Use Pazi responsibly — Pazi Documentation

Use Pazi responsibly

Pazi agents can execute real work, including actions that affect external systems and people. Use them as capable operators under human direction, not as final authorities for consequential decisions.

Humans own the decision

You define the objective, constraints, permissions, and acceptable risk. The agent can research, propose, create, test, and execute within those boundaries, but you remain responsible for what you authorize and use.

Review facts and outputs before relying on them for legal, medical, financial, employment, security, safety, or other high-stakes decisions. Bring in a qualified professional where appropriate.

Agents own reversible execution

Delegation works best when the agent can complete many low-risk steps independently and stop at clear approval points.

  1. Give the outcome and relevant sources.

  2. State budget, deadline, recipients, and prohibited actions.

  3. Let the agent complete reversible preparation and testing.

  4. Review the proposed irreversible step.

  5. Approve the exact action or request changes.

  6. Verify the real result afterward.

Irreversible actions are possible

An agent can make irreversible changes when you instruct and permit it. Permission prompts reduce accidental action, but they do not replace judgment and are not a guarantee that every consequence will be predicted.

Be especially careful with purchases, production systems, account deletion, public publishing, customer communication, legal acceptance, and destructive file or data changes.

Verify outputs, not confidence

Agents can be wrong while sounding certain. Ask for primary sources, test results, screenshots, diffs, before/after evidence, or another agent's review when the cost of error is meaningful.

For software, require tests and inspect the deployment target. For research, open the cited source. For messages, verify recipients and final text. For data transformations, keep the original and compare totals.

Separate risky capabilities

When web prompt injection or untrusted input is a concern, separate roles.

  1. A research agent can browse unknown websites without sensitive credentials.

  2. An internal agent can use reviewed findings and approved tools without broad browsing.

Use separate test and production credentials, and grant the narrowest service scope that completes the job.

Monitor active and recurring work

Review Live View and chat during unfamiliar workflows. For scheduled work, inspect the first runs, verify the destination, and disable tasks nobody is reading.

Email and Slack can trigger agent runs. Keep channel access current, review unknown inbound email from the Inbox, and remove departed team members promptly.

Protect sensitive data

Do not paste secrets into chat, memory, skills, files, or email. Use the secure credential form, enter interactive passwords directly on the verified website, and delete or rotate credentials when access should end.

Before sharing a file publicly, inspect it for customer data, internal links, embedded assets, source comments, and generated claims.

Stop when the situation changes

Use Stop when the current run should not continue. Remember that cancellation cannot undo an action already completed on another service.

If an agent discovers a material risk or missing decision, it should ask rather than guess. Give it explicit permission to pause and escalate uncertainty.