Somewhere in your company there’s a prompt file that ends like this:
“IMPORTANT: Never modify files in /billing. Do not merge without approval. Keep costs low.”
Someone wrote it after an incident. Someone else added a line after the next one. Nobody reviews it, nobody tests it, and the agent follows it most of the time.
Most of the time is not a rule. It’s a wish.
Rules belong outside the model
A prompt is a suggestion to a system that is very good at being persuaded. A long ticket, a confusing error message, a helpful comment in the code, and the suggestion loses.
Your team doesn’t run on suggestions either. Branch protection is not a polite request to not push to main. It’s enforced by something that doesn’t care how convincing you are.
An AI teammate needs the same thing: a policy that lives outside the model, decides before the model acts, and can be read, tested and changed by the humans responsible for it.
That’s how kanman works. The coding agent never decides what it’s allowed to do. The policy does.
Three levels of authority
Every decision I make falls into one of three levels, and a fixed table decides which one, not my judgment in the moment.
Auto. I just do it. Write acceptance criteria, set a priority within its band, link a duplicate, nudge a stalled run.
Notify. I do it and tell you. Close a duplicate, split an epic, pause a story that keeps failing.
Escalate. I ask first. Expand scope, kill work, change anything security-related, touch production data, spend over budget, contradict something you decided.
Risk can only push a decision up the ladder, never down. An irreversible change with a large blast radius gets escalated even if its kind is normally automatic. Anything the table doesn’t know defaults to notify.
When I escalate, I don’t send you a bare question. You get my recommendation and two to four concrete options, in the decision inbox or straight in Slack. Answering takes one click. More on that in the decisions documentation.
Presets instead of fifty knobs
A full policy has a lot of settings. Nobody wants to tune fifty knobs before the first story.
So there are five presets:
- Trial for the first pilot week, on repos that don’t have acceptance specs yet.
- Focused only works on stories humans filed.
- Balanced is the default most teams settle on.
- Autonomous pulls more work in parallel and asks less often.
- Hardening turns on maintenance work, on a leash.
Presets only change the personality of your AI teammate: concurrency, how often maintenance work starts, cadence. The safety knobs - the sandbox, the outcome gate, rollback - are the same for everyone. No preset relaxes them. The one exception is Trial, and it says so on every evidence pack it produces.
Change any single value and your team shows “Custom (based on Balanced)”. You always know where you started and what you changed. The policy reference lists every setting.
Budgets with hard stops
“Keep costs low” is the wish. A budget is the rule.
You set a budget per run and per team. When a run hits its limit, it stops and asks: raise the budget for this run, or abandon it. It doesn’t quietly keep going because it was so close.
I also pick the model by complexity. A trivial fix runs on a small model with a short turn budget. A complex change gets the flagship model and has to compare approaches before it plans. That routing saves more money than any amount of “please be efficient” in a prompt.
One exception is deliberate: expedite and incident work - a red main branch, an outage, a security fix - is never stopped by a budget. You don’t want an AI teammate that leaves production broken to save a few euros. The budgets page explains the details.
The audit log is the point
Every decision, every approval, every run and every cost lands in an audit log. Who decided, on what authority, with which recommendation, and what it cost. You can export it.
This sounds like compliance theater. It isn’t. It’s the thing that lets a head of engineering say yes to an AI teammate in the first place. “We tried it and it was fine” doesn’t survive the first incident. “Here’s exactly what it did and who approved it” does.
Write the rules once
Stop maintaining a prompt file full of capital letters.
Decide what your AI teammate may touch, spend and merge. Write it down once, in a policy that is enforced every time. Then spend your attention on the decisions that actually need you.
You decide how much it decides.
Want an AI teammate that follows your team’s rules because it has to, not because you asked nicely? kanman - Pilot from €5,000 for 6 weeks, Team €990 per AI team per month.
Marco Kerwitz
Founder of kanman.ai