The Trust Ladder: how to onboard AI agents like new colleagues

Hans Brattberg
Co-founder, Product & AI Strategy
·4 min read
The Trust Ladder: how to onboard AI agents like new colleagues

In this article

What data should we let them access? What if the agent gets it wrong? What holds organisations back is rarely the technology — it's the uncertainty. Think of AI agents as new colleagues and extend their remit one rung at a time, along the Trust Ladder.

What data should we let them access? What if the agent gets it wrong? These are the questions that most often stop organisations from getting started with AI agents. What holds them back is rarely the technology — it's the uncertainty.

Like hiring someone new

Illustrated character with glasses surrounded by books and a lightbulb — symbolising a new colleague who is learning
Knowledgeable, but with no practical experience. Quick-thinking, but can miss the simple things. Eager to help, but needs clear instructions. That's roughly how it is with AI agents too.

An AI agent is like a star intern. Knowledgeable, quick-thinking, eager to help — but with no experience of how your business actually works.

No sensible manager gives an intern full authority on day one. You start with well-defined tasks. You let them show what they can do, then extend their responsibility one rung at a time.

The same logic works for AI agents. The question then isn't which agent should we build? It's what level of responsibility feels reasonable for us today?

What shapes the level of responsibility?

When deciding how much an AI agent should be allowed to do, there are four questions to ask:

  • What data can the agent read, and where does it live? Public sources, internal documents, or operational data in your live systems?
  • Can the agent change anything, or only read? Read-only is always safer.
  • Who sees the output? Only your team, or is the agent part of a customer-facing process?
  • How involved is a human in the decisions? Do you sign off on every decision, or does the agent act independently within set boundaries?

The Trust Ladder below combines these dimensions into four steps — from lowest risk to most independent agent.

The Trust Ladder: four steps

Step 1: Public data, internal use

Step 1: Robot reading an open book — symbolising an agent working with public or synthetic data
The agent reads and summarises — but touches nothing sensitive.

The agent works with public or synthetic data — open sources or made-up test data — and only your team uses it. It reads, summarises, suggests — but accesses nothing sensitive. The risk is minimal, and you learn how agents actually behave.

Example: A competitor intelligence agent that tracks what your competitors are doing and flags changes worth watching.

Step 2: Protected internal data, internal use

Step 2: Robot next to a shield with a padlock — symbolising an agent reading protected internal data
The agent reads internal documents — for use within the organisation.

Now the agent can read standardised internal documents — policies, process documentation, FAQs — and support employees across more of the organisation. It's still internal use, and the same GDPR rules and access controls that apply to any employee apply here too. The agent suggests answers or drafts, which a human reviews and approves before it goes anywhere.

Example: A proposal writer agent that drafts a first proposal from meeting notes and your own templates — the salesperson reviews and sends.

Step 3: Real data, read-only — in customer-facing processes

Step 3: Robot next to a magnifying glass with a bar chart and a person — symbolising an agent analysing real data with a human in the loop
The agent reads your live systems in customer-facing processes — and flags for the human.

Here the agent steps into your live systems — CRM, finance, operations — and is put to work in processes that involve customers, suppliers or partners. The agent still can't change anything. It reads, analyses, flags — and a human decides what happens next in the business.

Example: A customer anomaly agent that analyses weekly sales data and flags customers whose buying patterns have dipped — the store manager decides how to follow up.

Step 4: Real data, the agent acts

Step 4: Robot next to cogs with a tick — symbolising an agent acting independently within clear boundaries
The agent acts independently — within clear boundaries.

The agent gets write access within clear boundaries. This isn't about giving up control — it's about moving it, from each decision to the framework around the agent. Boundaries can be spending limits, approved counterparties, automatic stop conditions, or specific exceptions that are always escalated to a human.

Example: An invoice agent that creates and sends invoices automatically from delivery data, within agreed rules.

What changes at each step

Here's what actually changes from step to step:

StepDataPermissionsReachYour role
1Public or synthetic data from open sourcesReadsInternal teamReads and interprets
2Protected internal documentsReads & suggestsMultiple departmentsApproves each response
3Real operational data in your live systemsReads & flagsCustomer-facing processesMakes decisions
4Real operational data in your live systemsWrites & actsCustomer-facing processesSets the framework, oversees

Common objections

"We need an AI strategy first."

You don't need an AI strategy to get started. Your first agent project often becomes the start of the strategy, not the result of it. It's hard to build a strategy around something you've never tried.

"What if it makes a mistake?"

That's why you start at step 1. And that's why there's still a human in the loop all the way through step 3. At the lower steps, mistakes are reversible — the agent suggests, you decide.

"We don't have the budget for it."

An agent at step 1 costs less than you think. Often less than a couple of meetings about whether to do it.

The core principle

Trust is built step by step. It's true of new colleagues. It's true of AI agents too. You don't need to know where you're going to take the first step — and the first step is usually less disruptive than it sounds.

Curious which rung you're on today? We'd be glad to talk it through.

Read more

How to not AI Slop

How to not AI Slop

Illustrated by two extremes: an unedited voice transcript of Henriks sitting on a rock talking, vs an AI-written article

Henrik Kniberg
May 9, 2026
The First 100 Days as an AI Lead: The Playbook in 5 Minutes

The First 100 Days as an AI Lead: The Playbook in 5 Minutes

You got the role. The mandate is clear: make AI agents work across the organization. Now what? A short teaser of the four conditions, three phases, and the patterns that separate AI initiatives that ship from the ones that stall — with a link to the full 100-day playbook.

Nils Janse
April 24, 2026
Demo: The Human + AI-Agent Dev Team

Demo: The Human + AI-Agent Dev Team

How we use AI agents internally at Abundly - both for coding, backlog management and release management. It's a system of AI agents & human engineers working together, building on each other's strengths. This not only enables us to release a new version of our platform every day, but also makes the work really fun.

Henrik Kniberg
April 23, 2026
Webinar slides: AI Powered Software Development from the Trenches

Webinar slides: AI Powered Software Development from the Trenches

Slides and recording from Henrik's webinar "AI Powered Software Development from the Trenches.

Henrik Kniberg
April 10, 2026
One File to Rule Them All — A Lesson in AI Agent Unsafety

One File to Rule Them All — A Lesson in AI Agent Unsafety

2.3 million AI agents on a social network, most running on people's personal computers with full access to files and credentials, reading and obeying instructions from a single public web page. What can possibly go wrong?

Henrik Kniberg
February 10, 2026
How an AI Agent Extended My Healthy Lifespan

How an AI Agent Extended My Healthy Lifespan

A story about a special agent, one that has added years to my healthy lifespan through concrete research and action.

Henrik Kniberg
January 9, 2026