Playbook: Give a Scheduled Agent Only the Access It Needs
You built an agent that reconciles supplier invoices against purchase orders every night. It saves your finance team ten hours a week. It also runs at 2am wi...
You built an agent that reconciles supplier invoices against purchase orders every night. It saves your finance team ten hours a week. It also runs at 2am with nobody watching, using tools that can post adjustments to the ERP. The agent does what it was told, but instructions are not limits. One unusual invoice, one confusing note in a supplier's PDF, and it could post an adjustment nobody approved. This playbook walks you through giving that agent a fixed set of things it may do, with hard limits on amounts, so that the worst case is a blocked call and a line in a report.
What you will build
By the end of this playbook, you will have:
- A reconciliation agent with a defined job and a schedule
- Rules that allow the agent the specific tools it needs
- A limit on the size of any adjustment it can post
- A rule that blocks everything else for that agent, without affecting anyone else in the workspace
- A message on each rule that tells the agent to record the item for a person instead of trying again
- A sandcastle app where your finance team reviews what the agent could not do
- A tested setup and a weekly view of what was blocked
What you need before you start
- An Assist workspace where you are a workspace admin.
- An AI client connected to your workspace through an MCP server, or the chat in Assist.
- Tools for your ERP. This playbook uses
erp_list_invoices,erp_get_purchase_order,erp_post_adjustment, anderp_flag_for_review. If you have not built them, your AI client can help you create them the same way as in Step 1. - A number from your finance lead: the largest adjustment the agent may post without a person approving it.
Step 1: Build the tools the agent will use
If the tools do not exist yet, build them from your AI client. Start with the ones that read:
"Create a tool called 'erp_list_invoices' that returns supplier invoices from our ERP for a date range, with the invoice number, supplier, amount, currency, and the purchase order it refers to."
"Create a tool called 'erp_get_purchase_order' that takes a purchase order number and returns the line items, quantities, agreed prices, and total."
Then the ones that write. Be deliberate about their parameters, because your rules will look at them:
"Create a tool called 'erp_post_adjustment' that posts an adjustment against an invoice. It takes 'invoice_number', 'amount' as a number, 'currency', 'reason_code' which is one of price_variance, quantity_variance, freight, or tax, and a 'note'. It returns the adjustment id."
"Create a tool called 'erp_flag_for_review' that marks an invoice as needing a person to look at it. It takes 'invoice_number' and a 'reason'."
Making amount a number and reason_code a fixed set of choices pays off later. The rule editor will offer number comparisons for one and a list of choices for the other.
Step 2: Create the agent
Describe the job:
"Create an agent called 'Invoice Reconciliation'. Every night at 2am it should list yesterday's supplier invoices, compare each one to its purchase order, and handle the differences. If the difference is a price or quantity variance under 250, post an adjustment with the right reason code. For anything else, flag the invoice for review with a clear reason. It should use erp_list_invoices, erp_get_purchase_order, erp_post_adjustment, and erp_flag_for_review."
Run it once by hand on a day you know well and read what it did. At this point the agent's limits are instructions. The 250 limit is a sentence in a prompt. The next steps turn it into something the agent cannot get around.
Step 3: Write down what the agent may do
| Tool | Allowed | Limit |
|---|---|---|
erp_list_invoices | Yes | None |
erp_get_purchase_order | Yes | None |
erp_flag_for_review | Yes | None |
erp_post_adjustment | Yes | Amount between -250 and 250, reason code price_variance or quantity_variance only |
| Everything else | No |
The last row is what makes this different from the rules you write for people. For a person, you block the few things they should not do. For an unattended agent, you allow the few things it should do and block the rest.
Step 4: Allow the read tools
In Assist, open Permissions and select the Tool Policies tab. Click New Rule.
- Under Action, select Allow.
- Under Applies to, choose Subagent, then pick Invoice Reconciliation.
- In Tool, type
erp_listand press Tab. - Reason: "Reconciliation agent may list invoices."
- Click Create Rule.
Repeat for erp_get_purchase_order and erp_flag_for_review. If your ERP tools share a tool pack and the agent may use every read tool in it, a pattern saves time: enter erp_get_* in Tool, and check the line under the target to see which tools it covers.
Step 5: Limit the adjustments
The agent may post adjustments, within limits. It is easier to write the limits as blocks and then allow what is left.
Block large amounts. Click New Rule:
- Action: Deny. Applies to: Subagent, Invoice Reconciliation.
- Tool:
erp_post_adjustment. - Click Add condition. Press Tab in Path and choose
amount. The operator list shows number comparisons. - Choose gt and enter
250. - Reason: "Adjustments over 250 need a person."
- Message returned to the model on deny: "This adjustment is over the limit. Do not split it into smaller adjustments. Flag the invoice for review with erp_flag_for_review and move on to the next invoice."
Click Create Rule. Then create a second rule the same way with lt and -250, so that large credits are blocked too.
The message is doing real work here. An agent that is blocked will look for another way to finish its job. Telling it not to split the adjustment, and what to do instead, turns a blocked call into the right outcome.
Block the reason codes it should not use. Click New Rule:
- Action: Deny. Applies to: Subagent, Invoice Reconciliation. Tool:
erp_post_adjustment. - Add a condition on
reason_code. Because the tool defines a fixed set of choices, Value shows them as a list. - Set Operator to in and tick
freightandtax. - Reason: "Freight and tax adjustments need a person."
- Message returned to the model on deny: "Freight and tax differences must be reviewed by a person. Flag the invoice for review."
Allow the rest. Click New Rule:
- Action: Allow. Applies to: Subagent, Invoice Reconciliation. Tool:
erp_post_adjustment. - No conditions.
- Reason: "Reconciliation agent may post small price and quantity adjustments."
- Under Placement, place it after the three blocks you just made.
Step 6: Block everything else for this agent
Click New Rule:
- Action: Deny.
- Applies to: Subagent, Invoice Reconciliation.
- Leave Tool pack and Tool blank. The line under the target confirms the rule applies to every tool.
- Reason: "Reconciliation agent is limited to its reconciliation tools."
- Message returned to the model on deny: "This tool is not available to you. Use only the invoice, purchase order, adjustment, and review tools. If you cannot finish a task with those, flag the invoice for review."
- Under Placement, choose Bottom of chain.
This rule applies to one agent. Everyone else in the workspace, and every other agent, is unaffected. The workspace default stays at Allow.
Your list for this agent now reads, from the top:
- Allow
erp_list_invoices - Allow
erp_get_purchase_order - Allow
erp_flag_for_review - Block adjustments over 250
- Block adjustments under -250
- Block freight and tax adjustments
- Allow remaining adjustments
- Block everything else
Because the first match decides, the order of 4 through 7 matters. If the allow in 7 sat above the blocks, every adjustment would be allowed.
Step 7: Test as the agent
Select the Simulator tab and switch to Tool call. In User, choose the person the agent runs for. In Agent (optional), pick Invoice Reconciliation. Source switches to Subagent.
| Tool | Values | Expected |
|---|---|---|
erp_list_invoices | Any | Allowed |
erp_post_adjustment | amount 120, reason_code price_variance | Allowed by rule 7 |
erp_post_adjustment | amount 900, reason_code price_variance | Blocked by rule 4 |
erp_post_adjustment | amount -400, reason_code quantity_variance | Blocked by rule 5 |
erp_post_adjustment | amount 50, reason_code tax | Blocked by rule 6 |
| A tool that sends email | Any | Blocked by rule 8 |
Then set Agent (optional) back to None and run one check as an ordinary person, calling the email tool. It should be allowed by the workspace default, which confirms the agent's rules do not spill over.
Step 8: Build the review app
The agent now flags what it cannot handle. Give your finance team somewhere to work through those. In your AI client:
"Build a sandcastle app called 'Reconciliation Review'. It should list invoices flagged for review, newest first, with the supplier, amount, purchase order, and the reason the agent gave. Each row should open a detail view showing the invoice next to the purchase order with the differences highlighted. Add buttons to approve an adjustment, reject it, or send it back to the supplier. Keep a record of who decided what and when."
Then refine it:
"Add a filter for supplier. Show a total at the top for the value of everything waiting. Make rows over 1,000 stand out."
When a person approves an adjustment in the app, the app calls erp_post_adjustment as that person. The agent's rules do not apply, because they are scoped to the agent. If you want limits on people too, add rules that apply to a group.
Step 9: Watch the first week
Open Tool History and select Blocked. After each nightly run, look at what was stopped:
- Adjustments over the limit are the rule working. Each one should have a matching flagged invoice. If it does not, improve the message on the rule.
- Blocked tools you did not expect tell you what the agent tried to reach for. If it was reasonable, such as looking up a supplier's contact details, add an allow rule above rule 8.
- Repeated attempts at the same call mean the agent is not taking the hint. Rewrite the message to be more direct about what to do instead.
On the Tool Policies tab, the Blocked 7d column shows which rules are doing the work.
What you built
Your reconciliation agent runs every night and does one job. It can read invoices and purchase orders, post small price and quantity adjustments, and flag everything else for a person. It cannot post a large adjustment, cannot split one to get under the limit without being told not to, and cannot use any tool outside its job. Those limits hold whatever the agent reads in an invoice, because they are enforced when the tool is called, not in the agent's instructions.
Your finance team reviews the exceptions in an app built for the purpose. And you can see, every morning, exactly what the agent tried to do and was stopped from doing.
Where to go next
- Raise the limit with confidence. After a month of clean runs, edit one number in one rule.
- Apply the same shape to other agents. A monitoring agent, a reporting agent, an intake agent: allow its tools, limit the risky one, block the rest.
- Add a classifier for the note. Use a classifier to check that the note on each adjustment explains the variance before it is posted. See Using a tool as a classifier.
- Limit by time. If adjustments should only post during the close period, have the agent check the date with a tool, and block when it is outside the window.