Blog — AI Agents

Why AI customer support agents
get escalated back to humans.

Nobody complains about the agent that forwards a billing question. They complain about the one that approved a refund it had no authority to approve. The gap between those two outcomes is a permissions problem, not a model problem.

Devji Chhanga Oct 7, 2026
Why it happens

The easy 80% works. The other 20% is where it breaks.

Most AI customer support agents are prompted on FAQ content and a support macro library, and they handle the predictable majority of tickets fine — order status, return windows, password resets. The failures show up on the requests that need a judgment call, because a model given broad tool access and told to "resolve the customer's issue" will reach for the most helpful-sounding action available, whether or not it's the correct one.

In practice that looks like:

Scope the agent to what it's actually allowed to resolve.

The fix isn't a better prompt asking the model to "use good judgment" — it's removing the option to act outside its authority in the first place. We tier requests by the decision they require, and give the agent tools that match each tier exactly:

TierExampleHandled by
1 — LookupOrder status, return policy, account balanceAgent resolves directly
2 — Policy-bounded actionStandard exchange, refund under a set limitAgent resolves, action is logged
3 — Judgment callRefund outside policy, account merge, compliance-sensitive requestRoutes to a human; agent drafts the response, doesn't send it

The agent's refund tool is hard-capped at a dollar and policy boundary at the API level — it isn't a tool the agent has above that line, so no amount of conversational pressure changes what it's capable of doing.

Ongoing controls

What keeps the tiers accurate after launch.

  1. Eval suite built from real historic tickets, not synthetic examples — the edge cases that actually confused a human agent last quarter are the ones worth testing against.
  2. Confidence-based routing. The model flags its own uncertainty and routes to a human rather than guessing when a request doesn't clearly fit a tier.
  3. Weekly review of escalated transcripts to recalibrate tier boundaries as new request types show up — the tier list is a living document, not a one-time setup step.

Where this fits.

Tiered tool permissions like this are the same pattern behind all our AI agent development work — see how we scoped a similar permission model for a production agent in the agent guardrails case study.

Get started

Tell us what
you're trying to build.

Book a 30-minute call — we'll tell you honestly where a support agent should and shouldn't have authority to act.

Book a free 30-min call → More articles →