Why this matters now
The AI agents that arrived this month — ChatGPT Work, Claude Cowork, Copilot Cowork — don't just answer one question. They take a whole task and work through it, reaching into your files, email and connected apps, sometimes for a long stretch. That's powerful, and it's exactly why you want controls. An agent that can do a lot on its own can also do the wrong thing on its own if you let it run unwatched.
The good news: every one of these tools ships with two controls that put you firmly in charge. They're called plan mode and approvals, and using them is the difference between a helpful assistant and a nasty surprise.
Plan mode: see the plan before any work starts
Plan mode makes the agent show you its intended steps before it does anything. Instead of charging off, it says: here's how I'll approach this — step one, step two, step three — and waits for your go-ahead. You read it, and if step two says "email the supplier" when you only wanted a draft, you catch it before it happens, not after.
This is the single most useful habit with agents. It costs you thirty seconds of reading and it removes almost all the risk of the agent misunderstanding what you meant. Always ask for the plan first.
Approvals: a checkpoint on the actions that count
Approvals are the second layer. Even after you've approved the plan, you can require the agent to stop and ask before it takes any action that can't be undone — sending an email, posting a message, deleting a file, submitting a form. It prepares the action, shows you, and waits. Nothing leaves your control without a deliberate yes from you.
All three tools are built around this idea of a human approving the final step. The mistake is switching it off to save time. The whole reason you can trust an agent with real work is that it can't finalise anything on its own.
The setting to check first
Before you run any agent on real work, find its permissions or approval settings and see what it's allowed to do on its own. The defaults vary between tools, and some are more eager to act than others. Thirty seconds confirming that "send" and "delete" need your sign-off is worth far more than discovering the setting after the agent has already emailed a client.
The way to build trust in an agent is to test its judgement where a wrong move costs nothing. Give it a low-stakes task — organising your own notes, drafting something only you will see — with plan mode and approvals on. Watch where it pauses and what it proposes. Once you've seen it handle a few of these sensibly, you'll know how long a leash it has earned.
Do this this week
Copy the plan-mode prompt above and keep it somewhere handy — a note, your saved prompts. Use it every single time you hand an agent a real task. It's the one habit that lets you get the benefit of these tools without ever being surprised by them. Set it up once and it protects you on every job after.