Session
The agent acts, the owner's asleep: trust and control for an always-on AI agent
At HoneyBook we shipped an agent that acts for small-business owners — it sends invoices, messages clients, and books meetings, and it's built to do all that while the owner is asleep. That's a liability with a login. Getting it to production forced a chain of problems, where every fix opened the next one, and that chain is the talk.
You can't put "ask before acting" in the prompt, because a prompt can be talked out of anything. So a gate outside the LLM decides whether a tool call runs, waits for the owner, or never happens. Once the gate defers something you're holding a half-finished action for eighteen hours, across redeploys. Then the owner finally answers "sure" — mid-conversation, with three requests pending. Which one did they just approve? Was it even really them? And is a yes still a yes when the world changed while you waited?
We ended up solving all of it in the architecture around the model: how a business stays in control of an agent that acts while nobody's watching.
Jenia Barabanov
Engineering Guild Lead @ Honeybook
Valencia, Spain
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top