Deciding What Your AI Is Allowed to Do

A customer-facing AI that only writes sentences is a fancy FAQ. The interesting version can act: check who is messaging, look at their last order, find a free slot on Thursday, book it. Each of those is a capability you switch on, and each one changes what a mistake costs. Our guide to teaching an AI to sound like your business treats this as a staged decision rather than a single setting.
Sort capabilities by what a mistake costs
The useful ordering is not by usefulness but by reversibility.
- Read-only lookups — who is this contact, what did they order, what stage is their deal in. A wrong lookup produces a confusing sentence and nothing more.
- Searching your own material — knowledge base and past conversations. Same risk profile, slightly more room to quote something out of context.
- Writing to internal records — adding a note, updating a custom field, moving an opportunity. Reversible, but now the AI is changing your data.
- Sending things to customers — templates, links, documents. Not reversible. A sent message cannot be recalled.
- Committing your capacity or money — booking an appointment, taking a deposit, cancelling a slot. Reversible only by inconveniencing a real person.
Turn them on in that order, and leave a week between steps. Most problems appear within three or four days of live traffic, and it is much easier to attribute a problem to the one thing you changed.
Booking is the big one
Letting an AI book appointments is the capability that changes the product from a chatbot into something that runs part of your business. It is also the one where the failure is physical: a customer arrives on Thursday and there is no room, no staff member, no chair.
Do it per service rather than all at once. Simple, fixed-duration, low-consequence services — a consultation, a standard cut, a viewing — are safe early candidates. Anything needing judgement about suitability, a specific technician, or more than one resource should stay with a human until you have watched the easy cases work. The mechanics of preventing double-bookings across staff and rooms are covered in scheduling multiple staff and resources without double bookings.
Enable capabilities one at a time and leave a week between them. It is the only way to know which change caused which surprise.
— be digital ai team
Reading is not always harmless
Lookups feel safe because nothing changes, but they carry a disclosure risk. If the AI can read the contact record, it can repeat what is in it — including internal notes a colleague wrote in shorthand about a difficult customer. The same care belongs in the material it retrieves, which is why building a knowledge base your AI can actually use insists on keeping internal notes out of it. Before enabling contact lookups, check what your team actually writes in notes, and keep genuinely internal commentary out of fields the AI can reach.
The same applies to conversation history. Being able to say "I can see you asked about this in March" is excellent service; reading back a complaint the customer made about a named staff member is not.
Web search: usually no
Live web search sounds attractive and is rarely right for customer chat. It introduces information you have not approved into a message sent under your name, and the most common result is the AI cheerfully citing a competitor or an out-of-date third-party page about your own industry. If a question needs the open web, it needs a human. Where search genuinely helps is in the internal copilot, not the customer thread — a distinction drawn in the difference between a customer-facing AI and a workspace copilot.
Write down who owns each switch
Capabilities get enabled during a busy week and forgotten. Keep a short note of what is on, when it was turned on, and who decided — and review it whenever you add a service or change how bookings work. An AI allowed to book a service you stopped offering is a specific and avoidable kind of embarrassment.
Pair every capability with a matching rule about when not to use it, and make sure there is always the escape route described in when the AI should stop and fetch a human. A capable AI that knows when to stop is far more valuable than a cautious one that never does anything — and far safer than a capable one that never stops.
A 20-minute walkthrough of enabling AI capabilities safely in be digital ai, service by service.
Book a Demo