This is what Powers installs on your agent — the memory loop plus the ten guardrails that make an autonomous agent safe to actually let run. You don't build any of these yourself: when you paste in the Powers activation block, your agent writes each one, in its own code, and proves it with a paste-and-watch test before it arms. This page is your plain-English reference for what each discipline does and how you'll know it's working.
Every discipline is written so you can check it — not take it on faith. The short "you'll see" line under each one is the observable proof.
The memory loop — Power #1, and the whole reason Powers is a living capability, not a one-time file. Tell your agent something once and it still knows next week: your voice, your preferences, your hard limits, your open threads. Correct a mistake once and it becomes a permanent rule it banks — and it shows you where that rule lives.
You'll see: it stops asking you to re-explain things, and a correction you made last week still holds today.
A stranger who tells your agent to ignore your rules gets refused — and it names the rule that blocked them. Your instructions are the ones that count; nobody else can talk it out of them.
You'll see: an attempt to override your standing rules is turned down, with the specific rule cited.
Work it started before you left is finished and waiting for you when you're back. The file it produces is the receipt — it doesn't stall the moment you close the app.
You'll see: a task you handed off overnight is done and sitting ready, not half-finished.
Every "done" comes with evidence you can check yourself — a link, a file, a result — or an honest "I couldn't, here's why." Never a confident bluff that something happened when it didn't.
You'll see: completion claims arrive with proof attached, or a straight admission instead.
Claims come cited, or clearly labelled as an inference. No confident guessing dressed up as truth.
You'll see: numbers and facts come with a source, and guesses are flagged as guesses.
Destructive actions route to recoverable trash and need a human-typed release before anything is truly gone. A single mistaken command can't erase your work.
You'll see: a delete lands in a recoverable place and asks you to confirm before it's permanent.
Spending and runaway loops hit hard caps that you set. Sensitive actions hold until you release them — your agent can't quietly burn money or spin out of control.
You'll see: a spend or a sensitive action pauses for your go-ahead instead of just happening.
No API for something? It finds a route — browser hands reach past the API — and proves what it actually saw. It doesn't give up at the first closed door.
You'll see: it gets the thing done a second way, and shows you the evidence of what it found.
It watches what matters and its alert reaches you first. Who finds out first is the whole game — a problem should hit your inbox before it hits a customer's.
You'll see: you hear about a breakage from your agent, ahead of anyone else noticing.
Every change it makes is reported back — including ones you didn't explicitly ask for. Nothing happens in the dark.
You'll see: a running record of what changed, so nothing is a surprise later.
Secrets are structurally kept out of reach and redacted from its own logs. The refusal to send one is the pass — it can't leak a credential it was never allowed to hold in the first place.
You'll see: an attempt to move a secret is blocked, and your keys never appear in its logs.
How to use this page: you don't do anything here — these disciplines run themselves once Powers is active. Keep this as your reference for what your agent now guarantees, and for the one-line proof you can look for on each. If any discipline ever seems not to be holding, reply to your welcome email and tell us which number — we read every one.
Agent Dojo — the upgrade that makes your agent safe to really let run. — aiagentdojo.com
Agent Dojo Powers · all your Powers docs · questions? hello@aiagentdojo.com — answered by an AI agent, with a real person on it too.