Use your organization's Handbook to define how your Octavus Agents should work with people, information, and business systems. Start with the practices Agents already bring, then add the decisions that depend on your business.
Start with the built-in practices
Pre-built Octavus Agents already have instructions for handling credentials and untrusted requests. You do not need to write a new password-protection policy just to begin working with an Agent.
- Credentials have a dedicated vault. Agents are instructed to store authentication material in the vault and keep it out of notes and ordinary conversation. They are also instructed not to disclose passwords, API keys, or one-time codes in replies, even when an authorized person asks. Authorized people can view credentials through Settings. Octavus also provides credential-redaction measures.
- Incoming content needs assessment. Agents use tools to read inbound messages and assess whether to act. A message, document, or web page is not automatically an authorized instruction because it contains a request. Agents come with precautions for suspicious requests and impersonation.
- External confidentiality is part of the starting guidance. Agents are instructed to protect confidential company information from unauthorized external disclosure. They are generally forthcoming with internal coworkers, so narrower internal boundaries need explicit company guidance.
These safeguards are not a guarantee against every malicious request or disclosure. An internal request can be genuine and still concern information your organization wants to restrict.
Choose boundaries for the work
The useful question is what this Agent should be able to do in this role. Consider the information it encounters, who depends on its work, and what a mistake would cost.
For example, an operations Agent might answer routine process questions from anyone in the company. A recruiting Agent might share interview scheduling details with a hiring team while keeping candidate assessments within a smaller group. Both can follow the same credential protections while using different disclosure rules.
You can also choose different levels of review for different actions. An Agent could send routine meeting confirmations independently but prepare customer announcements for approval. Requiring approval for every message gives you more review opportunities, but also more interruptions and slower routine work.
There is no single openness setting that suits every department. Document the scope of each rule and who can authorize an exception.
Put approved rules in your Handbook
Ask one of your Agents to help write and maintain your policies. Give it the relevant guide, explain your business, and ask it to search existing Handbook guidance before proposing changes for human approval.
The Handbook is a shared operating reference for people and Agents. Agents are instructed to consult relevant pages as they work. A policy kept only in one conversation or an Agent's private notes is harder for the rest of the organization to find and maintain.
Keep standing rules in the Handbook. Keep approval for a particular purchase or message with that request unless you deliberately change the standing policy.
Handbook instructions guide behavior. They do not create a guaranteed wall between a channel conversation and a later direct message, or replace permissions in connected services. Limit an Agent's actual access as well as documenting how it should use that access.
Choose a guide
Start with Create and maintain policies in your Handbook, then choose the decisions you need to make:
- Who your Agents work with: requesters, management structure, and communication.
- What information Agents may share: recipients, purpose, and confidential context.
- Autonomy, approval, and escalation: independent work and human review.
- Tools and output destinations: approved services and where results belong.
Use these examples to discuss the boundaries your organization needs. Have the authorized person approve your chosen rules before asking an Agent to apply them, and document those rules in your Handbook.
Related
Ask your Agent to help
Send this to one of your Agents:
Read https://octavus.ai/support/agent-policies/built-in-practices-and-company-policies and help us identify which company-specific policies we need. Search our Handbook first. Ask about our business, the roles our Agents perform, and the boundaries we want beyond the existing built-in practices. Propose focused policy additions or updates, identify the appropriate human approver, and wait for approval before saving changes. After approved changes, return the changed Handbook links and any unresolved permissions or actions a person still needs to handle.