Every door a web-browsing research agent can be pushed through, the control that closes it, and the kill switches to test before the first run. No control, no launch.
Fill one card per agent. If a row has no control, the agent does not run. Write NONE and stop. Do not write “the prompt tells it not to.”
Test every kill switch before launch. A cap that has never fired is a cap nobody tested.
flowchart LR
Q["Question"] --> G["Gate: budgets + blocklist"]
G --> A["Agent: read-only tools"]
A --> N["Notes store"]
N --> C{"Quote in fetched text?"}
C -->|No| X["Drop and log"]
C -->|Yes| R["Human review"]
K["Kill switch"] -.-> G
K -.-> A
Is an agent the right shape?
If you can name the pages, use a scheduled fetch, a diff, and one model step instead. An agent is for open questions where the path is not known.
The research question is open and the pages are not known in advance
A change monitor was considered and does not fit
One named owner for the agent and its output
Toolset (three tools, no more)
Tool
Allowed
Limit written here
Search public web
Yes
Queries per run: ____
Fetch page (GET only)
Yes
Pages per run: ____ Bytes per page: ____
Write note to notes store
Yes
One store, append only, schema-validated
Send email or post to chat
No
Delivery is a separate approved step
Run code or shell
No
Not needed
Access the customer relationship management (CRM) system, billing, or files
No
No credentials in the agent environment
Budgets enforced by the runner
Max steps per run (number)
Max pages fetched (number)
Max bytes per page (number)
Max wall-clock seconds (number)
Max model spend per run (amount)
Allowed methods: GET only
Blocked hosts include localhost, internal addresses, and our own services
Doors and controls
Door
Control (write it)
Tested on
Injected instructions in a page
Date
Scope creep (logins, forms, private areas)
Date
Fabricated findings
Date
Runaway cost or loop
Date
Leaky context in queries or URLs
Date
Quiet drift after a prompt or model change
Date
No secrets, customer data, or private notes in the agent prompt
Every outbound search query and fetched URL is logged with the run id
Page text is treated as data, never as instructions
Output gate
The agent writes claim records, not a finished brief
Each record has a claim, URL, verbatim quote, retrieval date, and source type
A script drops any record whose quote is not in the fetched text
A named person reviews survivors before anything is used
Kill switches (test each one)
Global flag blocks new runs. Tested by flipping it mid-run.
A run in flight can be cancelled by run id
Page cap lowered to three in a test and the run stopped at three
Any stop writes a log line and alerts the owner
The whole agent can be stopped in under one minute by someone who did not build it
Change control
Prompt, budgets, and allowlists are versioned
A short set of known research questions reruns after every change
Quote-check drop rate is logged. A sudden rise is an alert.