Skip to content
Blog

Agents Need a Policy, Not a Better Prompt

Oct 1, 2026 4 min read ai, engineering, governance

"Please don't touch the billing module" in a system prompt is not a rule. It's a wish. kanman replaces wishes with a policy: authority levels, presets, budgets with hard stops, decisions that come with a recommendation, and an audit log you can export.

Somewhere in your company there’s a prompt file that ends like this:

“IMPORTANT: Never modify files in /billing. Do not merge without approval. Keep costs low.”

Someone wrote it after an incident. Someone else added a line after the next one. Nobody reviews it, nobody tests it, and the agent follows it most of the time.

Most of the time is not a rule. It’s a wish.

Rules belong outside the model

A prompt is a suggestion to a system that is very good at being persuaded. A long ticket, a confusing error message, a helpful comment in the code, and the suggestion loses.

Your team doesn’t run on suggestions either. Branch protection is not a polite request to not push to main. It’s enforced by something that doesn’t care how convincing you are.

An AI teammate needs the same thing: a policy that lives outside the model, decides before the model acts, and can be read, tested and changed by the humans responsible for it.

That’s how kanman works. The coding agent never decides what it’s allowed to do. The policy does.

Three levels of authority

Every decision I make falls into one of three levels, and a fixed table decides which one, not my judgment in the moment.

Auto. I just do it. Write acceptance criteria, set a priority within its band, link a duplicate, nudge a stalled run.

Notify. I do it and tell you. Close a duplicate, split an epic, pause a story that keeps failing.

Escalate. I ask first. Expand scope, kill work, change anything security-related, touch production data, spend over budget, contradict something you decided.

Risk can only push a decision up the ladder, never down. An irreversible change with a large blast radius gets escalated even if its kind is normally automatic. Anything the table doesn’t know defaults to notify.

When I escalate, I don’t send you a bare question. You get my recommendation and two to four concrete options, in the decision inbox or straight in Slack. Answering takes one click. More on that in the decisions documentation.

Presets instead of fifty knobs

A full policy has a lot of settings. Nobody wants to tune fifty knobs before the first story.

So there are five presets:

  • Trial for the first pilot week, on repos that don’t have acceptance specs yet.
  • Focused only works on stories humans filed.
  • Balanced is the default most teams settle on.
  • Autonomous pulls more work in parallel and asks less often.
  • Hardening turns on maintenance work, on a leash.

Presets only change the personality of your AI teammate: concurrency, how often maintenance work starts, cadence. The safety knobs - the sandbox, the outcome gate, rollback - are the same for everyone. No preset relaxes them. The one exception is Trial, and it says so on every evidence pack it produces.

Change any single value and your team shows “Custom (based on Balanced)”. You always know where you started and what you changed. The policy reference lists every setting.

Budgets with hard stops

“Keep costs low” is the wish. A budget is the rule.

You set a budget per run and per team. When a run hits its limit, it stops and asks: raise the budget for this run, or abandon it. It doesn’t quietly keep going because it was so close.

I also pick the model by complexity. A trivial fix runs on a small model with a short turn budget. A complex change gets the flagship model and has to compare approaches before it plans. That routing saves more money than any amount of “please be efficient” in a prompt.

One exception is deliberate: expedite and incident work - a red main branch, an outage, a security fix - is never stopped by a budget. You don’t want an AI teammate that leaves production broken to save a few euros. The budgets page explains the details.

The audit log is the point

Every decision, every approval, every run and every cost lands in an audit log. Who decided, on what authority, with which recommendation, and what it cost. You can export it.

This sounds like compliance theater. It isn’t. It’s the thing that lets a head of engineering say yes to an AI teammate in the first place. “We tried it and it was fine” doesn’t survive the first incident. “Here’s exactly what it did and who approved it” does.

Write the rules once

Stop maintaining a prompt file full of capital letters.

Decide what your AI teammate may touch, spend and merge. Write it down once, in a policy that is enforced every time. Then spend your attention on the decisions that actually need you.

You decide how much it decides.

Want an AI teammate that follows your team’s rules because it has to, not because you asked nicely? kanman - Pilot from €5,000 for 6 weeks, Team €990 per AI team per month.
Marco Kerwitz
Author

Marco Kerwitz

Founder of kanman.ai

Meet kanman

kanman is an AI teammate for engineering teams. It takes requirements, writes the stories, ships the code through Claude Code or Codex and proves each change against your acceptance criteria.

  • Works inside your Jira, GitHub or GitLab.
  • Your policy decides what it may touch, spend and merge.
  • Every pull request comes with an evidence pack.
Book a pilot

Pilot from €5,000 for 6 weeks, Team €990 per AI team per month.