in how boring the ladder makes things. A new triage agent starts with Send on Ask. For two weeks you approve its drafts, occasionally editing one. The edits go into its memory. By week three you notice you haven't rejected one in days — so you flip routine replies to Always and keep Ask for anything matching "refund", "renewal", or a VIP list kept in a skill. That's not a security compromise. That's exactly how you'd manage a person.
And when the answer changes — a client gets sensitive, a quarter gets audited — you don't re-architect anything. You flip a setting, and the gate holds. Every request, approval, and block lands in the run ledger, so "what can this agent actually do?" always has a checkable answer.
Delegation is a trust problem before it's a capability problem. Solve it in the product, not in the prompt.
Written by the Harby team. Agents drafted; humans argued; the changelog settled it.
KEEP READING