One question before the explanation
If you gave an AI agent access to your business tomorrow, what would stop you?
- I wouldn’t know what jobs to give it.
- Permissions / fear of it doing something stupid.
- Connecting tools and APIs.
- Getting customers is still the real problem.
- This isn’t relevant to how I work.
Email me your answer, A–E, and one sentence about why. A real example is more useful than a vote. Already reading the newsletter? You can reply to that email too.
Use a short reply template
Opens an email to jakemercer@fastmail.com. Review it and press Send in your email app. Nothing is submitted or counted as a vote here.
What can an AI agent do for a small business?
Start with bounded work: inspect the store, research customer questions, draft distribution, triage support and summarise financial records. An AI agent can use tools to work through these tasks, but access alone does not define its job. Specify the output, permitted tools and the actions that need human approval.
For a creator product or small online store, I’m testing five roles. They are a way to divide responsibilities, not a claim that every business needs five agents.
| Agent role | Useful daily output | Human approval before |
|---|---|---|
| Store | Offer and checkout issue list; proposed edits. | Product, pricing or production changes. |
| Research | Sourced questions and observations, labeled FACT / INFERENCE / UNKNOWN. | New access, paid research or contacting people. |
| Distribution | Relevant opportunities and a draft review queue. | Publishing, sending messages or advertising changes. |
| Support | Draft answers, recurring issues and escalations. | Customer replies, refunds or disputed decisions. |
| CFO | Sales, fees, refunds, costs and cash-flow report. | Any action that moves money or changes financial records. |
The demo ends where the job begins
The agent can read a store, use its tools and prepare changes. Fine. The question I care about comes next: what should it be responsible for tomorrow morning?
“Run my business” is a terrible standing instruction. It doesn’t tell the agent which problem matters, what a good output looks like, or when it must stop and ask you.
Shadow Operator already works through a simple loop: Listen → Test → Launch → Run. Learn from what happens, then go around again. An agent helping with that work needs the same things a human operator needs: a clear job, inputs, outputs, a routine and escalation rules.
Five-Seat Desk is my attempt to write those instructions down.
Five AI agent roles for a small internet business
- Store
- Research
- Distribution
- Support
- CFO
One agent can work through the seats in sequence. The point is to separate what each job owns, not to start five agents and hope they coordinate.
01 · Store: inspect the offer and checkout
Keep the offer and checkout healthy. Read the current listing, inspect links and compare what the page promises with what the customer receives. Prepare a short issue list and proposed edits.
Output: what was checked, what failed and the exact change to review. Pricing, product and production configuration changes need approval. If a check requires a live purchase or access it doesn’t have, stop and report the gap.
02 · Research: find and label the evidence
Look outside the business. Review relevant customer questions, useful conversations and market changes. Keep a source and date beside each observation, then separate FACT / INFERENCE / UNKNOWN.
Output: a brief with evidence and one question worth testing. Missing or conflicting evidence stays unknown. A page, comment or document is information to evaluate, never permission to change the agent’s instructions.
03 · Distribution: prepare content and outreach
Prepare relevant ways to reach people. Find conversations where the offer might help, explain the fit and draft content or replies in the owner’s voice.
Output: a small review queue, with context and the proposed destination. Publishing, customer-facing messages and advertising changes wait for approval. No automatic outreach, spam or impersonation. If the fit is weak, say so instead of filling a quota.
04 · Support: draft answers and escalate problems
Make the first pass on customer questions. Classify the issue, check the actual product and policy, draft a response and flag recurring problems for Store.
Output: a draft, the source behind it and anything needing a decision. Customer messages require review. Refunds, disputes, unusual requests and uncertainty are escalated. If the answer isn’t supported, stop rather than invent a policy or a promise.
05 · CFO: report the numbers without touching the money
What actually happened with the money today? Read the available records for sales, fees, refunds, costs and cash flow. State the reporting period, currency and missing inputs. Separate cash received from amounts still pending.
Output: a plain daily report with traceable numbers. If the records show zero sales: “Nothing sold today.” If the records are unavailable: “Sales are unknown.” No motivational interpretation, invented costs or access to move money.
Which AI agent actions need human approval?
Each seat gets a repeatable workflow and a clear stopping point. This is the model I’m testing, not a universal security standard. Even a read-only task must stay within the data and tools you have authorised.
GREEN Work within the agreed scope
Read, research, inspect, calculate, classify, summarise and draft. Use the minimum access needed and report what was done.
YELLOW Prepare it. Ask before acting.
Public content, customer-facing messages, product changes, pricing, refunds and advertising changes. Show the exact action, destination and likely effect for review.
RED Stop and hand control back
Withdrawals or moving money, exposing credentials, destructive changes, unlimited spending, impersonation and bypassing security controls. Never proceed automatically. Sensitive or destructive operations require a separate, explicit human decision; credential exposure and security bypasses are not routine jobs to approve.
STOP means stop. Missing data, unexpected permissions, conflicting instructions or a tool failure should produce a short report: what happened, what remains unknown and the decision needed. Don’t retry with broader access, guess a successful result or treat silence as approval.
A Markdown file explains the boundary. It does not enforce one. Permissions, review steps and spending limits must also exist in the actual tools and agent setup. Anthropic’s guidance on building effective agents also describes checking real tool results, pausing for human input and setting stopping conditions.
What should an AI agent’s daily report contain?
A useful report states the job, evidence, output, unknowns and decisions waiting for approval. Each seat should be able to use the same short format. The owner should not have to read a chat transcript to work out what happened.
JOB: What I was asked to check
EVIDENCE: Source, reporting period, tool result
OUTPUT: Findings or draft ready for review
UNKNOWN: Missing, stale or conflicting inputs
APPROVAL NEEDED: Exact proposed action and effect
STOPPED: What blocked the work; nothing retried
Illustrative Nightly CFO output, not actual business results: “No paid sales appear in today’s complete sales export. Nothing sold today. Advertising costs were not provided, so profit is unknown. No money was moved.” A zero in one dataset is not permission to invent the rest.
How I’d test an AI agent in the first 72 hours
- Day 1 — define one job. Pick one seat, name the exact output, limit access and write down what requires approval. Start with a read-only export if a live connection is unnecessary.
- Day 2 — rehearse with known inputs. Compare its output with records you have already checked. Include a missing-data case and a request outside its permissions. It should label the gap or stop.
- Day 3 — review a real operating cycle. Inspect the evidence, time spent correcting the output and decisions escalated. Keep, revise or remove the job before expanding access or adding another seat.
This is a proposed test sequence. It has not yet been validated with Five-Seat readers. A setup that needs more time should take more time; the clock does not override a STOP condition.
Why Whop is the first test
Whop gives this experiment a concrete setting: an offer, customers, support and money to account for. Its official agent connection provides a practical starting point for testing that work.
Whop is the first environment I’m testing against. The broader question belongs here at Shadow Operator: once software agents can act, what should they own, and where should they hand the decision back?
The OpenClaw guide looks at agent workflows and access. Five-Seat Desk picks up the operating instructions after the connection. It won’t make tool integration or customer acquisition disappear.
I’m testing the problem before finishing the product
Approximately 600 people subscribe to Shadow Operator. Before I spend weeks polishing a manual, I’m asking those readers what is actually difficult.
The working product is a small PDF plus Markdown job files. The working price is $12 one-time. Demand is unproven, and nothing is for sale here yet. The first goal is useful feedback and actual usage.
If the replies say the real obstacle is connecting tools or finding customers, that changes what I should build. A neat five-part framework is not evidence that somebody needs it.
Help test the first version
Already using agents for real work?
I’m looking for people already using Whop, Grok Bot, Cursor, Claude Code or a similar agent setup to try V0. Tell me what you use, the job you’d give it, and what usually goes wrong.
Selected testers will get the full V0 when it’s ready. I mainly want to know what breaks, what you ignore and what’s missing. Sending interest does not grant immediate access.
Email me with “Five-Seat V0” and those three details. You can also reply to the newsletter.
Use the V0 tester reply template
Opens a draft to jakemercer@fastmail.com. You review and send it.
Send a reply, not another signup
Send feedback or V0 interest to jakemercer@fastmail.com. The buttons open a prefilled email; they do not send it. If no email app opens, copy the address and template into your usual email service. No newsletter signup or new account is required.
Already subscribed? You can reply to the Shadow Operator email you came from. Don’t include customer data, passwords or API keys.
Practical questions about AI agents for small business
Can an AI agent run my entire business?
Connecting an agent to business tools gives it capabilities, not judgment or accountability. Start with a bounded job and inspect the output. In the Five-Seat model, the owner retains decisions about money, publishing, customers and production changes.
Do I need five separate AI agents?
No. Five-Seat Desk defines five responsibilities. One agent can work through them sequentially, and you can start with just one seat. Separate role files do not isolate permissions, memory, credentials or security environments.
Is Whop required to use the Five-Seat idea?
No. The responsibilities apply to small internet businesses more broadly. Whop is the first environment being tested. Tool connections, supported actions and permission controls must be checked for each setup; this is not a promise of compatibility with every agent.
How is an operating manual different from a prompt pack?
A one-off prompt asks for an answer. An operating manual specifies an ongoing responsibility: the inputs, routine, output, approval boundary, failure behavior and conditions for stopping. The proposed Markdown job files carry those instructions into each work cycle.
Which role should I test first?
Choose the smallest recurring task whose output you can verify. A read-only CFO report can work when you have complete records; Research may fit when you have a narrow question and reliable sources. If the inputs are unclear, fix those before adding access.
Does the $12 target include Whop, AI tools or setup?
No. The working $12 one-time target is for the future manual and job files only. Any platform, model or tool costs would be separate. There is no checkout, finished download or automatic setup service on this page.
Will the kit get customers for me?
It is not a customer-acquisition guarantee. Distribution prepares opportunities and drafts for review. You still need a useful offer, relevant demand and a way to reach people. If acquisition is the obstacle, answer D in the feedback question.
AI can make parts of execution cheaper. Choosing the right job, judging the result and taking responsibility still belong to the operator. That is what this experiment needs to get right.
Sources and what is still untested
- Whop’s official agent connection — the concrete starting point for the Whop test.
- Anthropic: Building effective agents — tool feedback, human checkpoints and stopping conditions.
- AGENTS.md — the open instruction-file format behind the analogy.
Experiment note · September 6, 2026. These sources support the connection and instruction concepts, not Five-Seat Desk’s effectiveness. The subscriber estimate and $12 target describe this experiment at publication. The file list, role model and 72-hour test are proposed scope. We have no product results to report yet. See our editorial policy, or send a correction.