AI & Tools

How to Use AI for Operations Without Handing Over the Keys

By Viveka von Rosen · August 31, 2026


AI is good at preparing the recurring work of running a business and should not be trusted to finish it unsupervised. Here are ten operational tasks worth handing over, the boundary each one needs, and how to decide what an agent may touch before you build it.

The recurring work of running a business — the inbox, the meeting prep, the notes that have to become tasks by Friday, the client record nobody has touched since March, the invoice you are fairly sure went out — is the work AI is best at preparing and worst at being trusted with, and both halves of that sentence matter equally. An agent can gather the material, sort it, draft the next version, and hand the whole thing to you in a form you can approve in four minutes instead of rebuilding it from scratch in forty. What it should not have, at least not in week one, is standing permission to send, change, move, or delete anything with your name on it.

So this piece does two jobs at once: ten operational tasks worth handing to AI in a business built on your own knowledge and relationships, and the permission boundary each one needs before you hand it over. Because the fun part is building the agent, and the part that keeps you out of trouble is deciding what it may touch, and those two decisions arrive about fifteen minutes apart.

I will say the obvious thing first, since I own a business too: nobody starts a company because she has always wanted to spend a Wednesday afternoon reconciling a spreadsheet. The client work is the reason and the operational work is the tax, and it does not care that you are tired, and it compounds, politely, in a folder while you ignore it. (My Downloads folder was a crime scene for two years. We will get to that.)

This is one edition of a longer series of fifty practical AI uses, and if you have not decided which part of your business to point AI at first, start with how to choose your first use case and then come back here, because picking the wrong task first is the single most common reason this stuff gets abandoned in week two.

Why does the operational work in a small business never get smaller?

Operational work never shrinks because almost all of it depends on somebody remembering, and in a business built around your expertise, that somebody is you. The tasks themselves are small — update the record, send the reminder, pull the notes, name the file — but every one of them needs context that lives in your head, which means none of them can be handed off cleanly, which means they queue up behind the client work and wait.

This is also why hiring does not solve it as fast as people expect, because half the reason we struggle to delegate is that we have never written the process down, and you cannot hand a VA a procedure that exists only as a feeling you get on the second Tuesday of the month. (Some of us are also control freaks. Moving on.)

AI helps here for a reason that sounds boring and is not: it does the preparation step every single time without being asked twice, and preparation is where most of the hours go. The judgment stays yours; the gathering, sorting, drafting, and cross-checking do not have to.

What can an AI agent do in your operations, and what stays yours?

An agent can gather information, follow written instructions, use approved tools, and prepare a result for your review, and with more permission it can complete steps you have already tested. What stays yours is anything that makes a promise to a client, moves money, changes a record of truth, or reaches a human being.

The mental model I keep coming back to is the one where I imagine a very fast, very literal new hire on her first week. She is capable, she reads everything you give her, she does not get bored, and she has absolutely no idea which of your clients is in the middle of a divorce and should not receive a chirpy payment reminder on Tuesday. You would not hand that person your outbox on day one. You would give her the prep work, read what she produced, and expand the job as she earned it.

How much access should you give an AI agent?

Give it the least access the task can run on, and add one permission at a time, starting with read-only. An agent that reads your notes and prepares a morning brief carries one level of risk, and an agent that can email a client, edit a record, move files, or publish to your website carries a completely different one, and the platforms mostly let you choose which of those you are setting up.

The big platforms now ask to connect to your email, your calendar, your files, and in some cases your financial and health accounts, all with your permission and all behind a very friendly button, so treat every one of those as a decision rather than a default. One founder will happily let her agents roam through her files and apps, another wants to click yes at every step, and both are correct for their own business, their own clients, and their own blood pressure.

My own rule scales with the stakes: the more sensitive the data or the more consequential the action, the tighter the boundary, and read-only reporting comes a long way before permission to change a record or message a person. I am not recommending you copy my settings. I am recommending you have settings.

And one more thing, because it is the part people skip: you can find public agents, skills, and GPTs sitting in repositories all over the internet, and free does not mean private, maintained, safe, or plug-and-play. Before you give a downloaded workflow access to your inbox or your client folder, read what it does, and find out where the data goes, which provider processes it, and what happens when you delete it. (Not a fun paragraph. Less fun than the alternative.)

Three levels of permission

Read and report: the agent looks at approved material and gives you a summary or a brief, changing nothing. Prepare and propose: it drafts the email, the invoice, the record update, or the file-renaming plan, and everything waits for your approval. Act inside a fence: it completes a specific low-risk step you have tested repeatedly, with a log you can read afterward. Most operational work should live at the first two levels for a good long while.

What are the ten operational tasks worth handing to AI first?

These are ten recurring jobs that repeat often enough to be worth the setup, and each one comes with the boundary I would put on it. Take the ones that match a task already annoying you, and leave the rest — this is not a checklist, and you do not get a prize for building all ten.

1. Sort and summarize the inbox

An email agent reads the inbox and hands you a brief instead of a pile. One of the first agents I built groups messages by client, project, urgency, and next action, then tells me what needs me today and what can wait until Thursday.

It drafts replies when a thread has enough in it to draft from, and those drafts sit in the drafts folder until I have read them and changed at least one sentence, which I always do, because AI writes me as slightly more agreeable than I am. (Nobody who knows me is confused about this.) What I love most is the catching — the unanswered question buried in paragraph four, the promise I made on a Thursday and forgot by Monday, the chatty client whose eleven emails about one scheduling change contain exactly one sentence that matters.

The boundary: read and prepare only. No sending, no archiving, no deleting, ever, and start it on one folder or one week rather than the whole account.

Starter prompt: Review these emails and prepare an inbox brief, grouped into personal response needed, simple reply, information only, waiting on someone else, and unclear. For each message give me the sender, topic, deadline, any promised action, and why it landed in that group. Draft replies only where the thread has enough information to draft from. Do not send, archive, delete, or invent an answer.

2. Prepare for meetings

A meeting-prep agent pulls the invitation, the previous notes, the open tasks, the relevant emails, and the background into one brief you read on the way to the call. Mine reaches my client folders and the document where I track each client’s progress, checks recent email, and looks at LinkedIn for anything I should know before I say hello.

The brief covers who is attending, what we discussed last time, which decisions are still open, what I said I would bring, and five questions worth asking, and it replaced the twenty minutes I used to spend reconstructing a relationship five minutes before the call — a situation I am sure has never happened to any of you, ever, not once.

The boundary: pure read-only, and one of the best first agents for exactly that reason. It finds and organizes; the conversation is still yours.

Starter prompt: Prepare a brief for my meeting with [person or group] about [topic] from the attached invitation, notes, emails, and approved background. Include the purpose, who is attending, relationship history, previous commitments, open questions, and five questions I might want to ask. Separate facts from your assumptions and flag anything missing.

3. Turn meeting notes into tasks and follow-up

This one takes a transcript and returns a summary, the decisions, the open questions, the tasks with owners and dates, and a draft follow-up email, which is the highest-value hour you will get back, because post-call work is what slides when the next call starts in six minutes.

I have gone further than summaries with mine, building skills in Claude with very specific instructions, so one command turns a session transcript into the summary, the action plan, the homework, and the client resources that used to eat an afternoon. A client emailed me after one of those asking whether I had written the summary or AI had, and the answer was a little of both. Yes, Zoom and Fireflies and Calendly all produce decent summaries on their own — they do not produce the specific thing you want, shaped the way you work, until you teach them.

The boundary: it does not create the tasks in your system and it does not send the email. I still check who agreed to what, because a transcript is full of polite suggestions, half-finished thoughts, and enthusiasm that should not become a commitment.

Starter prompt: Review this transcript and prepare a short summary, the decisions made, open questions, tasks with their stated owners and dates, commitments I personally made, and a draft follow-up email. Distinguish firm decisions from ideas we were kicking around, and mark an owner or date as unassigned if it was never stated. Do not create tasks or send anything.

4. Write and update your procedures

AI is freaking excellent at turning screen recordings, transcripts, rough notes, and finished examples into a written procedure somebody else could follow, finding the steps you skipped when you explained it and writing the version for a person doing the work for the first time.

My memory used to be a steel trap and is now more of a colander, which turned out to be a gift, because it forced the processes out of my head and into documents a VA or a client or a future version of me can use. On supported plans, Claude for Mac can watch you perform a task in Cowork — your screen, your clicks, your muttering — and propose a reusable skill from what it observed, which is a deeply strange experience the first time. (Close anything private before you hit record. Ask me nothing.) I compared that setup to the ordinary chat window in this piece on ChatGPT Work and Claude Cowork.

The boundary: when the process changes, hand it the old procedure and the new evidence and ask for the proposed changes as a list you read before anything replaces anything. Nobody rewrites an operating document on my behalf without me seeing both versions.

Starter prompt: Turn this [transcript, recording, or example] into a written procedure for [task], including the purpose, required access, inputs, numbered steps, decision points, the quality check, common mistakes, and when to ask for help. Flag anything the source does not explain instead of filling the gap from general knowledge. End with the questions I need to answer before someone else could run this.

5. Organize projects and priorities

A planning agent reviews your active projects, deadlines, dependencies, available hours, and current goals, then proposes a realistic week. I need this one badly, because I start a build, get distracted by something shinier, and resurface on Thursday with four things half finished.

It tells me what deserves attention, what is blocked, what no longer supports a goal I care about, and what will not fit no matter how optimistic I feel on Sunday night. I take that considerably better from software than from my husband, who has made similar observations and received a less gracious response. 😊

The boundary: it does not touch a calendar entry or a project record. And the priority call stays with you, because AI has no idea which relationship, opportunity, or protected Friday afternoon matters most unless you tell it — it can only see what fits.

Starter prompt: Review this project list, calendar, deadlines, and weekly priorities, then prepare a realistic plan for [available work hours] with these non-negotiable constraints: [constraints]. Identify blocked work, missing owners, deadline conflicts, and tasks that no longer support a current goal. Recommend what to do, defer, delegate, or clarify, and say why. Do not change any project or calendar entry.

6. Keep client and prospect records current

After a call or an email exchange, the agent prepares the record update: the date, what was discussed, what she said she needed, what I committed to, the next action, and the follow-up date. I used to run all of that on a wish, a prayer, and my clients’ memories, and now it is there in black and white. (And purple and teal, because I am me.)

This one pays off hardest when the context is scattered, which it always is — a little in the inbox, a little in the calendar, a little in a notes app you stopped opening in April. I ran a similar cleanup pass on the network side of things in this piece on cleaning up LinkedIn connections with Claude.

The boundary: it prepares the update and you write it in, at least until the process has proven itself over a stack of real calls. It should also quote the source for every commitment it lists and flag anything sensitive that has no business being stored in a record at all.

Starter prompt: Using these approved notes and messages, prepare an update for this client record: date, type of interaction, topics discussed, stated needs, commitments, resources promised, next action, owner, and follow-up date. Quote the source line for each commitment and flag sensitive details that should not be stored. Do not update the record or trigger any sequence.

7. Draft invoices and payment reminders

AI can gather the approved billing information, match payments against outstanding items, prepare the invoice, and draft the reminder when something is late. Moving my invoicing into Stripe let me stop paying monthly for a separate invoicing tool, and my AI now prepares the first version of what goes out.

I want to be careful here, because this is something I do for myself and not something I am telling you to go do, since financial work carries compliance and accuracy risk that email sorting does not. AI can prepare and it can flag, and you still confirm the legal entity, the amount, the currency, the tax treatment, the recipient, and the due date before anything leaves the building. I review every outbound dollar figure, and I still pay a professional for the work that requires a professional.

Also, watch the tone. A first reminder sent one day late should not read like a collection agency has arrived and set up a folding chair in the lobby. (Or is that only my reminders?)

The boundary: draft only, with the source shown for every number. It does not send, it does not issue, it does not touch the ledger, and it never assumes a late fee.

Starter prompt: Using the approved agreement and billing record, prepare a draft invoice or payment reminder for my review. Show the client, service, amount, currency, tax treatment, issue date, due date, payment method, and the source for each detail, and flag any conflict or missing information. Do not send it, issue it, change the ledger, or assume a late fee.

8. Organize your business files

An organizing agent proposes a folder structure, renames files to a consistent pattern, finds duplicates, and builds an index of where the important things live. This is the one that blew me away, and I say that as somebody who assumed file management was beneath the technology.

My Downloads folder was a holy disaster of half-read contracts and screenshots named Screenshot, so I built an agent to sort it, and it is clean now, and it stays clean because the agent runs a pass every week. Documents is next, slowly, one area at a time.

The boundary: start on a copy or a small test folder, and have it produce a change table — current name and location beside proposed name and location — that you approve before anything moves. Do not give an untested agent permission to reorganize your business drive while you go make coffee. That is how a time-saving experiment becomes a Saturday and some creative language.

Starter prompt: Review this file list and propose a simple organization system for [business area]: folders, naming rules, archive criteria, and duplicate-review steps. Give me a change table showing current name and location beside proposed name and location, and flag sensitive, unclear, or conflicting files. Do not move, rename, merge, or delete anything.

9. Produce a weekly business report

A reporting agent gathers a small set of numbers and updates and prepares a one-page view of clients, prospects, revenue, marketing, projects, and the decisions waiting on you. Time to fess up: this one is still on my list, I have been meaning to build it for ages, and I suspect I will finally do it on the next long flight.

What makes a report useful is restraint — the few signals connected to what you are trying to do this quarter, shown plainly, with unreliable data marked as unreliable rather than rounded to zero because nobody looked, instead of twenty colorful charts you feel vaguely guilty about not reading.

The boundary: read-only against approved data, with interpretation separated from fact, so you can see which part is the number and which part is the software guessing at what the number means.

Starter prompt: Prepare a one-page weekly business report from the attached approved data, covering [chosen areas]. For each area show what changed, what needs attention, and any missing or unreliable information, keeping facts separate from interpretation. End with the decisions I need to make and one recommended focus for next week. Do not change records or treat missing data as zero.

10. Build one assistant that runs the recurring jobs

Once several of these work on their own, you can build an agent that runs the others, so one assistant keeps the recurring rhythm going without waiting for you to remember to ask — the morning brief, the meeting follow-up, the content queue, a shared inbox, and the weekly report on Friday.

Give it instructions, reference material, approved tools, permissions, and review rules the way you would brief a person, then start it read-only with everything landing in drafts and add one action at a time, watching how it handles normal input, incomplete input, contradictory input, and the deeply weird input every real business produces. (My VA does not do all of that, and she is excellent.) If the line between using AI and building something with it is still fuzzy, I pulled that apart here.

The boundary: every action it takes gets logged where you can read it, and the review rules are written down before the first run rather than invented after the first surprise.

Starter prompt: Help me define an AI assistant for [recurring job]. The result I want is [result]. It may use [approved sources and tools], it may prepare [outputs], it may not [forbidden actions], and it must ask for approval before [review points]. Design the workflow, required inputs, error handling, an activity log, and test cases. Start read-only and do not connect to or change any system.

What do you write down before you build an operational agent?

Six things, and if you cannot write them, the agent is not ready for more access than a chat window. This takes about ten minutes with a cup of coffee and saves you the version where you find out what the boundaries were by watching one get crossed.

The six-line job description

The job it performs. The finished result you expect. The information it may use. The actions it may take. The actions that require your approval first. What it should do when the information is missing, contradictory, or weird. Write those six lines before you write a single instruction, and keep them where you can edit them, because you will.

Then run the workflow by hand, several times, saving the inputs, the instructions, the output, your corrections, and the version you finally approved, because those corrections are the most valuable thing you will produce all week — they become the instructions that make an agent good instead of merely fast. And do not build an agent for a process you have never once run yourself, because you will be automating a guess.

What does one of these look like all the way through?

Take the file organizer, because it is the least glamorous of the ten and it taught me the most. The problem was a Downloads folder I could no longer search, which meant re-downloading contracts I already had, always at the exact moment I needed the document.

The result I described: every file filed by client, filed by business area, archived, or flagged for me, named in a consistent pattern with the date first, with duplicates identified rather than assumed. The material it could use: the file list, the dates, and the contents of the documents it had to read to classify them. The boundary: propose, never move, and give me a change table before anything happens.

The first run was wrong in a useful way, because it grouped everything by file type — PDFs with PDFs, images with images — which is technically an organization system and completely useless to a human being hunting for one client’s signed agreement. So I rewrote the instruction to sort by client and business area first and treat file type as a detail, gave it examples of how I name things, and the second run was close, and the third I approved. I ran it on a copy of the folder before I ran it on the folder, which I recommend with my whole chest.

It also flagged a handful of duplicates that were not duplicates, because the names were similar and the contents were not, which is exactly why the change table exists and why I read it. Now it runs a weekly pass, I skim the changes over coffee and approve them, and I can find things. (Reader, I did not expect to have feelings about a folder.)

When is AI the wrong answer for operational work?

When the task is rare, when it is undefined, or when the real problem is a decision you have been avoiding. A quarterly task does not deserve a workflow, and I would rather you do it four times a year and go outside.

Undefined is the sneakier one. If your client onboarding is different every time because you have never decided what it should be, an agent gives you inconsistency at speed, and then you have two problems and a subscription. Decide the process first, run it by hand until it stops surprising you, and then automate the part that repeats.

And sometimes the operational mess is a symptom of something else entirely. If your records are chaos because you keep taking on clients who are not a fit and every project improvises its own shape, then building the file-naming agent is a very productive way to avoid having that conversation with yourself, and I have watched smart women spend a month on the machine so they would not have to make the decision underneath it. (I have been one of those women. It was a lovely machine.) The tooling gets easy once the decision is made.

Who is responsible when the agent gets it wrong?

You are, which is why a person has to own the decision and the result even when software produced the draft. AI can prepare an email, an invoice, a task list, or a report, and none of that transfers responsibility for what goes out under your name.

So review anything client-facing, anything financial, anything with legal or contractual language in it, and any action that changes a system outside your own laptop. Keep an activity record you can read, showing what the agent accessed, prepared, changed, or tried to change — not because you expect disaster, but because you want to be able to answer the question if a client ever asks it.

I am not promising AI will run your business, and some people are out there attempting exactly that, and I wish them a functioning backup. What it will do is remove the repeated preparation, surface the information you were missing, and give you a much better starting point for the decisions that were always going to be yours.

Where should you start?

Choose one recurring task you understand well enough to describe out loud, write the six lines, and let an agent prepare it read-only a few times. If the result is good and it gives you back real time, expand the job. If it is not, you have lost an afternoon and learned something about a process you had never written down, which is not nothing.

This gets easier, and waaaaaaaay faster than you expect. The first one feels slower than doing the task yourself, because you are making decisions you have kept in your head for years and never had to say in complete sentences — and then the second one takes twenty minutes and the fifth one takes ten. If you want help deciding which operational task is worth it in your business specifically, that is a good chunk of what I do with clients.

Pick the one that has been annoying you longest, and then use some of the time it gives back for something that is not work at all. I hear Costa Rica is lovely this time of year!!

Questions

Frequently asked


What is the best first operational task to give AI?

Meeting preparation, because it is read-only, it repeats constantly, and the worst case if the agent gets it wrong is a brief you ignore. It gathers the invitation, the previous notes, the open items, and the relevant emails into one place, and nothing it does can change a record or reach a client.

How much access should an AI agent have to my business systems?

As little as the task can run on, added one permission at a time. Start with read and report, move to prepare and propose once you trust the output, and only allow an agent to complete an action after you have watched it handle the same task correctly on normal, incomplete, and unusual inputs.

Should AI send emails on my behalf?

Not without review, and not in the beginning. Let it draft into your drafts folder so every message waits for a human read before it goes out, because an email that sounds almost right to a client who is mid-crisis is worse than an email that arrives a day late.

Can AI handle invoicing and payment reminders?

It can prepare drafts and flag conflicts, and financial work carries compliance and accuracy risk that ordinary admin does not. Confirm the legal entity, amount, currency, tax treatment, recipient, account, and due date yourself before anything goes out, and keep a financial professional for the work that requires one.

What should I write down before building an operational AI agent?

Six lines: the job it performs, the finished result you expect, the information it may use, the actions it may take, the actions that need your approval first, and what it should do when information is missing or contradictory. If you cannot write those, the task is not defined well enough to automate yet.

Is it safe to use an AI agent or skill I downloaded from a public repository?

Only after you have read what it does and where the data goes. Free does not mean private, maintained, or safe, and many public projects also need hosting, API fees, and upkeep before they run at all. Check which provider processes the data, who can access it, and what happens when you delete it before connecting anything to client information.

How do I stop an AI agent from making a mess of my files?

Run it on a copy or a small test folder, and require a change table showing the current name and location beside the proposed name and location so you approve the plan before anything moves. Duplicate detection in particular gets things wrong when filenames are similar and contents are not.

When is AI the wrong tool for operational work?

When the task is rare, when the process has never been defined, or when the disorganization is a symptom of a business decision you have been avoiding. Automating an undefined process produces inconsistency faster, which is a worse problem than the one you started with.

The Series

Get All Fifty Use Cases as They Publish


The whole series runs on my Substack — fifty practical AI uses for a business built on your own expertise, one category at a time, with the prompts and the boundaries included.

Subscribe Free