Not what you told it to do. What it could do tonight, on its own, if it decided that was the job.
Nate Herk teaches AI automation to a few hundred thousand people, and he tells this one on himself. His team had an agent with access to email. It found a task sitting on a to-do list, read it as send the discount code to the list, and sent it. To roughly a hundred and fifty thousand people.
No prompt asked for that. The instructions were fine. The agent simply had a send key, and one day it turned it.
His conclusion, and mine: if a system holds a tool, you have to assume it uses it eventually. Not because it is malicious. Because no agent runs the same way twice, and the day the model underneath it changes, the whole thing reinterprets what you told it.
So the instruction was never the boundary. The key was.
A rule in the prompt is a suggestion. A rule in the tools is a restriction.
A system built on your judgment needs both. And if someone has already built you one, ask to see where either is written down.
The Refusal Map governs what it will not say in your name. The calls you would decline, the advice you would never give, the client you would turn away. That is excavated from how you actually decide, and it is the part no system trained on your published work can reach, because a refusal never appears in your output.
The Access Limitations govern what it cannot do at all. Not because it was told not to. Because it holds no key to the thing.
The first is a matter of teaching. The second is physics, and it is what makes the first worth trusting.
Most agents belong in the bottom two and stay there. A higher tier is a cost, not a badge.
And the rule that sits over all four: the one that writes never sends. The agent drafting your email does not hold a sending credential. It cannot be talked into sending, because there is nothing there to talk into. Release happens through you, or through a separate agent whose only input is something you already approved.
That single rule closes the category of failure this page opened with. An agent that cannot send cannot send the wrong thing.
One page. Plain language. It lives in your vault next to the agent it governs, and it does not change without your sign-off.
A specimen, not a client's card. Every card is written for the specific agent it ships with.
Any system can be asked to do the thing it should not do, and any system can answer nicely that it would rather not. That proves the wording was good on the day you asked.
So before an agent is handed over, it gets told to do the forbidden thing. Not asked whether it would. Told to do it.
It passes when the attempt fails: no such tool, key out of scope, permission denied. It fails the test when it declines politely while still holding the key, because that is an agent whose only boundary is its own good mood.
And it gets re-tested every time the model underneath changes. A new model is new behavior. The keys carry over; the proof does not.
Your Blue Island AI is the work of Koen de Wit. For close to a decade, under his practice The Funnel Therapist, he has helped coaches, consultants, speakers, and creators with their marketing and their funnels. He was certified on the Funnel Hacking Live stage, and he consults for ClickFunnels in their funnel-builder coaching and certification program.
He is mentored by Rich Schefren, the strategist the biggest names in marketing quietly turn to. Koen is in Rich's Zenith Pro, and has sat with him privately at his home in Delray Beach.
Everything on this page is a written build standard, not a vague assurance. The tiers, the card, and the test were set down in writing before a single client was asked to buy a build. Access decided in the middle of a build is how the discount-code story happens.
And the method itself he built on himself first. The system carrying his judgment is his own, running on his own machine, before any of it was offered to anyone else. He does not sell what he has not built for himself.
You do not need this page to answer it. Ask whoever built your setup, or ask yourself: what can this thing actually do on its own? Can it send, or can it only draft? Who holds the keys, and what else do those keys open?
If the answer makes you uneasy, the fix is not a better prompt. It is the access.
Leave your email and Koen will send you the card, the four tiers, and the test an agent has to pass before it is handed over.
Already know this is your problem? Skip the email. Thirty minutes, one real decision from your work, and whether your judgment can be excavated at all. If it cannot, you will hear that on the call.
Bring one decision you have made this year that your AI would have gotten wrong.