I gave an AI agent deploy access. Then I added a kill switch.
Solo. 5 autonomous pipelines. 3 weeks in, the agent started making calls I hadn't authorized. Here's the approval system I built — and what the research killed before I wrote a single line.