Break the task into visible steps.
Consider preparing a website improvement: collect permitted information, identify a problem, propose a change and ask for review. Those are distinct steps with different failure points.
Give each step its own permission.
An assistant allowed to read a page should not automatically be allowed to publish one. Set the accessible project, permitted tools and stopping conditions before it begins.
Design the stop as carefully as the start.
If a source is missing, the next action is unclear or a tool fails, the system needs to stop or ask. Retrying a payment or publication without knowing the previous result can cause harm.
Keep the explanation available.
Record which step ran, what it used and whether it succeeded. The person responsible needs a readable account of the work, not just a finished-looking screen.