Image

Before an Agent Runs, Write Its Operating Envelope

October 7, 2026
By
Joshua Goldfein

Someone on the team will hand you a working agent before anyone asked for one. Whether it may run against the team’s work comes down to six lines you can sign, written before the prompt. This is that checklist.

In short

It arrives as good news. Someone on the team built a scheduled task over the weekend that scans the week’s intake and posts a summary, and it works. The question that lands on the operations lead’s desk is whether it may keep running, and on what. There is no spec to review, because it was built in an afternoon by describing the job to an assistant.

That is the moment to write the operating envelope: the boundary around what the agent may read, what it may do, what it must produce, where it stops, where it runs, and who owns it. Six lines. The envelope is what an operations lead is approving when they say yes, so it should exist on paper before the yes.

What you are approving

The job of an agent is simple to state: carry a task across several steps to a defined output. The envelope depends on which of three shapes the task takes.

01

Chat workflow
A repeated sequence inside a project or custom assistant: briefs, digests, draft variants. The boundary is sources and output format. The risk is an unsupported claim inside a clean-looking document.

02

File workflow
A defined set of files read and processed: summaries, extractions, clean-ups. The boundary is folder scope and file types. The risk is a destructive action on the wrong folder.

03

Scheduled workflow
A run on a cadence with nobody watching. The boundary is stop rules and a named owner. The risk is quiet noise, or quiet failure, for weeks.

A first agent of any shape produces drafts and recommendations and leaves the externally visible action to a person. That rule holds until the workflow has earned production controls, and the envelope is how it earns them.

The six lines

  1. Sources: what it may read

    Named files, folders, or systems, and nothing it finds on its own. Pasted context counts as a source and goes on the list.

  2. Actions: what it may do

    Draft, summarize, classify, organize. No sending, deleting, approving, purchasing, publishing, or changing a live system. Write the forbidden list; the allowed list follows from it.

  3. Output: what finished looks like

    A template or a worked example with the required sections, and the place the result goes. If the agent cannot tell whether it is finished, the reviewer will not be able to either.

  4. Stop: when it halts and hands off

    A missing source, contradictory sources, sensitive content, a request outside the charter. The agent stops and says why. Filling the gap is the failure the line exists to prevent.

  5. Location: where the run executes

    On a laptop, in the vendor’s cloud, or in your own environment, and which files it can reach from there.

  6. Owner: who changes it, and how

    One name, and a change log. Every correction becomes an instruction, an example, or a test case before the next run.

Line five is the one that moved this year. As of October 2026, Anthropic’s help documentation says Cowork scheduled tasks run remotely, and that from October 6, 2026 new Cowork tasks run in the cloud, with the “only on your computer” option removed. A file workflow approved for a laptop is a different approval once the run happens in a vendor’s cloud. Check where the run executes before anything is scheduled, and write the answer on the line.

The envelope is what an operations lead is approving when they say yes, so it should exist on paper before the yes.

The signature line

When six lines stop being enough

Six lines are enough while the agent produces drafts for a person. They stop being enough when the workflow touches higher-risk data, an external party, unattended recurring execution, revenue decisions, regulated information, or a live system. At that point each line grows a production version, and the table is the trigger list.

FROM ENVELOPE TO PRODUCTION CONTROL
Line Envelope version Production version
Sources A named list A ranked source hierarchy, access policy, and retention rules
Actions Draft-only, forbidden list written down Tool permissions, approval gates, and an incident path
Output Template and example, human review before use Output validators, eval cases, and regression tests
Stop A short list of halt conditions Alerting, retry policy, and escalation records
Location Written down and checked before scheduling Execution in the firm’s own environment, with its logs and network rules
Owner One name and a change log Versioned instructions, change review, and workflow memory

The right-hand column is a different project with its own budget. The envelope’s job is to tell you, line by line, when you have reached it, and to keep the agent drafts-only until you have.

Where Mercury fits

Mercury’s AI integration engagements begin with one workflow and its envelope, written with the operations lead who has to sign it. We deliver the six lines as a one-page document the team keeps, the drafts-only version of the agent running inside it, and a written trigger list for the production controls on the right of the table. If an agent built over a weekend is already running in your team, that envelope is the first thing to write.