What it must never do alone
Rules first, because afterwards is too late
Everything in this course makes your AI more capable, and this is the lesson that stops more capable from meaning more dangerous.
One idea does most of the work:
A rule the AI reads before it acts is a system you can trust. A mistake you catch in the output is luck, and luck runs out precisely when the stakes go up.
The approval list
These belong in your instructions file, and every line stays in:
- Send an email, message or reply to anyone
- Publish or post anything anywhere
- Buy anything, or enter payment details
- Delete a file, an email or a record
- Change a setting on an account or a system
- Share anything outside this folder
- Agree to terms on your behalf
Then add to it. Anything specific to your situation: a client who must never be named, a figure that cannot leave the building, a person whose sign-off is always required. You already named some of these in the interview; make sure they survived into the file.
This is not a stage you grow out of once the system is good. The approval step is the feature that makes everything else safe to hand over at all.
None of this is theoretical any more. Switch on an email connector and a reply the AI drafts can arrive with a live Send button sitting underneath it. The draft is the AI's work. The button is yours, every time.

Add the list to your instructions file now.
Add a section to my instructions file called "Never without asking". Before doing any of the following, stop and ask me first, even if the request seems to imply permission: send an email, message or reply to anyone; publish or post anything anywhere; buy anything or enter payment details; delete a file, an email or a record; change a setting on an account or a system; share anything outside this workspace; agree to terms on my behalf. Then ask me what else belongs on this list for my situation.
What never goes in the files
Passwords, API keys, card numbers. Not in any file in your AIOS, ever. The files are meant to be read, copied, and moved between AIs, which is exactly what you do not want happening to a credential.
And check what your employer's policy says about which AI tools may see company information. Putting something in a folder does not change the rule, and if you work in a regulated industry the rule was written before this course and still applies to it.
The honesty instruction
Make sure this survives in your instructions file, in whatever words you like:
An AI that guesses confidently is more dangerous than one that says it is not sure, and the second behaviour has to be explicitly asked for. It will not volunteer it.
Worth being clear-eyed about what all this buys you. None of it makes the AI accurate. A system makes errors catchable: the rules say where a person looks, the honesty line says where the AI is guessing, and the approval list says what cannot happen while nobody is looking. That is what reliability actually is, and most organisations have not written down this much of it.
Stuck anywhere in this lesson? Reply to any Build Notes email and tell me where. I would rather fix the lesson than have you quietly give up.