WED, SEPTEMBER 30, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude Productivity

Six Prompts Before You Give an Agent Your Passwords

OpenAI's dots went live on 29 September: always-on agents with their own cloud computer and browser, able to sign into websites using saved passwords. The safety limits that matter are that background research runs read-only and password changes stay user-controlled. Everything else is a decision you make once and live with. These six prompts turn that decision into something you have actually thought about rather than clicked through.

⌨️ 6 prompts 🕐 Updated Sep 30, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
Map the Blast Radius Before You Connect Anything
The tier 3 list is the whole exercise. Most people connect everything and discover the tiers afterwards.
I am about to give an always-on AI agent access to the accounts listed below.<br/><br/>For each one, tell me the worst thing that could happen if the agent acted wrongly with it - not the likely thing, the worst one. Cover money moved, data exposed, messages sent in my name, and anything that cannot be undone.<br/><br/>Then sort the accounts into three tiers:<br/>1. Recoverable in minutes<br/>2. Recoverable with effort<br/>3. Not recoverable<br/><br/>Tell me plainly which tier 3 accounts I should not connect at all.<br/><br/>ACCOUNTS:<br/>[list them]
2
Separate Read From Write, Properly
Read-only background work is where the value is and almost none of the risk. This finds the line.
Here is what I want an AI agent to do for me.<br/><br/>Split every task into the part that only needs to READ and the part that needs to ACT.<br/><br/>For each acting step, tell me whether it genuinely needs to happen autonomously or whether it could stop and wait for one click from me. Be strict - "it would be slower" is not the same as "it needs to".<br/><br/>Then give me the smallest set of write permissions that still makes this useful.<br/><br/>TASKS:<br/>[describe them]
3
Design the Review Gate
The last paragraph is the point. Alert fatigue is how review gates fail in practice.
I want an agent to handle [task] but I want to approve certain actions before they happen.<br/><br/>Write me the rules for when it must stop and ask, specific enough that they could be implemented rather than just believed. Base them on things that can actually be checked: amount thresholds, recipients not seen before, anything irreversible, anything outside working hours, anything touching a new account.<br/><br/>Then tell me which rules will fire so often that I will start approving without reading - because a gate everyone waves through is worse than no gate, it just moves the blame.
4
Write the Revocation Plan First
Write this while nothing is wrong. You will not compose it calmly during an incident.
Assume the agent has been running for three months with the access below, and I now need to cut it off immediately.<br/><br/>Give me the exact steps in order, fastest first. Include every place a credential or token might persist after the obvious revoke: saved sessions, OAuth grants, API keys, app passwords, connected devices.<br/><br/>Tell me what the agent could still do after step 1, after step 2, and so on, until the answer is nothing.<br/><br/>ACCESS:<br/>[list]
5
Audit What It Actually Did
Run this weekly for the first month. The third group is where you learn what the agent thinks you meant.
Below is a log of actions an AI agent took on my behalf.<br/><br/>Group them into: things I asked for, things that followed reasonably from what I asked for, and things I did not anticipate.<br/><br/>For the third group, work out what the agent inferred to get there, and tell me whether that inference was reasonable.<br/><br/>Flag anything that touched an account, contact or system outside the scope I set - even if the outcome was fine.<br/><br/>LOG:<br/>[paste]
6
Decide Now What Happens After a Mistake
Deciding the walk-away threshold before you are invested is the only time you can decide it honestly.
An always-on agent working for me will eventually do something wrong. Help me decide, in advance, what happens then.<br/><br/>Answer four things:<br/>1. How would I find out - what would surface it, and how long would that take?<br/>2. What is my first action, before diagnosing anything?<br/>3. Who else needs telling, and how fast, if it touched their data or sent something in my name?<br/>4. What would have to go wrong for me to stop using it entirely, rather than tightening a setting?<br/><br/>Question 4 in particular: give me a concrete threshold, not a feeling.<br/><br/>CONTEXT:<br/>[what the agent does for you]