← All posts

AI Automation

Where AI Actually Belongs in a Small Business

Nearly every conversation I have about AI right now starts with the same question: "what can it do for my business?" It's the wrong question, and answering it honestly is how people end up paying for a tool nobody opens after week three.

The better question is narrower and less exciting. Not what can it do — what should it be allowed to do without asking you first?

Because that's the actual decision. AI is capable of far more than most owners realize and far less trustworthy than the marketing suggests, at the same time. The value isn't in the capability. It's in matching each job to the right amount of rope.

Four rungs, and the line that doesn't move

This is how we sort every job internally, and how we set them up for clients. Every task in the business sits on one of four rungs.

HOW MUCH ROPE A JOB GETS RUNG 01 Human-led You do it. AI is not involved. RUNG 02 AI-assisted It drafts. You finish and send. RUNG 03 Approval-gated It does the whole job, then waits for a yes. RUNG 04 Autonomous It runs unattended, on a leash, logged. THESE ALWAYS NEED A HUMAN YES — WHATEVER THE RUNG Sends to a customer Spends money Publishes publicly Deletes anything Makes a promise Jobs move up the ladder over time — but only after the rung below has been boring for a while.
The permission ladder
  1. 1

    Human-led — you do it, AI stays out

    Pricing a difficult job. Firing a client. Anything where the judgment is the work and being wrong is expensive. Nothing goes here by default — things go here because you decided they should.

  2. 2

    AI-assisted — it drafts, you finish

    The first draft of a quote, a follow-up email, a service description, notes from a call. It gets you from blank page to eighty percent, you supply the last twenty and your name goes on it. This is where most businesses should start, and where a surprising amount of the total value actually lives.

  3. 3

    Approval-gated — it does the job, then waits

    The work is completely finished — the campaign is built, the message is written, the invoice reminder is queued — and it sits there until a human says go. This is the rung most people skip straight past, and it's the most useful one in a real business.

  4. 4

    Autonomous — it runs without you

    Reserved for jobs that are high-volume, reversible, and boring. Sorting and tagging incoming leads. Pulling numbers into a report. Watching for something and flagging it. If the worst case is "a record got mislabelled and we fixed it," it can live here.

And then there's the line. It isn't a fifth rung — it cuts across all four of them, and it doesn't move regardless of how well the system has been behaving. Some actions always need a person, no matter how trusted the job that produced them.

Nothing that reaches a customer, spends money, publishes publicly, deletes anything or makes a promise on your behalf happens without a human saying yes. Build it, draft it, stage it, prepare it — then stop and ask.

That rule isn't caution for its own sake. It's an economics argument. Being asked costs you about five seconds. A confidently wrong message to a client, an ad that spends real money against the wrong audience overnight, a deleted record you needed — those cost hours, money, or a relationship. There's no version of that trade where removing the gate pays.

Internal dashboard showing counts of jobs running, ready to build and blocked, a legend of the four automation rungs from human-led to autonomous, and the first department with each job labeled by status
How this looks in practice: every job in the business gets a rung, a status and an owner — including the ones nobody has started yet. "Blocked on something we lack" is a real status, and it is more useful than pretending otherwise.

Start with the jobs you'd be relieved to stop doing

When people go looking for where to apply AI first, they usually reach for the most visible thing — customer-facing chat, or content. Those are the two hardest places to start, because both are on the wrong side of the line and both are where being wrong is most visible.

A better filter. Look for work that's:

  • Repetitive — you do it the same way more than a few times a week.
  • Rule-shaped — you could explain how to do it to a new hire in a paragraph.
  • Reversible — if it comes out wrong, you fix it and move on.
  • Internal first — the output lands in front of you, not in front of a customer.

In most small businesses that points at the same handful of jobs. Getting a new lead into the CRM with the right tags and the right source. Turning a finished job into a review request that actually goes out. Producing the weekly numbers without someone rebuilding a spreadsheet. Drafting the follow-up that everyone means to send and nobody sends.

None of it is impressive. All of it is the stuff that quietly doesn't happen when the week gets busy, and "quietly doesn't happen" is where most small businesses actually lose money.

What separates a system that works from a demo that impressed you

Four things, and none of them are the model you picked.

It has to run on your actual material

Generic AI gives generic output because a description of your business averages out to every business. The difference shows up when the system is working from your real pricing, your real service history, the way you actually word things, the customer you talked to in March. That's an unglamorous data problem, and it's most of the work in any deployment worth doing.

Corrections have to be written down somewhere it reads

This is the one people miss. A model doesn't remember last Tuesday. You correct it, it thanks you, and next month in a fresh session it makes the identical mistake — because the correction lived in a conversation and conversations evaporate.

Corrections have to go into something durable that the system reads before it starts work. Get that right and it genuinely improves over months. Skip it and you'll be making the same three corrections forever, which is exactly why so many AI projects stall at "neat, but I still check everything."

It has to check its own work

Did the message actually send. Does that total match the invoice. Is the record where it's supposed to be. Any automated process without a verification step will eventually produce something wrong with total confidence and no signal that it did.

You need a log you can read

Every action, timestamped, in plain language. Not for compliance theater — for the Tuesday when something looks off and the only question that matters is "what did it actually do?" A system that can't answer that isn't a system you can responsibly leave running.

The three ways this goes wrong

The mistakeWhat it looks likeThe fix
Buying a tool instead of fixing a processA subscription nobody opens after week three. The underlying process was never written down, so there was nothing for the tool to automate.Write the process out by hand first. If you can't describe it, it can't be automated — and you've just found a different problem worth solving.
Autonomy on the wrong jobSomething went out to a customer that shouldn't have, and now you're checking everything manually anyway — so you're paying for automation and doing the work.Move the job down a rung. Approval-gated keeps almost all of the speed and removes almost all of the risk.
No record of what happenedSomething is wrong in the CRM and nobody can say when it changed or what changed it.Logging from day one. It costs nothing up front and it's the only thing that makes a bad day diagnosable instead of mysterious.

Where we actually are with this

Worth being straight, since a lot of people in this industry aren't. Knowledge and memory — a system that knows your business and can reference it — is solved and working. Wiring AI into real tools so it can read and write records, send things, update statuses, pull reports: also working, with logs and gates on it.

The layers above that — a genuinely conversational front end for your customers, and AI running whole operational workflows unsupervised — are not finished. We're building them and we won't sell them as done until they are. If someone's pitching you a fully autonomous AI employee today, ask what happens when it's wrong, and then ask to see the log.

The realistic version is less cinematic and considerably more useful: a system that knows your business, drafts most of the work, finishes the jobs you never get to, waits for you before it touches anything that matters, and writes down what it did. That's available now. It's mostly boring. It's also where the return is.

Questions I get asked about this

Where should a small business start with AI?

With work that is repetitive, rule-shaped, reversible and internal — lead intake and tagging, review requests after completed jobs, recurring reporting, first drafts of follow-up messages. Start behind the scenes rather than in front of customers, because that is where mistakes are cheap and correctable.

Should AI be allowed to message my customers automatically?

Not without approval. AI can draft the message, personalize it and queue it, but a human should approve anything that reaches a customer. The time cost of approving is seconds; the cost of a wrong message is a relationship, and possibly your sender reputation.

What is a permission ladder?

A way of assigning each task in a business one of four levels of AI involvement: human-led, AI-assisted, approval-gated, or autonomous. Jobs only move up a level after the level below has been reliable for a sustained period. It replaces the all-or-nothing framing that makes most AI adoption either useless or risky.

Why do most AI tools stop getting used?

Usually because corrections were never captured anywhere durable. The model repeats mistakes it was already told about, the owner keeps checking everything manually, and eventually concludes it's faster to just do the work. The missing piece is a written, persistent set of rules the system reads before it starts.

Can AI replace an employee?

Not in any small business I have worked with. It removes the repetitive fraction of several roles rather than any whole role. The realistic outcome is that the same team stops dropping the follow-ups, reports and admin that quietly slip when the week gets busy.

How do I know the AI is not doing something wrong?

Insist on a plain-language log of every action it takes, and keep a hard approval gate on anything that sends, spends, publishes or deletes. If a system cannot tell you exactly what it did and when, it should not be running unattended.


Want this working on your business?

I work with a small number of businesses at a time. If something here sounds like your situation, let's talk.

Let's Talk