ContentsTap to jump to a section+
- 01The change worth watching: AI is being asked to do work, not only answer questions
- 02Vietnamese use cases are already becoming concrete
- 03Do not start with the shared inbox or the entire CRM
- 04Five boundaries to define before delegating work to AI
- 05Run a four-week pilot instead of an open-ended project
- AI agents can use tools and act across connected systems, making access control the first question.
- Keep the first pilot narrow, use filtered data and require human approval for external actions.
- Measure time, errors and rework before expanding to another workflow.
The change worth watching: AI is being asked to do work, not only answer questions
On 29 September, OpenAI announced a set of DevDay 2026 updates, including agents that can take on continuing responsibilities and tooling that lets agents interact with software. Its Dots product page describes an agent that can use connected tools, work on its own computer and continue making progress between conversations. These are OpenAI product announcements; availability still varies by plan and market.
For a business, the important point is not the product name. An AI error in a document summary usually ends in a draft. An AI that can read an inbox, query a CRM, update a work board or call other tools can turn a poor permission setting into a wrong recipient, bad data or a bad decision.
- The first teams affected are likely to be sales, customer care, operations, HR and teams spread across internal systems.
- The immediate move is to choose one small workflow—not to connect every data source or allow autonomous sending and updating.
- Risk grows with access, not with how impressive an answer sounds.
AI does not need broad access to prove its value. A small, measurable workflow with a clear owner is the better starting point.
Vietnamese use cases are already becoming concrete
Local examples are also moving beyond using AI simply to write faster. Tuổi Trẻ recently reported on HRCV using AI to read CVs, match candidates with roles and support interview practice; the result is still decision support rather than a replacement for recruitment judgement. Another report described BEMINE combining CRM, data, automation and AI to reduce repetitive work across sales, stock and reporting.
Those examples do not prove every company is ready for agents. They point to a sensible starting point: choose a step with clear inputs, verifiable output and one accountable owner. It is a better route than buying a tool first and looking for a task later.
- Classify new enquiries and prepare a reply draft.
- Summarise a sales report from a selected dataset.
- Compare a profile with defined criteria for a person to review.
Do not start with the shared inbox or the entire CRM
Deeply connected agents are appealing because they promise to remove many manual steps. But a shared inbox, the full customer database, contracts, payroll records and email-sending rights are high-consequence areas. Starting there makes it difficult to tell whether a failure comes from data, instructions, tools or permissions.
Instead, confine the agent to the smallest useful dataset and an action that can be reversed. For example, let it read new enquiry forms, label the need and draft a reply. A team member reviews the draft before sending. If it gets something wrong, the team can see where and fix it without damaging a customer record.
- Separate a test environment from production data where practical.
- Start with read access; add create, edit or send access only when evidence justifies it.
- Never put API secrets or administrator access in prompts, spreadsheets or client-side interfaces.
Five boundaries to define before delegating work to AI
First, define the work boundary: what the agent may do, may not do and when it must stop. Second, define the data boundary: only the fields needed for the task belong in context. Third, define the action boundary: anything that communicates externally, changes a state, creates cost or reveals information needs an approval step.
Fourth, define the observation boundary: retain an audit trail of input, tool calls, outcomes and approvers. Fifth, define the accountability boundary: name a business owner for the workflow rather than handing the entire problem to engineering. Technology can make a system safer; the process owner knows what a correct outcome looks like.
- Every task needs a stop control and a safe way back.
- Set thresholds for human hand-off rather than forcing the agent to handle every edge case.
- Review permissions and audit trails on a schedule, especially after changes to tools or staff.
Run a four-week pilot instead of an open-ended project
In week one, select a repetitive task and record the baseline: time per request, rework rate and current owner. In week two, connect sample or minimised data and let the agent make suggestions only. In week three, test with a small user group and record exceptions. In week four, compare speed, quality, review time and observed risk to decide whether to stop, refine or expand.
The aim is not to prove that AI never makes a mistake. It is to learn which step it improves, how much oversight it needs and whether it deserves integration into the real operating process. A website, software product or AI application for a business should start with a work map and control criteria before a model is selected.
- One speed metric: time to complete a request.
- One quality metric: the percentage of drafts that need material revision or rejection.
- One safety metric: the number of cases blocked or handed to a person.
FAQ
Frequently asked questions
Should an AI agent send customer emails automatically?
Not in the first pilot. Let the agent classify and draft, then require an accountable person to review before sending. Consider automation only for repetitive, low-consequence cases with proven performance.
Does an AI agent need access to the entire CRM?
No. Grant only the data required for the defined task. A smaller data scope reduces disclosure risk and makes a bad output easier to diagnose.
How should a business measure an AI pilot?
Compare like-for-like work: processing time, rework rate, human hand-offs and operating cost. Do not measure only how many tasks the AI completed.
References
Sources used in this guide
We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.
