All posts in the series

Post 1 of 8

How to take the right first steps toward AI agents

Where to start if you want an agent rather than another chat: pick a task with a verifiable result, start with the simplest solution, give the agent a way to check itself, and only then widen its autonomy.

Alexander Mihalkevich · Fact-checked October 5, 2026 · 4 min read

The right steps toward AI agents
1. Start with the task, not the tool
The simplest thing first: One model call → Workflow → Agent
2. Give the agent a way to check itself
3. Start read-only
Autonomy is a setting: Plan, read-only → Approve every action → File edits without asking → Everything, with background checks → No limits
4. Measure on real tasks
You're ready for a first agent if: You have a task with a verifiable result; Tests or the build run with one command; The agent works on a separate branch; Permissions are minimal; There's a task set to compare against
Next: the first setup
Slide 1 of 9

There is a lot of noise around AI agents. Yet teams whose agents actually work usually started in a boring way: with one narrow task and a check the agent can run on its own. Below is an order of decisions that saves weeks. It is based on Anthropic's guides on building agents and on the Claude Code documentation.

Agent or workflow

In Building effective agents, Anthropic distinguishes two types of systems:

  • Workflow: the model and tools follow steps predefined in code. Example: email → classification → draft reply → review.
  • Agent: the model decides which steps to take and which tools to use, and tracks how the task is progressing on its own.

The main advice of the same article: look for the simplest solution and add complexity only when it is really needed. Many tasks are served by a single well-built request with the right context and examples. An agent is justified when the steps are not known in advance: “find out why the build is failing and fix it.”

Step 1. Pick a task with a verifiable result

A good first task:

  • repeats: the time invested in setup will pay back;
  • is machine-checkable: tests, build, linter, comparison against a reference;
  • is bounded: it touches a clear piece of code, not “improve the architecture.”

Examples: fix a failing test from the CI log, update a dependency and run the tests, triage new bugs and propose a fix with a test.

Step 2. Give the agent a way to check itself

In the Claude Code best practices this is the first item: the agent stops when the work looks done. If it has no check it can run, you remain the only control. If there is a check, the loop closes: the agent does the work, runs the check, reads the result, fixes.

State the criterion in the task itself:

Write a validateEmail function. Examples: user@example.com is true,
invalid is false, user@.com is false. After implementing it, run the tests
and show the output.

Ask for evidence, not claims: test output, the command and its result, a screenshot. Checking evidence is faster than re-checking everything yourself.

Step 3. Restrict permissions from the start

The agent's autonomy is configurable. Claude Code has permission modes:

Mode What the agent does without asking
plan Only reads and proposes a plan
default (Manual) Read-only; everything else needs confirmation
acceptEdits Reads, edits files, runs simple filesystem commands
auto Everything, but a separate classifier model checks the actions
dontAsk Only pre-approved tools; everything else is denied
bypassPermissions Everything; only for isolated containers and VMs

You switch modes with Shift+Tab. For your first tasks in an unfamiliar project, start in plan mode:

claude --permission-mode plan

Allow/deny rules work on top of the modes. A deny rule applies in any mode, even in bypassPermissions. Rules are covered in detail in the next post.

Step 4. Measure instead of trusting your impressions

When you change the prompt or the model, or connect a new tool, you need to know whether things got better. In Demystifying evals for AI agents, Anthropic recommends starting with 20–50 simple tasks taken from real failures. A good task is one on which two specialists would independently reach the same pass/fail verdict.

Keep two separate sets:

  • regression: what the agent can already do; here you expect close to 100%;
  • capability: what it cannot do yet; a low pass rate is normal here.

Step 5. Increase autonomy gradually

Once the agent consistently passes the task set in a mode with confirmations, expand its permissions: pre-approve safe commands, enable automatic file edits, let it work in the background. Each step demands less of your attention but more trust in your checks.

What to avoid

  • Starting with a framework. Anthropic recommends working with the model API directly first: frameworks hide prompts and responses, which makes debugging harder.
  • Giving the agent everything at once. Extra tools and broad permissions are both noise in the context and a risk. OWASP lists excessive agency as a separate category of LLM application vulnerabilities.
  • Checking “by eye.” Plausible code without tests is the most common trap. If you can't verify it, don't ship it to production.

What's next

The second post covers the first setup step by step: installing Claude Code, Codex or Cursor, the instructions file, permissions and the first task.

Terms in this post

Practise it in

Sources

  1. Anthropic — Building effective agents
  2. Claude Code — Best practices
  3. Claude Code — Choose a permission mode
  4. Anthropic — Demystifying evals for AI agents
  5. OWASP — LLM06:2025 Excessive Agency
ShareTelegramXLinkedIn

Practise this for real

In the school's simulators an agent does the task, and you learn to set it, check it and never trust it blindly.

Open simulators