When a business owner hears "AI employee," the first question usually isn't what it can do. It's what it could do wrong. That's the right question, and it deserves a better answer than "don't worry about it."
Governance sounds like a big-company word. For a small business it comes down to three questions. What is this thing allowed to touch? What can it never do? And who finds out when something looks off?
Here's how I answer those in my own businesses, where three digital employees already work for me.
Start with a job description, not a tool
Every digital employee I build starts on paper: a role, a goal it's measured against, a short backstory, and a list of guardrails. Peter Swain teaches the first three as role, goal, and backstory. The guardrails list is where most of the real thinking happens.
If the job isn't written down, the limits can't be either. A vague job is how an AI ends up "helping" in places nobody asked it to.
Put the limits in the system, not in a polite request
Telling an AI "please don't pay any bills" is a suggestion. Taking away its ability to pay bills is governance. Every limit I care about lives in the permissions, not the prompt.
| Digital employee | What it can do | What the system won't let it do |
|---|---|---|
| Bailey, bookkeeper | Record bills and receipts in Xero | Approve or pay anything. Every entry lands as a draft |
| Sarah, rental manager | Write new event pages for our rental's website | Touch any other part of the site, or publish without my approval |
| Garry, executive assistant | Draft and send routine follow-up | Pass as human. He signs with his own name and a title that says what he is |
Sarah is the clearest example. She works from her own restricted account that can reach one website, and only one folder in it. A separate check rejects any change outside that folder, and her database access is read-only. If she got confused, the worst she could do is propose a bad page that I'd decline.
Give each employee its own accounts
I don't let digital employees share logins with each other or with me. Each one gets its own accounts, its own credentials, and its own memory. When something goes wrong, I know exactly which one did it, and I can shut one down without touching the others.
Same reason you don't give every new hire the owner's password.
Keep a human on anything that matters
Decide up front where a person stays in the loop. My short list is money moving, anything sent to a client for the first time, anything public, and anything that can't be undone. Those always wait for me. Routine work doesn't.
Ramp it like a new hire
No digital employee of mine publishes or sends anything on its own in week one. The first week is daily check-ins and approvals. The second week loosens up. After that, approvals drop away one category at a time, as the error rate earns it.
It's slower than flipping a switch. It's also how you end up trusting it for the right reasons.
Write down every skill it learns
Digital employees pick up new skills over time. I keep a registry of every skill each one has, who approved it, and when. Nothing gets added quietly, and nothing runs on autopilot without a line in that log.
A governance checklist for your first digital employee
- A written role, goal, and list of things it must never do
- Its own accounts, with the least access the job needs
- Hard limits enforced by permissions, not instructions
- Named approval points for money, clients, public posts, and anything irreversible
- A supervised first week, with approvals removed one at a time
- A log of every skill and permission change
If you want to see how I'd set this up for your business, here's how I build digital employees. And if you're wondering who owns the thing once it's running, I wrote about that here.
Want the guardrails designed before anything runs?
Email me the job you'd hand off and what worries you about it. Email is by far the best way to reach me, and I'll reply with the limits I'd build in.
Email matt@shepardconsulting.ai →Frequently Asked Questions
What does AI governance mean for a small business?
Deciding in advance what an AI system can touch, what it can never do, and who reviews its work. For a digital employee that means a written job description, restricted accounts, hard limits enforced by permissions, and named approval points.
How do you stop an AI digital employee from making a costly mistake?
Remove its ability to take the costly action. A bookkeeper that can only create drafts can't pay a wrong bill. Limits enforced by permissions hold even when the AI misunderstands an instruction.
Should an AI digital employee have its own login?
Yes. Separate accounts with the least access the job needs make every action traceable and let you shut one employee down without affecting anything else.
How long before a digital employee works without approval?
Plan on at least a week of daily approvals. Approvals are then removed one category at a time as the error rate drops. Money and anything irreversible can stay with a person permanently.