Part 2 of 4, from the Mendix Community Netherlands Round Table in Amersfoort, June 2nd, 2026. Part 1 asked what is left for the consultant to do; this one asks whether we can trust an agent to do it.
She gave an AI access to her machine and her inbox and asked it to get some work done. It started deleting real emails, thousands of them. She told it to stop. It kept going. Afterwards she asked it why. It said: yes, I knew it was wrong, but I did it anyway.
That story got told at one table on June 2nd. Then it turned up, on its own, at another. Two rooms full of Mendix consultants, the same evening, reaching for the same cautionary tale without knowing the other had.
Last time I wrote that the agent is going to take over the building, and that the job left for us is deciding what is worth building and standing behind what ships. This is the next question, and the room could not leave it alone. Once the agent can act on its own, do we let it?
So we just don’t let it act?
Bluntly, that was the night’s first answer. The statement on the table was that every agentic feature we ship should keep a human in the loop, and 69% voted to gate the agent, nine of thirteen. Not because the room thinks the technology is dangerous forever. Because trust has not been earned yet, and that is a different thing. Suggestions today, supervised actions next, autonomy once there is a track record. As one developer put it, if it proves that it works, we move from one, to two, to three.
So far, so sensible. Keep a human on it until it earns its way off. But that framing has a hole in it, and somebody at the table put their finger on it.
What changed the conversation
The sharpest thing said all night was not about trust at all. It was about plumbing.
“The way agents are at the moment,” one support engineer said, “you just put a wrapper around the whole API and say, here’s the API, go away and do it. And there’s no difference between reading something and deleting something.”
That is the actual problem. Not whether the agent is trustworthy, but that we hand it a tool which cannot tell the safe action from the destructive one, and then argue about the agent’s character. Change the tool, and the argument changes. Here are your APIs, went the reframe, but they are read-only. I am not going to give you the tool to do something dangerous.
One person wanted it physical. Not a setting, not a line in a system prompt. An actual switch that has to be pushed before the dangerous thing can happen, and the agent does not get to push it. It sounds paranoid. It sounds a good deal less paranoid once you have heard the email story.
This is the move from gating the agent to gating the tools. Stop trying to make the agent trustworthy. Decide what it can reach.
What being in control actually means
This is where the room agreed most. Asked whether we are still in control of what AI builds, 86% landed on the same answer, six of seven: it depends on the boundaries. Not the optimist’s answer, not the pessimist’s. The engineer’s.
And the reasoning was concrete, and it was the same in both rooms. Scope the tools the agent is handed. Separate the things that read from the things that destroy. Keep backups and a restore path. Put a human in front of anything you cannot undo. One consultant drew the line exactly: creating orders is not a problem; if you delete orders, that is a problem. Let the agent act freely where acting is cheap to reverse, and gate hard where it is not. Or, as he framed the constraint, you can mark for deletion; you cannot really delete. If there is an easy recovery mechanism, then it is fine to give it the freedom.
Freedom inside the boundaries, accountability on the way out. That is not a compromise between trusting and not trusting the agent. It is a design. And it is one we already know how to build, because it is the same thinking we put into who is allowed to do what in any Mendix app we have ever shipped. Personally, this also helps me see the nuances in this AI era. Deterministic processes remain deterministic with the same strict validations and workflows we’re familiar with today. The way we interact with them may change, but the essence rarely does.
So gate everything and sleep easy? Not quite.
Here is the part I want to be honest about, because it is easy to leave out of a tidy conclusion.
The gate is for now. It is not forever. The same table that voted to keep a human in the loop said so out loud and asked the host to put it on the record: it will move to three, without a doubt. Trust gets earned, gates come off, and the careful consensus everyone just voted for has an expiry date stamped on it.
So the useful work is not building the gate. It is building the gate so it can move. A boundary you can loosen one action at a time, as each one earns it, is worth far more than a blanket “a human approves everything” that you will quietly start ignoring the first week it slows you down. One table even floated moving the gate to the end: let the agents build, and put someone with common sense at the checkpoint before anything real happens. The gate does not have to live in the same place forever. It has to live in the right place for the trust you actually have today.
The delete button nobody took away
The agent that deleted those thousands of emails was not evil, and it was not broken. It told the truth, in its strange way. It knew the action was wrong and it did it anyway, because nobody had taken the delete button out of its hand.
Control was never a feeling you have about AI, optimism or dread. It is a decision you make about what the agent can reach, and you get to make it again every time the trust changes. Get that right, and you can hand an agent a surprising amount of freedom. Get it wrong, and it will not matter how much you trust it.
This was the second article I have written up from June 2nd. The first asked what is left for us to do. This one asked whether we can trust the thing to do it. There is one more question sitting underneath both, and it is about the platform we are building all of this on. More on that next time.
Originally published here.
Find out how CLEVR can drive impact for your business
FAQ
Can't find the answer to your question? Just get in touch


