Cresec

Draft first: a safer way to let AI act on your behalf

By the Cresec team ·

Most of the value of an AI helper comes from the work it does before anything is sent: reading, sorting, summarising, writing a first version. The risky part is the last click — sending the email, updating the record, posting the message.

A "draft first" approach keeps the value and holds back the risk.

How draft first works

  1. Everyone starts with drafts. When someone new starts using a tool, it can read and prepare, but it can't send or change anything.
  2. People check the drafts. The person reviews what the tool wrote and sends it themselves. They learn quickly where the tool is good and where it needs help.
  3. Sending is granted, not assumed. Once someone trusts the tool for a task, a manager or admin allows sending — for that person, for that tool.
  4. It can be taken back. If something goes wrong, sending is switched off for that person without affecting anyone else.

Why it helps everyone

For the person using the tool, nothing goes out in their name that they haven't seen.

For the person who built it, teammates can start using it right away, without waiting for a big approval.

For IT and security, the default is safe, and every step beyond it is a decision someone made and recorded.

What if the service is down?

A good setup falls back to the safe side: if the service that checks permissions can't be reached, the tool can still read and draft, but it doesn't send. Work slows down a little instead of stopping — and nothing happens without a record.