What your agents may and may not do:
written down, and actually enforced
Most businesses running AI agents have an unwritten sense of what the agents should not do, but no actual document, and no enforcement beyond hoping each agent was built carefully. We write the policy with you and then build it into the agents as hard rules, rate limits, approval gates, scope limits, so the policy is enforced in code, not just stated in a document.
The process today
A business that starts using AI agents usually develops an informal sense of what feels safe and what does not, an agent probably shouldn’t send money without a check, probably shouldn’t message a customer with something unreviewed, but that sense rarely gets written down, and even less often gets built into the agents as an actual enforced limit. Each new agent gets whatever safety thinking the person who built it happened to apply that day.
The second cost is that even a written policy, where one exists, tends to live in a document nobody checks before building the next agent, which means the policy and the actual behavior of the agents drift apart over time, with nobody noticing until an agent does something the policy clearly prohibited but nothing stopped it from doing.
The third is that without a consistent review process, a new agent’s risk level is assessed, if at all, informally and inconsistently, so a genuinely risky agent can go live with the same light scrutiny as a low-stakes one, simply because nobody has a checklist that forces the distinction.
What the agent does
We draft a written AI policy with your team covering what agents may and may not do, categorized by risk, financial actions, customer-facing communication, data access, irreversible actions, and then build that policy into each agent as actual code: rate limits, budget caps, scope restrictions on what tools or data an agent can reach, and approval gates on anything the policy marks as sensitive. The policy exists as both a document your team can read and update, and as enforcement the agents cannot simply ignore.
New agents go through a review checklist before launch that maps the agent’s planned actions against the policy, so a risky agent gets the scrutiny its risk level actually warrants rather than whatever attention it happened to get from whoever built it. The policy document itself stays owned and editable by your team, not locked inside our process.
Typical scope: any existing or planned agent your team wants brought under a consistent, enforced policy rather than ad hoc judgment calls.
What stays with humans
Deciding what the policy actually says, what counts as risky, what agents are allowed to do without a human check, is your team’s call; we draft options and flag what we have seen go wrong elsewhere, but the policy itself reflects your risk tolerance, not ours. Reviewing and approving each new agent against the checklist before it goes live stays a human step. Updating the policy as your business and your use of agents evolves is something your team does independently once the initial setup is handed off.
Guards
Enforcement is built as hard rules in the code, rate limits, scope restrictions, approval gates, not as guidance an agent could be prompted around. Every policy violation attempt, an agent trying an action outside its allowed scope, is logged and alerted, not silently blocked without a trace. The policy and its enforcement are tested against each agent’s real behavior in a dry run before going live, and the whole setup can be tightened or loosened by your team at any time without needing us involved.
Price and timeline
| Option | Price | What it covers | Timeline |
|---|---|---|---|
| Single automation | from $900 | Written policy, enforcement for 1 to 3 agents, launch checklist | 1 to 2 weeks |
| Department package | from $3,000 | Policy and enforcement across the full agent fleet, ongoing review process | 4 to 7 weeks |
Running cost is usually $15 to $50 a month in monitoring and model usage depending on agent count and action volume.
Related
This pairs well with agent approval queue and audit log for the day-to-day enforcement mechanism this policy relies on, and with agent cost and quality monitoring for tracking whether the guardrails are holding up over time. See the AI agents service page and the automation-everything overview for full package details. For real builds on governed multi-agent systems and monitored multi-channel sales agents, see the ProBay own marketplace AI agent team case study and the seven-channel AI sales agent case study.
Running agents without a written, enforced policy? Get in touch and we will map what your current agents can actually do today.
Tired of doing this by hand? We can take the whole routine off your team, not just this step: Routine takeover, from $400 →
FAQ
How much does it cost to set up AI policy and guardrails?
From $900 covering a written policy and enforcement for 1 to 3 agents, live in 1 to 2 weeks. Larger agent fleets or regulated industries with more detailed compliance needs usually run $2,000 to $4,000.
How long before it is live?
1 to 2 weeks: drafting the policy with your team takes a few days, and wiring the enforcement into each agent takes the rest.
We already have an AI policy document. What does this add?
Enforcement. A policy that lives only as a document relies on every developer remembering and applying it correctly every time; we turn the same policy into rate limits, scope restrictions and approval gates the code actually respects.
Does this slow our agents down or limit what they can do?
It limits what they can do outside the policy your team already wants enforced. Within that scope, agents run exactly as before; the guardrails only activate at the edges you define as risky.
Who owns the policy document afterward?
Your team does. We help draft it and build the enforcement, but the policy itself is yours to review and update as your use of AI agents evolves.