00 / the question nobody asks

What is your AI actually allowed to do?

Not what you told it to do. What it could do tonight, on its own, if it decided that was the job.

One email, from Koen, not a sequence: the one-page card that says what an agent cannot do, and how that gets enforced.

That did not go through. Email koen@thefunneltherapist.com directly.

01 / how it actually goes wrong

Nobody told it to send anything.

Nate Herk teaches AI automation to a few hundred thousand people, and he tells this one on himself. His team had an agent with access to email. It found a task sitting on a to-do list, read it as send the discount code to the list, and sent it. To roughly a hundred and fifty thousand people.

No prompt asked for that. The instructions were fine. The agent simply had a send key, and one day it turned it.

His conclusion, and mine: if a system holds a tool, you have to assume it uses it eventually. Not because it is malicious. Because no agent runs the same way twice, and the day the model underneath it changes, the whole thing reinterprets what you told it.

So the instruction was never the boundary. The key was.

A rule in the prompt is a suggestion. A rule in the tools is a restriction.

02 / two different boundaries

One is judgment. The other is physics.

A system built on your judgment needs both. And if someone has already built you one, ask to see where either is written down.

The Refusal Map governs what it will not say in your name. The calls you would decline, the advice you would never give, the client you would turn away. That is excavated from how you actually decide, and it is the part no system trained on your published work can reach, because a refusal never appears in your output.

The Access Limitations govern what it cannot do at all. Not because it was told not to. Because it holds no key to the thing.

The first is a matter of teaching. The second is physics, and it is what makes the first worth trusting.

03 / four tiers, decided before anything is built

Every agent gets exactly one tier, and it is written down first.

Most agents belong in the bottom two and stay there. A higher tier is a cost, not a badge.

tier 0
Read
It reads your vault and answers questions. That is all it can do. Nothing it touches changes.
tier 1
Draft
It writes drafts inside your vault. Nothing leaves your machine, because it has no way to make anything leave.
tier 2
Connected read
It can look at one named outside system, read only, through a key scoped to that one place. It can see. It cannot change.
tier 3
Act
One agent, one action that changes something in the outside world, and the narrowest key that performs it. An agent that sends does not also update your CRM. Two actions means two agents and two cards.

And the rule that sits over all four: the one that writes never sends. The agent drafting your email does not hold a sending credential. It cannot be talked into sending, because there is nothing there to talk into. Release happens through you, or through a separate agent whose only input is something you already approved.

That single rule closes the category of failure this page opened with. An agent that cannot send cannot send the wrong thing.

04 / the page you get

Every agent is handed over with a card that says what it cannot do.

One page. Plain language. It lives in your vault next to the agent it governs, and it does not change without your sign-off.

specimen · one card per agent
Newsletter Draft Writer
access tier
  • 1 DRAFT. It writes drafts inside your vault. It cannot send anything, and it cannot reach any outside system.
what it can do on its own
  • Read the files in your vault.
  • Write a draft newsletter into your Drafts folder, in your voice, from your own material.
what it can only draft, never release
  • It writes the email. It has no send key. Nothing reaches your list unless you release it.
what it cannot do, because it holds no key
  • It cannot send email.
  • It cannot post, publish, or schedule anything, anywhere.
  • It cannot change or delete anything in your CRM, your site, or your course platform.
  • It cannot spend money. It holds no payment method of any kind.
the off switch
  • Close the app. The agent has no life outside it.
changing what it can do
  • Nothing on this card changes quietly. Widening what an agent can reach means a new card first, naming the change and the reason, and nothing moves until you approve it in writing.

A specimen, not a client's card. Every card is written for the specific agent it ships with.

05 / the test it has to pass

A polite refusal is not a boundary.

Any system can be asked to do the thing it should not do, and any system can answer nicely that it would rather not. That proves the wording was good on the day you asked.

So before an agent is handed over, it gets told to do the forbidden thing. Not asked whether it would. Told to do it.

It passes when the attempt fails: no such tool, key out of scope, permission denied. It fails the test when it declines politely while still holding the key, because that is an agent whose only boundary is its own good mood.

And it gets re-tested every time the model underneath changes. A new model is new behavior. The keys carry over; the proof does not.

Koen de Wit receiving the Certified Funnel Builder award on the Funnel Hacking Live stage with Russell Brunson and Todd Dickerson
certified funnel builder · the funnel hacking live stage, 2025
Koen de Wit and Rich Schefren working together
with rich schefren · zenith pro, delray beach
06 / who is behind this

The standard he holds himself to before anyone else.

Your Blue Island AI is the work of Koen de Wit. For close to a decade, under his practice The Funnel Therapist, he has helped coaches, consultants, speakers, and creators with their marketing and their funnels. He was certified on the Funnel Hacking Live stage, and he consults for ClickFunnels in their funnel-builder coaching and certification program.

He is mentored by Rich Schefren, the strategist the biggest names in marketing quietly turn to. Koen is in Rich's Zenith Pro, and has sat with him privately at his home in Delray Beach.

Everything on this page is a written build standard, not a vague assurance. The tiers, the card, and the test were set down in writing before a single client was asked to buy a build. Access decided in the middle of a build is how the discount-code story happens.

And the method itself he built on himself first. The system carrying his judgment is his own, running on his own machine, before any of it was offered to anyone else. He does not sell what he has not built for himself.

07 / the question to take with you

Ask it of whatever you are running today.

You do not need this page to answer it. Ask whoever built your setup, or ask yourself: what can this thing actually do on its own? Can it send, or can it only draft? Who holds the keys, and what else do those keys open?

If the answer makes you uneasy, the fix is not a better prompt. It is the access.

Leave your email and Koen will send you the card, the four tiers, and the test an agent has to pass before it is handed over.

That did not go through. Email koen@thefunneltherapist.com directly.

Already know this is your problem? Skip the email. Thirty minutes, one real decision from your work, and whether your judgment can be excavated at all. If it cannot, you will hear that on the call.

Bring one decision you have made this year that your AI would have gotten wrong.