I gave an AI agent a business and told it never to touch the money
Sixty sprints of an AI-operated course business, and why the guardrails matter more than the automation.
I often tell clients that AI can run recurring operational work, as long as the boundaries are designed before the automation. At some point I had to test that claim on myself.
So I built a small business to be run that way. unai-labs.com sells plain-language courses on AI literacy, neuroplasticity and brain health. An AI agent operates it in logged sprints. Sixty sprints in, 31 posts and four paid courses are live.
The interesting part is not what the agent does. It is what it is not allowed to do.
The rules
It never touches money or logins. The agent will not enter credentials and will not place an order. Connecting the payment gateway needs my credentials, so it waits for me, even though that blocks revenue. That is a deliberate trade. A few weeks of delayed sales is cheaper than an agent with access to payments.
The live site is the source of truth. Each sprint starts by comparing the real, public site with the sprint log. If they disagree, the site wins and the log is corrected. This catches drift that a system trusting its own records would miss.
Decisions are separated from tasks. Pricing, naming, ISBN registration, whether to publish under a pen name: these sit in a running backlog that only I can clear. The agent does the work around them and flags what is blocked. It never makes the call.
It audits itself on a schedule. Every fifth sprint is a full content audit: every post, course, product and page checked against the live site, with findings logged. One audit found two posts covering nearly the same topic, a risk to search ranking. The agent did not fix it on its own. It logged it as a decision for me.
What this taught me
Most of the effort went into the operating model, not the prompts. Where does the agent get its truth? What can it change without asking? What must it always hand back? How does it prove it did what it says?
Those are the same questions any organisation should answer before giving an agent real work. They are governance questions, not technology questions.
What is still open
The payment gateway is still not connected, by design. Four finished posts are waiting because the agent needs an admin session it is not permitted to create for itself. Both are the guardrails working, not failing.
If you are planning agentic AI in a real operation, start with the list of things the agent must never do. Build the automation around that list, not the other way round.