The Protocol Is Not the Process
The safest protocol is firm about authority and consequence, then generous about how the work gets done.
Fix the edges. Free the middle.
John Rector
September 16, 2026
Implementation note 01
The previous article argued that a company should publish a clear way to accept good work. That argument can be implemented badly.
A nervous organization can turn every insight into a required field, every exception into a prohibition and every successful example into the only approved method. The protocol grows until it becomes a process manual. The process manual grows until the capable person—or capable agent—spends more effort satisfying the system than solving the problem.
This is especially dangerous with AI. An intelligent system creates value by interpreting an outcome, exploring alternatives, noticing unexpected evidence and changing its approach. If we prescribe every intermediate step, we buy intelligence and then prohibit it from thinking.
The opposite failure is easier to see. “Use your judgment” plus broad credentials is not freedom. It is unbounded authority. The agent may discover a brilliant route and still send the wrong message, expose private data, spend without limit or convert an unfinished idea into an institutional promise.
A living protocol distinguishes the path from the perimeter. It is strict where harm can escape into the world and flexible where exploration remains private, reversible and observable.
Begin by separating the work into three zones. Most protocol failures come from treating them as one.
The hard edge contains conditions that cannot be traded for convenience: legal limits, privacy boundaries, credential scope, spending ceilings, prohibited claims and the definition of who may bind the company. The review gate contains actions that can happen, but only after a named person or stronger automated check sees the proposed artifact. The open middle contains the search, synthesis, drafting, comparison, simulation and invention that make intelligence worth having.
Swipe the safety envelope
Rigid where it matters
The design goal is not maximum control. It is maximum useful freedom inside an envelope whose failures remain limited, visible and recoverable.
Zone 01 / Hard edge
Never cross silently
Secrets, protected data, legal commitments, irreversible deletion, unbounded spend and authority the person does not possess. Enforce these limits with credentials, infrastructure and deterministic checks—not hopeful instructions.
Zone 02 / Review gate
Propose before acting
Publishing, sending, paying, changing a customer record, modifying production and making an external promise. Put the artifact, destination and consequence in front of the accountable reviewer.
Zone 03 / Open middle
Explore aggressively
Research, draft, compare, prototype, test, branch, challenge assumptions and surface better questions. Keep this work private or staged. Reward useful surprise. Preserve evidence so novelty can be evaluated.
A practical protocol needs fewer rules than most policy documents and more structure than most prompts.
These parts should not have equal weight. Invariants should be few and hard. Heuristics should be plentiful and soft. Gates should sit close to the consequence. Receipts should be automatic whenever possible. The learning loop should have an owner and a cadence.
A long protocol often signals that the organization has placed procedural preferences inside the invariant layer. Ask of every rule: What harm does this prevent? Could a test, permission boundary or review gate prevent that harm more directly? If the answer is yes, replace the mandated step with a measurable edge.
Novelty cannot be specified in advance. It can be given favorable conditions.
First, give the work an outcome rich enough to reason about. “Follow these six steps” rewards compliance. “Reduce the time between a qualified lead and an accurate proposal without lowering margin or surprising the customer” creates room for discovery.
Second, make experiments cheap. Give the agent a staging environment, synthetic data, a draft-only credential, a branch, a spending limit or a small customer cohort. Freedom expands when failure is reversible and the blast radius is small.
Third, ask for alternatives before commitment. A strong protocol may require three approaches with tradeoffs, one recommendation and the evidence that changed the recommendation. The requirement is not that creativity occur in a particular way. The requirement is that the decision surface becomes inspectable.
Fourth, preserve the exception channel. The most valuable signal may be that the requested artifact is wrong. An agent should be allowed to return: “I can complete this, but the evidence suggests a different objective.” That is not noncompliance. It is intelligence reaching the boundary.
Organizations often put control at the beginning: a long approval process, a restricted tool list, a prompt template and a training course. Then they give the approved system a large credential and hope the instructions hold.
Better control sits near the moment an action becomes real.
An agent can research freely and still require approval before it emails a customer. It can produce ten pricing structures while a deterministic rule rejects anything below the company’s floor. It can prepare a database migration in a sandbox while production access remains unavailable. It can draft a payment while a second person must authorize release.
OpenAI’s practical guide to building agents describes guardrails as a layered defense and identifies human intervention as especially important for failure thresholds and high-risk actions such as payments or large refunds. The design principle is broader than any one agent framework: use several independent controls, and escalate where sensitivity, irreversibility or stakes increase.
Instructions remain useful. They express purpose, tone, context and preference. They should not carry the full burden of security. A sentence that says “never send without approval” is weaker than a credential that cannot send, a review queue that shows the exact recipient and message, and a log that records who released it.
The open middle becomes safer when the exit carries evidence.
A useful receipt contains the artifact, the sources or tests that support it, the actions taken, the permissions used, the uncertainty that remains and the location of the institutional record. It does not need to expose every private thought. It needs enough provenance for another person to review the result and enough operational history to reconstruct consequential action.
Evidence also protects creativity. Without it, a novel result looks like a deviation. With it, the contributor can show why the deviation is better. The reviewer can disagree with the judgment while still learning from the path.
Anthropic’s guide to evaluations for AI agents emphasizes that useful evaluation combines methods because agents operate across many steps, tools and changing state. Static checks can verify structure. Simulations can test workflows. Human judgment can assess qualities that remain contextual. The same layered approach belongs in a company protocol: measure the invariant mechanically, inspect the artifact against a rubric and keep a human close to the consequence.
A protocol that never changes is a frozen guess about the future.
Every exception should produce one of four outcomes. The protocol was right and the work should be corrected. The protocol was unclear and the language should improve. The protocol was too strict and a new safe route should become available. The protocol was too loose and the edge needs a stronger control.
The NIST AI Risk Management Framework Core treats monitoring, appeal, override, incident response and change management as continuing parts of AI risk management. That matters here because a protocol is not finished when it is published. It begins learning when real work presses against it.
Version it like a product. Name the owner. Record why a rule changed. Keep old receipts readable under the old version. Test the new version on representative and messy cases. Roll it out to a limited lane. Watch both failures and the disappearance of useful variation.
Safety can overfit too.
Imagine a company wants personal AI systems to help create customer proposals.
The rigid design specifies the sequence: use this template, pull these fields, write these headings, calculate price this way, use these sentences and ask this manager. The system is consistent and brittle. It cannot notice that the customer’s real constraint is schedule, that the standard package creates unnecessary work or that a better scope exists.
The loose design says: “Create a great proposal.” The agent receives the CRM, price book and email account. The system is creative and unsafe.
The living protocol defines the outcome: an accurate, profitable and comprehensible offer that reflects the customer’s stated need. It defines invariants: approved services only, price above the authorized floor, no unsupported promise, customer data stays within approved systems. It grants read access to the relevant record and draft access to the proposal workspace. It keeps research, structure, explanation and option design open. It requires evidence for nonstandard scope. It places a human gate before the proposal is sent. It records the accepted offer and the approval.
Now novelty has somewhere to live. The AI can propose a phased option, discover a contradiction, reframe the explanation or surface a risk. The company remains protected because creativity cannot silently become commitment.
The best protocol feels less like a checklist and more like a well-designed landscape.
The banks are obvious. The dangerous crossings have gates. The open field is genuinely open. Alternate routes are expected. People can stop, inspect and appeal. The company can see what became real without demanding ownership of every draft, question or intermediate thought.
This is how a protocol supports evolution. It does not preserve one process. It preserves the conditions under which many processes can compete, learn and improve.
This is how it supports safety. It does not hope intelligence will remain predictable. It limits authority, locates review, records consequence and watches the evidence.
This is how it supports creative problem solving. It tells capable contributors what must remain true, then gives them room to discover a better way.
Evidence / checked 09.16.26
Sources
- OpenAI, A Practical Guide to Building AI Agents, for layered guardrails and human intervention around failure thresholds and high-risk actions.
- Anthropic, Demystifying Evals for AI Agents, published January 9, 2026, for evaluation across multi-step, tool-using agent behavior.
- NIST AI Risk Management Framework Core, for ongoing monitoring, human-AI oversight, appeal, override, incident response and change management. NIST notes that AI RMF 1.0 is being revised.