This is a good reminder that the hard part is not getting an agent to act. It's constraining what it can do once it acts.
The controls that keep coming up for us are pretty boring: scoped authority, clear stop conditions, repeated-blocker breakers, and a receipt that explains why the run ended. That layer matters just as much as the model once the agent is attached to real systems.