1. Map the process and mark the judgement calls. We list each step and sort it: routine, needs a rule, or needs a person. That map is the design.
2. Put the rules in code, not the prompt. Prices, limits, thresholds and allow-lists live in tested functions and the database. The model reasons; code enforces.
3. Validate everything that crosses a boundary. Model outputs are checked against a schema before anything acts on them. Unknown citations are rejected. Missing information pauses the flow.
4. Build the approval screen properly. The person approving sees what the agent saw, what it proposes and why, and can approve, reject or edit, with the decision recorded.
5. Deploy and hand over. Keys stay server-side, health checks never expose credentials, and you get a runbook covering the model, the tools and how to switch the agent off.