Skip to content
Workflows Resources Case Studies Pricing About

An AI agent that talks to customers is not a feature you switch on. It is a representative of your business that speaks at machine speed, hundreds of times a month, without a manager listening. Most problems we see with customer-facing agents are not model problems. They are governance problems: nobody decided what the agent may promise, nobody wrote down when it must hand over to a person, and nobody kept records of what it said.

Governance does not require a committee or a compliance department. It requires four artifacts and a habit: approved content rules, escalation paths, an audit trail, and a monthly review. This playbook builds all four for a small or mid-sized business.

Key takeaways

  • Decide in writing what the agent may say and never say; approved content beats improvised answers.
  • Define escalation triggers and destinations before launch, including after-hours behavior.
  • Log every conversation, decision and handoff with timestamps; an audit trail you cannot read is not an audit trail.
  • Keep a human in the loop with a monthly sample review against a short rubric.
  • Treat prompt injection and excessive permissions as security risks, not edge cases.
  • Put it all in one page that lives with the system, so new team members inherit the rules instead of reinventing them.

Why governed agents outperform ungoverned ones

Established risk frameworks already describe the work. The NIST AI Risk Management Framework, released in January 2023 and revised as part of ongoing federal work, organizes risk management around four functions: govern, map, measure and manage. You do not need to adopt the framework formally to benefit from its logic. In practice, govern means someone owns the rules, map means you know where the agent operates and what it touches, measure means you review real conversations, and manage means you fix and improve.

Regulation is converging on the same idea. The EU AI Act, which entered into force in August 2024 and became broadly applicable on August 2, 2026, includes transparency duties such as informing people when they are interacting with a machine. If you serve customers in the EU, that requirement applies to chatbots and voice agents. If you serve customers elsewhere, your local consumer protection rules still apply to every claim the agent makes on your behalf.

The upside is not only defensive. Agents with clear approved answers and clean escalation produce better conversations, fewer refunds and faster human handoffs. The AI customer support agent builds we ship are designed around that trade: the agent handles the routine, and the human handles the judgment.

Step 1: Approved content rules

The fastest way to keep an agent honest is to give it approved material and forbid invention. Write four lists:

  • Approved answers. The questions customers actually ask, with the answer your team has approved. Services offered, coverage areas, scheduling windows, warranty terms, cancellation policy, what happens in an emergency. These become the agent's source of truth, and the agent should be able to cite where an answer came from.
  • Forbidden claims. Anything the business cannot stand behind: guaranteed outcomes, comparative claims, invented timeframes, health or legal advice, promises about price that have not been approved. Give the agent language for saying "I do not want to guess, let me get someone who can confirm."
  • Pricing wording. Either quote approved ranges and rules, or have the agent capture details and route to a human. Whichever you choose, write the exact phrasing. Improvised pricing is the single most common source of angry escalations.
  • Disclosure rules. When the agent must identify itself as AI, and when it must record consent for follow-up. The transparency duties above make this a requirement in some jurisdictions and a trust builder everywhere.

Keep this document short enough that a new hire can read it in ten minutes. Version it, and require review before changes go live.

Step 2: Escalation paths

An escalation path has two halves: when to escalate, and where the conversation goes. Write both.

Typical triggers:

  • The customer asks for a human, directly or indirectly ("this is ridiculous," "I want to speak to someone").
  • Money changes: negotiation, discount requests, disputes, refunds.
  • Complaints, threats, legal language or regulator mentions.
  • Safety and clinical topics, or anything involving a vulnerable person.
  • The agent's confidence drops, or the answer is not in approved content.
  • Repeated misunderstanding: two failed attempts to resolve the same question.

A working escalation matrix looks like this, adjusted to your team size:

TriggerFirst actionDestination
Customer asks for a humanWarm transfer with transcript attachedOn-duty person or queue
Pricing negotiation or disputePause quoting, no promisesSales owner
Complaint or legal languageAcknowledge, escalate, logOperations lead
Safety or sensitive topicHand off immediately, flag priorityDuty manager
Two failed attempts on one questionSwitch to human, keep contextSupport queue

The destination matters as much as the trigger. A warm handoff passes the full transcript, the customer's details and a one-line summary to a named person or queue. A cold handoff drops a notification and makes the customer repeat everything, which is worse than no automation. Platform rules reinforce this: WhatsApp's business policy requires that automated replies inside the service window offer prompt, clear escalation options such as an in-chat transfer, phone or email. Set a working-hours destination, an after-hours destination and a fallback for when nobody is available, and test all three before launch.

Step 3: Logging and audit trails

If it is not recorded, it did not happen. For every conversation, store:

  • Timestamp, channel, and conversation identifier.
  • The full message history, including the agent's replies and any content it cited.
  • The agent version and the approved-content version in use at that moment.
  • Every decision the agent made: qualification outcome, booking, tag, stage change.
  • Every escalation: trigger, destination, time to human pickup, resolution.
  • Every opt-out or consent change, especially for messaging channels.

Retention is a policy decision, but pick a number and write it down, and restrict access to the transcript store the same way you restrict access to the CRM. People say sensitive things to businesses; a transcript archive with open access is a privacy incident waiting to happen.

The audit trail earns its keep three ways: it settles customer disputes with facts, it shows you exactly which agent answer caused a problem, and it is the raw material for the monthly review below. If your team uses an internal AI assistant to help manage this volume of data, give it read access to transcripts only through the same permissions model the team already has.

Step 4: Human-in-the-loop review

There are three moments where humans belong in the loop:

  • Before launch. A person approves approved content, escalation triggers and examples. Run a test set of awkward conversations: angry customers, trick questions, prompt injection attempts designed to pull the agent off script. OWASP's Top 10 for LLM applications lists prompt injection and excessive agency among the most serious risks, and both are testable before a customer ever sees them.
  • Before changes. Any update to pricing wording, policy answers or agent behavior gets a named approver. Unreviewed content changes are how agents drift.
  • Ongoing sampling. Review a fixed sample of real conversations monthly against a rubric. Look for invented claims, missed escalations, tone problems and repeated customer frustration. Score each conversation pass or fail on four lines: accurate, on-brand, escalated correctly, recorded correctly.

Step 5: The monthly QA routine

One hour, once a month, same agenda every time:

  1. Pull the sample: conversations across channels, including all escalations and any flagged conversations.
  2. Score each against the four-line rubric.
  3. List every factual claim the agent made and check it against approved content.
  4. List every escalation and check time to human pickup.
  5. Review opt-outs and consent records for the channel rules you operate under, including message categories and quiet hours.
  6. Check for prompt injection or unusual attempts in the log.
  7. Update approved content, then note what changed and who approved it.
  8. Write three sentences: what improved, what broke, what changes next month.

That is the entire habit. It takes less time than a single lost customer argument.

What to put in writing

Keep one document, one page, attached to the system itself. It should contain:

  • The agent's scope: which channels, which hours, which jobs it may perform.
  • Approved content rules and where the approved answers live.
  • Forbidden claims, pricing wording and disclosure requirements.
  • Escalation triggers, destinations and response expectations.
  • Logging rules: what is stored, where, for how long, and who can read it.
  • The review cadence, the rubric and the named owner.
  • The change process: who approves content updates and how versions are tracked.

Review it quarterly and after any incident. If you work with an agency or vendor, this document is also your contract annex; our about page explains how we run builds with the client owning these rules. For teams handling messaging channels, pair this with the channel-specific rules in our guides to WhatsApp automation and SMS compliance.

FAQ

Is AI agent governance legally required?

It depends on where you operate and what the agent does. In the EU, the AI Act imposes transparency duties, including informing people when they interact with a machine, and the rules became broadly applicable in August 2026. Even where no rule names your exact use case, industry regulators and consumer protection law still apply to claims your agent makes. Treat governance as risk management, not paperwork.

Who should own agent governance in a small company?

One named person, even if that is the founder. Governance fails when it belongs to everyone, because review meetings get skipped and content drifts. The owner approves content changes, reviews sample conversations monthly and keeps the written policy current. A second person should be able to run the review if the owner is away.

How many conversations should we review each month?

Pick a sample you will actually sustain, such as 20 to 30 conversations spread across channels, and review them against a one-page rubric. Consistency beats volume: a small sample reviewed every month finds more problems than a large audit that happens twice a year. Flag anything involving pricing, complaints or promises for a closer look.

What belongs in an escalation path?

A clear trigger list and a clear destination. Triggers typically include requests for a human, pricing negotiations, complaints, legal or safety topics, and anything the agent is unsure about. Escalation should hand a person the full transcript and context, not just a notification, so the customer never repeats themselves.

How do we protect against prompt injection and misuse?

Treat your agent like any other software system with access. OWASP's Top 10 for LLM applications ranks prompt injection and excessive agency among the top risks. Limit what the agent can read and change, require approvals for sensitive actions, log everything, and test attempts to talk it out of its rules before launch.

Frequently asked questions

Is AI agent governance legally required?
It depends on where you operate and what the agent does. In the EU, the AI Act imposes transparency duties, including informing people when they interact with a machine, and the rules became broadly applicable in August 2026. Even where no rule names your exact use case, industry regulators and consumer protection law still apply to claims your agent makes. Treat governance as risk management, not paperwork.
Who should own agent governance in a small company?
One named person, even if that is the founder. Governance fails when it belongs to everyone, because review meetings get skipped and content drifts. The owner approves content changes, reviews sample conversations monthly and keeps the written policy current. A second person should be able to run the review if the owner is away.
How many conversations should we review each month?
Pick a sample you will actually sustain, such as 20 to 30 conversations spread across channels, and review them against a one-page rubric. Consistency beats volume: a small sample reviewed every month finds more problems than a large audit that happens twice a year. Flag anything involving pricing, complaints or promises for a closer look.
What belongs in an escalation path?
A clear trigger list and a clear destination. Triggers typically include requests for a human, pricing negotiations, complaints, legal or safety topics, and anything the agent is unsure about. Escalation should hand a person the full transcript and context, not just a notification, so the customer never repeats themselves.
How do we protect against prompt injection and misuse?
Treat your agent like any other software system with access. OWASP's Top 10 for LLM applications ranks prompt injection and excessive agency among the top risks. Limit what the agent can read and change, require approvals for sensitive actions, log everything, and test attempts to talk it out of its rules before launch.
Keep reading

Related articles

Get Your AI Automation Plan