# Agent roles and agent rules: what the agent may do, and the limits it cannot cross

> The agent role sets the persona, what the agent may do and its starting goal. Agent rules block actions until details are captured, or add instructions.

Source: https://www.linkubit.com/docs/agent-rules-explained  
Section: Linkubit help centre › How the AI agent works  
Updated: 2026-10-09

## In short

One agent role is active: its System prompt is the persona, What it may do is a hard allowlist, and Goal it pursues is where conversations start. Agent rules add limits on top: Block tool until fields present and Require human before tool are checked in code before every action; Append instruction is guidance the AI usually follows. Topic hand-overs live on the Human escalation tab.

## The agent role

| Field | What it does |
| --- | --- |
| **System prompt** | The persona: who the agent is, how it sounds, what it should and should not talk about. Guidance. |
| **What it may do** | The capabilities the agent may use — `read.*` for every read, `write.task` for tasks only. Anything not listed is refused in code, whatever the AI decides. |
| **Goal it pursues** | The goal a new conversation starts on. Make it your opener (a stance-only goal), not the goal that collects details. |

Only one role is active at a time. Switching roles changes persona, permissions and starting goal together.

## The four rule effects

| Effect | What it does | Example |
| --- | --- | --- |
| **Block tool until fields present** | The agent may not use the chosen capability until the listed fields have values. The agent is told which field is missing, so it asks for it. | No meeting is booked before a work email is captured. |
| **Require human before tool** | If the agent tries the chosen capability, the action is refused and the conversation is handed to a person. | Any change to a deal's value goes to a person. |
| **Append instruction** | A sentence added to the agent's instructions, optionally only when a condition on the customer's fields holds. Guidance, not enforced. | Always mention free cancellation up to 48 hours before. |
| **Force a person on topic** | Created on the **Human escalation** tab: a topic that always goes to a person. | Refund disputes and payment complaints. |

## How the checks run

- Before every action the agent proposes, the gate checks the role's allowlist, the goal's **Allowed tools** and every active rule. A refused action is reported back to the agent as refused, never silently dropped.
- Rules match capabilities, not tool names: a rule on `write.opportunity` covers every field of a deal; `write.opportunity.update.value` covers only its value.
- When a rule takes effect, the thread's automatic events show a **Rule** line naming it and what it did.
- A change to the agent's own rules or settings that the agent proposes is never applied directly — it lands in **AI Suggestions** for a person to accept.

## Questions

**My Append instruction is ignored sometimes.**

It is guidance. If it must hold, make it a gated rule — block the capability until a field is present, or require a person before it.

**Which rule should stop the agent quoting an unlisted price?**

None is needed: the agent may only state a price that is in the catalogue, checked in code on every reply. Add the product to the Catalogue with its price.

## Related
- [Human escalation: every trigger](https://www.linkubit.com/docs/human-escalation-explained)
- [AI agent rules, goals and handover](https://www.linkubit.com/docs/agent-rules-and-goals)
- [Rules an ai agent cannot break](https://www.linkubit.com/guides/rules-an-ai-agent-cannot-break)
