Sep 4, 2026
High agency, low authority
I keep ending up in the same spot.
An agent has already done the hard part. The briefing is written. The newsletter draft is sitting there with three picks and a voice that is almost mine. The to-dos are proposed. Sometimes even the commit is ready. And I am staring at a button I still want to press myself.
A few months ago I wrote about making my newsletter smart. The short version: AI removes the activation energy. I still decide what ships. That line felt specific to Pixel Perfect Picks at the time. It turned out to be a more general rule than I expected.
The job got easier. The boundary got sharper.
Once agents can prepare complete work products, the interesting question stops being "can it do the job?" It becomes "where does authority end?"
I want high agency. Retrieve the bookmarks. Scan the week. Draft the picks. Analyze the brief. Propose the next actions. Write the thing end to end. Do the substantive work without me hovering over every step like a nervous project manager.
I also want low authority. Sending, publishing, deleting, purchasing, inviting: those stay behind an explicit human commit. The agent can get me to the door. I still open it.
That is not a clever enterprise slogan. It is just how I have been running personal agents lately, and how the newsletter skill already works in public: Shiori to draft to human edit to publish. The AI helps with the part that does not require me. The picks are still mine. The last click is still mine.
What I let run, and what I don't
I get asked versions of the same question a lot: what are you willing to auto-run without reviewing the artifact first?
Honest answer, today: commits, creating to-dos, writing things, proposing ideas. Basically everything that is good at generating.
That side of the line feels useful. Generation is cheap to reverse. A draft I do not like gets rewritten. A to-do that misses the point gets deleted. A proposed idea that is wrong just sits there until I ignore it. Even a commit, in the right setup, is a save point more than an irreversible leap.
The other side is different. Once something leaves my machine and enters someone else's inbox, calendar, bank, or public feed, undoing it costs more than typing a better prompt. So the agent can prepare the email. It does not send it. It can draft the invite. It does not fire it. It can stage the newsletter. It does not publish.
I am not pretending this split is eternal. It is just the split that currently matches how much trust I have, and how much mess I am willing to clean up.
The approval tax is real
There is an obvious tension here.
If every consequential action waits for me, I risk recreating the approval-prompt tax that makes agents feel slower than doing the work myself. You know the feeling: five "are you sure?" dialogs, and suddenly you are doing the task by hand because the ceremony costs more than the task.
People building around this problem keep landing near the same pattern. Tend frames knowledge work as a loop you approve: cards get prepared, nothing sends without sign-off. Dan Shipper's After Automation argument is adjacent too. Cheap competence creates more human work, not less, because someone still has to stay ahead of the frame. And if you look at agent harnesses and safety plates in places like the AI Systems Atlas, the recurring theme is not "never automate." It is "know where trust ends."
I also keep thinking about blast radius. Domenic Denicola's write-up of a disposable agentic coding setup is useful here, even if my stack looks different. Give an agent more room when a mistake is cheap: a VM you can wipe, frequent pushes, narrow permissions for the scary stuff. That can look like more authority from the outside. Internally it is still low authority over irreversible external actions. Autonomy expands where reversal is boring.
So "low authority" does not mean "never auto-run anything." It means "never auto-run the irreversible thing without a visible commit." Reversible generation can run hot. External consequence waits.
Why I still want the last click
I have had drafts that were good enough to almost ship. Newsletter issues. Briefings. The kind of almost where editing would mostly be fidgeting.
What made me keep the last click anyway?
Mostly the feeling of control. Not a dramatic near-miss story. Not a scar from an agent that emailed the wrong person. Just the quiet preference to remain the person who says yes.
I know how that sounds. A little soft. Maybe even temporary. I guess it is just a matter of time until more and more automation comes into daily life, and the line moves. I am fine admitting that. The commit point does not have to be sacred forever. It has to be honest today.
There is also a practical reason hiding under the feelings. When I still decide what ships, I stay responsible for taste. The newsletter skill taught me that writing down the judgment criteria was half the value. If the agent publishes without me, I stop practicing that judgment. High agency without a commit point slowly turns into low ownership.
This is personal posture, not workplace policy
I am talking about my own agents. The ones that help me write, plan, brief, and ship side projects. Workplace and regulated deployments have different constraints, different blast radii, different people who get hurt when something goes wrong. I am not importing that world into this essay, and I am not pretending my home setup is a compliance framework.
For personal agents, the design problem is simpler and weirder: how do I get end-to-end help without sleepwalking into actions I did not mean?
My current answer is boring on purpose. Let the agent be ambitious about preparation. Keep authority narrow at the edge. Make the commit visible. Prefer reversible mistakes over silent sends.
The line I am actually drawing
High agency, low authority.
Do the research. Draft the issue. Build the options. Stage the change. Then stop somewhere I can still see the boundary.
In Computer speak, computer do I wrote about friction collapsing to nearly zero. Voice makes action cheap. That is powerful. It is also exactly why the commit point matters more, not less. When speaking can trigger work, "almost shipped" becomes a real category of risk.
I do not have a final map of every action that should sit on which side of the line. The inventory will keep moving as the tools get better and as I get less precious about control. For now the rule is stable enough to write down:
Generate freely. Commit deliberately.
That is the whole essay, really. The agent can do the work. I still mean the yes.