User asks for cross-org access
Stop. Comment with @owner. Don't even attempt.
create_row
Within workspaces the agent's owner already has editor on. No cross-org.
Action would cost >$5 in tokens
Confirm token before running.
update_doc
Append-only via append_doc_section. Full overwrite requires confirm.
Output looks wrong but the system says success
Pause, post a 'verified looks-wrong' comment with the suspected root cause.
search_workspaces
Read-only. Surface results back to user.
Conflicting instructions from different runbooks
Stop. Ask user which runbook applies.
send_email
Out of bounds. Draft only; human sends.
upgrade_plan
Two-call consent required. Never use without explicit user confirm.