Every office has a list of tasks nobody wants. Copying details from an email into a form. Chasing the same follow up every Thursday. Rebuilding the same report from the same three spreadsheets. None of it is hard. All of it eats hours, and it usually lands on whoever is least able to say no.
That is the work custom AI agents are actually good at right now. Not replacing your team, and not running your business. Handling the repetitive middle of a process while a person keeps their name on the outcome. Harrison likes to say that AI is the dumbest it will ever be today, which is both a warning and a promise: judge it on what it does now, and expect the same task to get easier every year.
What a Purpose Built Assistant Actually Is
A general chat tool answers whatever you type. An agent is narrower on purpose. You give it a specific job, the instructions for doing that job the way your company does it, access to a defined set of information, and permission to take a defined set of actions.
Picture the difference between asking a stranger a question and hiring someone for a role with a written job description. The stranger might be brilliant and might be confidently wrong. The role has boundaries, a supervisor, and a way to escalate when something looks unusual. Agents work the same way, and the boundaries are where the value comes from.
What It Can Handle at a Small Business
These are the patterns we see working, described by what they do rather than what any vendor calls them this quarter.
- Intake and triage. Read what came in, pull out the important fields, categorize it, and route it to the right person with a suggested priority. The human still decides. The sorting is done.
- Follow up reminders. Watch for the quote nobody answered, the invoice nobody paid, the signature nobody returned, and surface it before it goes cold. This alone pays for a lot of experimentation.
- Drafting recurring reports. The weekly summary, the monthly recap, the same slide deck with new numbers. A draft that is eighty percent right and needs a human edit beats a blank page every time.
- Summarizing a week of email or messages. What happened, what needs a decision, what is still waiting on somebody. Especially useful for an owner who was out of the office and does not want to scroll through four hundred messages.
- Answering internal questions from your own documents. What is our policy on this, what did we quote that client last year, which form does this situation need. This works when your documents are organized and fails when they are not, which tells you something useful either way.
Treat It Like a Junior Staff Member
This is the framing we come back to constantly, because it makes the right decisions obvious. A capable new hire on their first week is eager, fast, and unfamiliar with your business. You would not let that person send contracts unsupervised on day one. You also would not hire them and then never give them work.
The specific failure mode is worth naming. NIST, in its 2024 profile on generative AI, defines confabulation as a phenomenon in which these systems “generate and confidently present erroneous or false content in response to prompts.” Confident and wrong is harder to catch than obviously wrong, which is exactly why review matters. NIST’s guidance in that same 2024 document includes reviewing and verifying sources and citations in system outputs, both before deployment and during ongoing use.
So supervise like a manager. Define who owns the agent’s output. Spot check the work weekly at first, then monthly. Give it an escalation path, meaning a clear rule for what it must hand to a person instead of deciding: anything involving money above a threshold, anything about a legal or personnel matter, anything where it is not confident. NIST’s 2023 AI Risk Management Framework says organizations should have policies that “define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems,” and notes that risk management may need to include human intervention where the system cannot detect or correct its own errors. That is a formal way of saying somebody has to be the supervisor.
The people side matters as much as the technology. We wrote about that in how to actually prepare your team for AI without the hype.
The Permissions Question
Before you turn anything on, answer one question in writing: what is this allowed to touch? An agent inherits access from whoever set it up, and it will happily read everything you point it at, including the folder with payroll in it.
NIST’s 2024 generative AI profile is direct about the privacy stakes, warning that models “may leak, generate, or correctly infer sensitive information about individuals,” and it recommends establishing transparent acceptable use policies. In practice, for a small business, that comes down to a few decisions.
- Give it the minimum access that lets it do the job. One mailbox, one folder, one system. Not everything, just in case.
- Separate reading from doing. Reading your files is low risk. Sending email as you, moving money, or changing records is not. Start with read and draft only.
- Know where the data goes. Ask your provider how your information is stored, whether it trains anything, and where it lives. Get the answer in writing, and confirm it again at renewal, because these terms change.
- Log what it did. If you cannot see the actions it took, you cannot supervise it. That is a dealbreaker, not a nice to have.
Start Small, and Know When to Stop
Pick a first task that is boring, repetitive, and reversible. Reversible is the key word. If the agent gets it wrong, you want the fix to be deleting a draft, not calling a customer to apologize. Run it alongside the human process for a couple of weeks and compare. NIST’s 2023 framework frames this as a go or no go decision made with real context about impacts, and that is the right instinct: decide with evidence, not with enthusiasm.
Be equally willing to say no. An agent is the wrong tool when the task happens twice a year, because you will spend more time building it than doing it. It is wrong when the process is undocumented and lives in one person’s head, because you cannot automate what you cannot describe. It is wrong when every case is genuinely unique, when a mistake is expensive or public, or when the real fix is a simple rule in software you already own. And it is wrong when nobody has time to supervise it, because an unsupervised agent is not a helper, it is a liability with a schedule.
Measure the result in hours returned to your team rather than in software you can brag about. That is the same standard we apply to every tool we recommend, and we made the case for it in why saving time takes priority over saving money.
The Bottom Line
A custom agent is a junior teammate with a narrow job, limited keys, and a supervisor. Give it the repetitive work nobody wants, keep a person accountable for the output, restrict what it can touch, and start with tasks where a mistake costs you five minutes instead of a client. Capabilities are improving quickly enough that the honest advice is to build the habits now on small things, so you are ready when the bigger things become reasonable.
If you want help picking a first task, setting the guardrails, and deciding what your agent should never be allowed to touch, that is a conversation we have every week. Contact us today.
Sources:
Comments are closed