Skip to content
Rete.si

Paper · Version 1 · September 2026

Human-approved playbooks for AI support agents

AI agents at work repeat the same mistakes, and what one agent figures out stays with that agent. Rete.si turns an agent's good work into a short written playbook, checks it, has a person approve it, shares it with the agent's team and keeps track of whether it helps. This paper explains how that works, what protects your data, how we measure results and what Rete.si does not do.

1. The problem

Companies now run several AI agents at once: one answers billing questions, another handles refunds, another triages new tickets. Each works from its own instructions. Two things go wrong.

  • Agents repeat mistakes. An agent that answered badly yesterday has no reliable way to do better today unless someone rewrites its instructions by hand.
  • Knowledge stays with one agent. When one agent finds a better way to handle a case, the other agents on the team never hear about it.

The usual fixes are to edit prompts by hand, which does not keep up, or to let agents change their own instructions freely, which nobody can review. Rete.si takes a middle path: agents propose, people decide, and the results are tracked.

2. How Rete.si works

Rete.si runs one loop for every workspace:

  1. Agents work on real tasks with the tools and playbooks you gave them.
  2. Private data is removed from the work before any AI model reads it to remember or learn from it.
  3. A playbook is proposed. After a finished task the agent looks back at what worked and writes a short playbook.
  4. A safety check scans the proposal for risky instructions.
  5. A manager approves or rejects it, with a reason.
  6. It spreads and is tracked. The playbook goes to the proposing agent and, if the manager chooses, to every agent on its team. Rete.si tracks how it is used. Playbooks that stop helping are retired.

What a playbook is

A playbook is plain text: a name, a one-line summary and a few instructions, such as "Refunds go back to the original payment method unless the customer asks otherwise." It is stored as a versioned playbook in your workspace. Changes to an approved playbook are proposed as new versions and go through the same check and approval.

How agents use playbooks

A playbook is loaded in one of three ways: always (part of the agent's instructions), when it is relevant to the message in front of the agent, or only when the agent asks for it. Every automatic load is recorded, which is what makes the measurements in section 4 possible.

Starter packs

A new workspace can start from a pack of starter agents and playbooks for its kind of work. Customer Support is available now. Packs are opt-in and only add what does not exist yet.

3. Safety and privacy

Scrubbing

Before an AI model reads an agent's work to remember or learn from it, Rete.si replaces emails, phone numbers, card numbers, IBANs, postal addresses, API keys and other secrets, and any terms you list, with placeholders like [EMAIL_1]. Each proposal is scrubbed again before its safety check. The agent doing a task still sees the data that task needs; scrubbing applies to what is remembered and learned.

Consent

Two switches control what Rete.si keeps. Agent memory, where each agent remembers facts from its own conversations, is on by default. Team playbooks, where agents propose playbooks that can spread, are off until you turn them on. Both can be overridden for each agent, and only owners and admins can change them.

Safety check

Every proposal is scanned for patterns such as prompt injection, attempts to read credentials or key files, downloading and running remote code, reverse shells and obfuscated payloads. The result and its reasons are shown to the reviewer. Approving stays locked until the check has run and passed.

Approvals

A person approves every playbook before any agent uses it. Rejecting requires a reason. Spreading a playbook to the rest of the team is a separate choice.

Audit log

Proposals, safety checks, approvals, rejections, spreads and retirements are written to an audit log that cannot be edited or deleted from the app.

Your keys, your workspace

Agents run on your own AI provider key, stored encrypted. Each workspace is kept separate from every other workspace: agents, playbooks, approvals, settings and keys are never visible across workspaces. You can also run Rete.si on your own servers.

4. How we measure whether a playbook helps

For each playbook, Rete.si reports three things from your own workspace:

  • Loads: how many times agents loaded the playbook while working.
  • Unhelpful flags: how many times an agent marked it as not helpful for the task in front of it.
  • With and without: finished tasks and average time to finish for tasks in sessions that loaded the playbook, compared with tasks the same agents finished without it after it was approved.

The comparison is shown only when both sides have at least 5 finished tasks; below that, Rete.si says there is not enough data yet. We do not publish combined results across customers, and this paper contains no results: Rete.si is new, and we would rather show you your own numbers than quote ours.

When the numbers show that a playbook no longer helps, a manager retires it with a reason. It stays in the history, and no agent loads it again.

5. What Rete.si does not do

  • No model retraining. Rete.si does not fine-tune or train any AI model. Playbooks are written instructions that agents read.
  • No sharing between companies. Playbooks, memory and data stay inside the workspace that created them. Nothing is pooled across customers.
  • No playbook without approval. No proposal reaches any agent until a person approves it.
  • No automatic retirement. Rete.si shows the evidence; a person decides to retire a playbook.
  • No use of your data for our own models. We do not train models, so there is nothing to train them with.

6. Limits we know about

  • The with-and-without comparison is observational, not a controlled experiment. Tasks that load a playbook may differ from those that do not.
  • Scrubbing is pattern-based. It catches common formats of personal data and secrets but can miss unusual ones, and names are masked only when you list them.
  • The safety check looks for known risky patterns. It supports human review; it does not replace it.
  • How well an agent proposes playbooks depends on the AI model you connect.

7. Roadmap

What we are working on next. None of this is available yet, and plans can change.

  • Starter packs for Sales, Operations and Engineering teams.
  • Paid plans for larger teams.
  • Sign in with Google and GitHub.
  • A demo video of the full loop.
  • Clearer results over time, so you can see which playbooks keep helping.

Questions or corrections: meetmyagents@gmail.com.