An instruction saved months ago is not a permanent grant to perform every later action. Divide recurring work into observation, recommendation, draft creation, and external effect. The trusted application grants each category separately and can revoke it. If a run proposes a sensitive effect, the prompt must produce a reviewable proposal tied to fresh evidence and request an approval bound to that exact effect. A prior approval for another window, recipient, or amount does not transfer. Recheck access at each run; a user who lost permission must not inherit it through an old schedule.
Recurring prompts: renew authority for sensitive actions
Operational case
The North Pier manager authorized read-only daily reviews, not customer emails. A held parcel may merit an outreach recommendation, but the assistant saves a draft with shipment ID, reason, and proposed recipient; no message is sent. A supervisor can approve a specific draft after checking current shipment status. If the status changes before approval, the draft expires and requires a fresh review. If the manager's depot access is revoked during the pilot, later scheduled runs stop reading that depot's records.
Scheduled authority: read North Pier status only.
Candidate outreach: draft D-71 with current evidence.
Effect: send requires supervisor approval bound to D-71.
Status changes before approval -> expire D-71.
Depot access revoked -> stop future reads.Performance and operating cost
Per-run authorization and pre-effect rechecks add lookup latency, generally O(1) for indexed identity and record checks. Draft review creates human work, so reserve it for genuinely consequential effects. A stale approval is more expensive than a missed automation: it can send the wrong message to the wrong person. Log the approval identity and effect receipt without storing unrelated customer data in the prompt trace.
Common Mistakes
- Do not treat a saved schedule as permanent consent for future effects.
- Do not reuse approval from a different draft or reporting window.
- Do not rely on the model to enforce revoked access.
Connected lessons
- Production prompt engineering
- Prompt Engineering
- Tool calls: validate intent and arguments before an external effect
- Browser forms: treat preview, submit, and server validation separately
- Retrieval prompts: enforce document permission first
- Recurring prompts: define the trigger and stop condition
- Recurring prompts: bind local time and data windows
- Recurring prompts: validate fresh inputs and empty states
- Recurring prompts: survive retries without duplicate effects
- Recurring prompts: notify only on actionable changes
- Recurring prompts: make every run replayable and auditable
- Project: build a North Pier recurring review
- Recurring prompt workflow decisions
