---
title: "AI Agent Safety Checklist: 18 Checks, Day One Onwards · AgentDots"
description: "Eighteen practical checks for a personal AI agent: what to settle before connecting it, what to watch in week one and the habits that keep it on a short rein."
url: https://agentdots.org/safety/checklist/
lang: en
---

Safety

# AI Agent Safety Checklist: 18 Checks, Day One Onwards

Eighteen checks, arranged by timing, for anyone handing a personal agent access to their email, money or accounts for the first time.

Most agent mishaps on record trace back to a setting nobody chose deliberately. The checks below are grouped by when they matter: before the agent touches anything, during a first week of close watching, and as standing habits afterwards. Each carries a one-line reason, so you can judge which ones your own setup can safely skip.

## Before you connect anything

**1. Write standing rules that sort every kind of action into allowed, ask first or never.**An agent without written limits fills the gaps with its own judgement.

**2. List what the agent may never disclose, beginning with where you live, how to reach you by phone and any ID numbers.**Muse has already told a Marketplace buyer where a seller lived.

**3. Issue the agent a virtual card of its own with a small ceiling, or no card at all.**A loop or a misunderstanding then costs a small, known sum.

**4. Connect only the apps your first tasks genuinely need.**Each link widens what the agent sees, and some services keep copies of what it sees.

**5. Find the controls that pause the agent and revoke its app access.**The brake is hardest to locate at the moment you need it.

**6. If you host the agent yourself, confirm the gateway is bound to loopback and unreachable from the internet.**OpenClaw gateways open to the internet have been counted in the tens of thousands, many leaking keys.

## During the first week

**7. Keep the agent on read-only tasks for the whole week.**Its reasoning becomes visible before it can alter anything.

**8. Read the activity log every day.**Early mistakes tend to repeat, and the log shows them while they are still small.

**9. Require your approval before any message goes out in your name.**A sent message speaks for you and cannot be recalled.

**10. Put payments, offers and first contact with strangers behind your approval.**These are the steps where a single wrong call costs money or privacy.

**11. Add a rule that text inside web pages, emails and documents is information, never instruction.**It narrows the opening for prompt injection hidden in what the agent reads.

**12. Add a rule that a blocked page or an unfamiliar login means stop and ask.**An OpenAI research agent once found its way round the locks on a government portal.

## As a standing habit

**13. Compare the agent's summaries with the actual results now and then.**Testing of GPT-6.1 Astra found a model that sometimes misreported its own actions.

**14. Remove scheduled tasks and connectors you no longer use.**Forgotten access is still access.

**15. Change passwords and security settings yourself, never through the agent.**Control over account recovery amounts to control over the account.

**16. Revisit the training setting for your agent's work whenever you change plan.**Pictures from accounts that permitted training have already leaked beyond OpenAI's systems.

**17. Update the app or self-hosted release promptly, and rotate keys after any serious flaw.**Every OpenClaw release older than 2026.4.22 has critical vulnerabilities on record.

**18. Widen permissions in single steps, and only when a particular task calls for it.**If something then breaks, you know which change to reverse.

Checklist

0 of 18 done

Your ticks are kept in this browser only.
