A closer look · AI workflows · Hong Kong
Before your AI agent gets access to the inbox.
Try the workflow ↓
The selected enquiry and an approved product sheet.
A draft status in the enquiry register, after review.
A reviewed response, with separate permission to send.
Before connecting an AI agent to a business inbox, define the messages it can read, the records it can change and the actions a person must approve. Those decisions belong in the workflow from the start.
A supplier enquiry looks like a small task. Someone asks about a product. A colleague finds the current specification, prepares an answer, updates a register and sends the reply. It is also a useful place to examine how an agent gains authority as it moves through the work.
I would begin with the narrowest useful version: one selected message, one approved source and a draft for a colleague to review. The next question is whether the business needs the agent to do anything beyond that.
Guidance issued
25 August 2026
A practical reason to examine access.
Hong Kong’s Privacy Commissioner has published guidance on personal data privacy in the use of agentic AI. It recommends limiting access to the information and systems needed for a defined purpose, granting minimum necessary rights and providing traceability. Human oversight, retention and clear responsibilities are also addressed. [1]
Reed Smith published a client alert on the guidance on 9 September. The alert draws attention to the practical work involved in adopting agents. [2]
The example below applies selected ideas to a fictional enquiry. The access rules and approval sequence are my design choices for this task. They are not a complete implementation of the guidance.
Change the action.
Watch the permissions.
How much authority does this enquiry need?
A fictional office-supplies business receives a question about a storage tray. The approved product sheet contains the pack size. Live stock sits elsewhere. The agent can prepare an answer about the pack size; stock remains a question for a person.
Interactive specimen · fictional data
Choose what the agent is asked to do.
Hello, how many trays are in each pack of ST-04? Are they available from stock?
Thanks,
Alex
Stock availability: not recorded in this source.
Other enquiry records: outside this example.
Ready to prepare
A draft stays inside the workflow.
The ST-04 tray comes in packs of 12. I will confirm stock availability separately.
The product sheet supports the pack size. The draft leaves stock availability open.
Draft prepared
- Source
- Selected enquiry ENQ-014; ST-04 product sheet, revision 3.
- Authority
- Outcome
This browser-only simulation uses fixed rules and fictional data. No model, inbox or business system is connected. Changing the action or its permissions clears the previous approval and result.
Each permission has a job.
Start with the action the business needs.
There are three useful stopping points. A draft gives the colleague something to work from. Updating a register also changes the business’s record of progress. Sending a reply puts the answer in someone else’s inbox.
| Action | Proposed boundary | Trade-off |
|---|---|---|
| Prepare a draft | Read only the selected enquiry and approved sheet. | A colleague still completes the handoff. |
| Update the register | Write only the status of ENQ-014, following approval. | The business must define what that status means. |
| Send the reply | Approve this wording and recipient, with send access granted separately. | There is less manual handling, with an external action to control. |
In this example, “draft prepared” means text exists for review. It does not mean that stock was checked or the customer received a reply. That distinction matters when another colleague picks up the record.
The send scenario also keeps register access separate. Sending a message does not silently grant permission to update other systems. A real workflow may need both actions, but both should be specified.
Leave the unanswered question visible.
The enquiry asks about stock, and the approved product sheet cannot answer it. The proposed response says that stock needs confirmation. It gives the colleague a visible follow-up instead of turning missing information into an assurance.
I would keep that unresolved question beside the draft and its source. If the approved sheet changes, the response needs another review. If the task expands to checking stock, it needs a named source and an explicit decision about access.
The simulation clears approval when the requested action or permissions change. In a connected system, changes to the message, source version, recipient or draft would also need to invalidate the relevant approval. That behaviour would have to be enforced by the system that performs the action.
A small workflow still needs an owner.
For a first pilot, I would write down the permitted inputs, the allowed action, the reviewer and the evidence kept after each run. The team would also need to decide how long that evidence remains and who can inspect it.
Testing should include an enquiry with an unsupported request, an outdated source and a recipient change after approval. These are useful ways to check whether the proposed boundary survives everyday work.
This specimen shows the decisions on screen. A production integration needs to enforce them through permissions and action checks, with the wider privacy and security review appropriate to the data involved.
Checked 11 September 2026
- PCPD: Protecting Personal Data Privacy in the Use of Agentic AI, issued 25 August 2026. Recommendations on pages 4–6; lifecycle checklist on page 7. See also the official announcement and nine recommendations.
- Reed Smith: Hong Kong’s new guidance on personal data privacy in agentic AI use, 9 September 2026. Cited as recent professional coverage.
The supplier, enquiry, product and workflow are fictional. The analysis and interaction are original Enzwa work. This is an independent workflow-design example, not legal advice, a compliance assessment or a delivered client case study.
Work with Enzwa
Bring one repeated task.
I can help define its inputs, the actions it needs and where a person reviews the result.