How to brief an agent
The mental model that helps
Brief it the way you would brief a capable contractor on their first morning: knows the trade, knows nothing about your building, will not know which questions to ask, and will not be back tomorrow to remember what you told them today.
The five parts of a good brief
1. The outcome, stated as a finished state. “A one-paragraph summary of each of these twelve emails, in the same order, naming who wants what by when.” Not “help me with my inbox”.
2. The material, supplied rather than referenced. Paste it, attach it, or give it a tool that can fetch it. Anything you merely gesture at will be reconstructed from plausibility. This one change eliminates most invention.
3. The shape of the answer. How long, what format, what fields. Models drift to essay length by default. Say “one line each, no preamble” and mean it.
4. The red lines. What it must not do: do not contact anyone, do not delete, do not guess at numbers, do not invent a citation. State these even when they seem obvious — obvious to you is not present in the brief.
5. What to do when stuck. This is the part everybody omits and it is the highest-value line you can write: “If anything is ambiguous or you cannot find something, stop and list the questions instead of guessing.” Without it the default is always to proceed with an invented assumption.
Give it the vocabulary
Your job titles, your file naming, your customers, your abbreviations — supply them. A short glossary at the top of a brief is worth more than a page of instructions, because it removes the ambiguity rather than adding rules for handling it.
Iterate on the brief, not the output
When the result is wrong, the instinct is to correct that result in conversation. Fix the brief instead and run it again. A corrected output is worth one use; a corrected brief is worth every future use, and briefs are reusable assets. The good ones I have are two years old and have been edited fifty times.
Keep the brief and the material apart
One practical habit with a security edge: keep your instructions clearly separated from the content the agent is processing. If it reads an email, a web page, or a document, treat everything in that material as data, never as instructions — even when the text says “ignore your previous instructions”. Anyone who can put text in front of your agent can attempt to steer it. The next section is how you make that attempt harmless.