MODULE 8 / 14🔊0:00SAFETY  50
A glowing set of keys hovering over a laptop running an AI agent console, dark blue glow
AI Safety 101 by Mandrify

The Agent

Air Canada's chatbot invented a refund policy. The airline argued the bot was 'a separate legal entity.' The tribunal disagreed - and Air Canada paid $812 for its bot's words.

20 minutes. Three delegation dilemmas, a permission audit, and 12 autonomy calls. A safety score that follows you.

Before you start

  • One real incident, played as decisions - no slides, no lectures.
  • About 20 minutes, one sitting - leave early and you start over.
  • You make timed choices; your score changes with your decisions.
  • You get a safety score with feedback on every decision - never a leaderboard, never your name.
  • Your firm sees completion evidence - never your answers. Teammates never see your score.
  • Finish and you get a certificate with a unique ID anyone can verify.

This module is included with team access.

Module 1 stays free. Modules 2-14 open with team access.

See team access
The real incident - Moffatt v. Air Canada, 2024

The bot invented a policy. The company owned it.

$0
Refund Air Canada paid for its chatbot's invented policy
0st
Tribunal ruling holding a company liable for its AI's words

Jake Moffatt asked Air Canada's chatbot about bereavement fares. The bot confidently described a retroactive discount that didn't exist. When the airline refused to honor it, Moffatt sued - and won.

Air Canada's defense was remarkable: the chatbot was 'a separate legal entity responsible for its own actions.' The tribunal's answer is the law of the road now: your AI's promises are your promises.

Now give that same AI real permissions - send, spend, delete - and every mistake happens at machine speed, with your name on it. Permissions are the product.

Sources: CBC, BBC (Feb 2024); BC Civil Resolution Tribunal, Moffatt v. Air Canada - see Case Library.
Dramatized scenario

Tuesday. Your AI agent gets its first keys to the building.

You are Sam, ops lead. The new agent can triage support email, update the CRM, and handle refunds - if you let it.

YOUR SCREEN

Three calls before lunch: how much mailbox to give it, whether refunds fly solo, and whether it may email customers as you.

Scenario 1

The agent asks for full mailbox access 'to triage support email.'

Scenario 2

The agent wants to issue refunds under $500 without review - it's faster for customers.

Scenario 3

Sales wants the agent emailing prospects as you - 'it sounds exactly like you.'

Permission audit - agent - 1 of 2

Flag what the agent must NOT get.

Select every requested permission that should not be granted by default. Then check your work.

AGENT PERMISSION REQUEST - FLAG THE OVERREACH
Automate or not?

Set the autonomy level.

1 / 12
Knowledge check - 4 of 5 to pass
Module complete
0

Decision points-
Permission audit-
Autonomy calls-
Knowledge check-
AI Safety 101 by Mandrify - Official Certificate
AI
SAFETY
101

This certifies that

has completed Module 8 - The Agent: least privilege for machines on with a safety score of /100 in of active time.

Safety score - control: how your decisions held up, graded 0-100.

Objective: Bound what an AI agent may do and approve its actions deliberately.

Seat time ~10-25 minutes. Verify this certificate at aisafety101.com/verify.

Evidence on record: decision history, lab accuracy, sprint calls, knowledge check. This certificate ID verifies in your firm's admin report. A team certificate issues when every enrolled employee completes all 14 modules.

Your one rule to keep: an agent's permissions should be exactly its job description - and money or promises always get a human.

Next: The Record. You just learned to bound what an agent may do. Next: making it provable - the records that turn "we were careful" into evidence.