A rule is only useful if the agent can apply it in the middle of a live call, with a caller waiting. Rules written like policy documents ("staff should exercise appropriate discretion") fail that test. Rules written like instructions to a new colleague ("you may move an appointment within thirty days; beyond that, ask the manager") hold up.
AI agent guardrails work when each rule states one action, the condition for it, a limit and what happens beyond that limit. Vague wording such as use appropriate discretion forces the agent to guess, so write rules that a person could check against the call afterwards.
This guide shows how to write permissions, limits and handoffs that behave the same way on call one and call ten thousand.
Why vague rules fail
Consider a rule such as: be generous with refunds when appropriate. On a real call, the agent has to decide what "generous" and "appropriate" mean, and it will decide differently depending on the caller's tone. Different answers for similar callers is a fairness problem and a cost problem.
A good rule removes the guess. It states the action, the condition and the limit in words that can be checked against the call.
The four parts of a rule
Every rule should answer four questions.
- What action? A specific thing the agent might do: move an appointment, issue a credit, share a document.
- Under what condition? When it is allowed.
- Up to what limit? Amounts, dates, counts or time windows.
- What happens beyond the limit? Ask for approval, hand over, or decline.
If any of the four is missing, the agent is improvising.
Example wording
Here are rules written in the shape that works. Adapt the numbers to your own business.
Action: Offer a goodwill credit
Condition: Delivery was more than 24 hours late and the caller is verified
Limit: Up to 20 per cent of the order value
Beyond the limit: Ask the duty manager for approval and tell the caller you are checkingAction: Share a customer's booking details
Condition: Caller has passed verification (name plus date of birth)
Limit: Only the booking they ask about
Beyond the limit: Decline and offer to send details to the number on fileAction: Cancel an appointment
Condition: Caller confirms the cancellation out loud
Limit: Single appointment per request
Beyond the limit: Hand over to the front deskNotice what these share. They are concrete, they can be checked afterwards, and each one says what happens when the situation is bigger than expected.
Permissions: what the agent can touch
Start with permissions per action, not per topic. For the kinds of errors guardrails are there to stop, see why AI voice agents make things up. Create three lists:
- Always allowed. Answering common questions, checking availability, sending approved documents.
- Allowed with conditions. Moving bookings, issuing small credits, updating contact details after verification.
- Never allowed. Medical or legal advice, changing payment details without a verified human, promising outcomes you cannot guarantee.
Keep the "never" list short and unambiguous. A long list of prohibitions gets read less carefully than a short one.
If a rule needs a paragraph to explain, split it into two rules that each fit in a sentence.
Limits: numbers beat adjectives
Use numbers wherever you can. "A small discount" becomes "up to 10 per cent". "A reasonable time" becomes "within two working days". "Several attempts" becomes "three attempts across three days".
Where you cannot give a number, give a test the agent can apply, such as "if the caller has contacted us twice about the same issue, hand over".
Handoffs: who, when, what
A handoff rule names the trigger, the recipient and what travels with it. The warm handoff guide shows what the human should see.
- Trigger. The caller asks for a person; the caller is distressed; the request is outside permissions; the agent is not making progress.
- Recipient. A named role or team, with a fallback if nobody is free.
- What travels. A short summary, the facts gathered and what the human is asked to do.
Include the out-of-hours case. If no one is available, the rule should say: collect the details, book a callback and create a task.
Approvals: asking before acting
Approvals sit between "allowed" and "not allowed". The agent asks a named person, who can approve, modify or deny in one tap, and the agent carries on. See the control page for how approvals work.
Write down who approves what. A refund approval might go to a team lead, a contract change to the account owner. Give a time limit: if no answer arrives in five minutes, what does the agent tell the caller?
Consent, redaction and records
Some rules are about data rather than actions.
- Which channels the customer has agreed to be contacted on.
- Which details are redacted from transcripts, such as card numbers.
- How long recordings are kept.
- Which details can be spoken aloud, and which must be sent in writing.
These should be set once in your guardrails, not repeated inside each conversation script.
Testing rules before you rely on them
Rules look right on paper and fail on calls. Test each one with three calls:
- A caller who clearly qualifies.
- A caller who is just over the limit.
- A caller who argues, interrupts or changes their mind.
The second and third are where problems appear. If the agent behaves inconsistently, the rule is not tight enough.
A review habit
Every week, read the calls the agent flagged. For each, ask whether a rule was missing, unclear or wrong. Change the rule, retest it, and move on. Over a month, your rules will get shorter and clearer, not longer.
Mistakes to avoid
- Rules that depend on the agent guessing the caller's mood.
- Limits that are different in three documents.
- Handoffs with no named recipient.
- Exceptions buried in a long paragraph.
- No instant pause: always know how to stop the agent if something looks wrong.
What to do next
Pick your five most common actions and write each as action, condition, limit and what happens beyond the limit. That page is a better starting point than any template.
Read about guardrails, see how rules apply in healthcare, and use the seven-day go-live plan to fit rule writing into your launch week.
Frequently asked questions
What should an AI agent rule include?
Four parts: the action, the condition, the limit and what happens beyond the limit. If any one of the four is missing, the agent is improvising.
How many permissions should an agent have?
Keep three lists: always allowed, allowed with conditions and never allowed. Keep the never list short, because long lists of prohibitions get read less carefully.
How do I test a rule before I rely on it?
Run three calls: one caller who clearly qualifies, one who is just over the limit, and one who argues or changes their mind. If the agent behaves inconsistently, the rule is not tight enough.
How do I keep the rules up to date?
Each week, read the calls the agent flagged and ask whether a rule was missing, unclear or wrong. To see rules working on a live line, try a call.






