Postbase is open source.Star us on GitHub
AI agents

How to let an AI agent post for you without losing control

Guardrails for letting Claude, ChatGPT or any AI agent post to your social accounts: drafts first, scoped access and one-click revoke.

23 September 2026 · 3 min read

Letting an AI agent post for you sounds either brilliant or terrifying, depending on who you ask. It can be brilliant, as long as you set it up so a bad post gets caught before it goes out, and a misbehaving connection can be switched off in seconds.

These are the rules we recommend, roughly in the order you should put them in place.

1. Give the agent the fewest powers that work

The biggest safety decision is made before you type a single prompt: which tools the agent gets. An agent can only do what its tools allow, so pick a connection with a short, boring list.

For posting, the agent needs to:

  • see which accounts it can post to
  • create a draft or a scheduled post
  • see what's queued
  • cancel something it got wrong

It doesn't need to delete published posts, disconnect accounts, invite people to your workspace or touch billing. If a tool offers those to an AI, think twice.

What can my agent call?
list_channelsSee connected accounts and their platforms.
create_postDraft or schedule a post/thread to any channels.
list_scheduledReview what's queued to publish.
cancel_postPull a scheduled post before it goes out.
Postbase gives AI tools four tools and nothing else. There's no delete, disconnect or settings tool to misuse.

2. Connect with a sign-in, not a shared password

Never give an AI tool your social media passwords. Connect it through a service that uses OAuth, where you approve access in a browser window and can take it back later.

The same goes for API keys: if you do use one, give each tool its own key with a label like "Claude on my laptop", so you can revoke one without breaking the others.

3. Drafts first, for at least a week

For the first week, tell the agent to save everything as a draft:

Write the posts, but save them as drafts. Don't schedule anything.

Read what it writes. You'll quickly learn where it's reliable (summaries, trimming to length, reformatting for each network) and where it needs help (your tone of voice, facts it can't check, anything time-sensitive). Once the drafts consistently need only light edits, let it schedule.

4. Always go through a calendar

An agent that posts straight to X is fine for a quick one-off, but anything regular should go through a calendar or queue that a human looks at. That gives you a window between "the agent scheduled it" and "the world can see it".

Calendar
New post
21 – 27 Sep 2026Today
Mon
21
Tue
22
Wed
23
Thu
24
Fri
25
Sat
26
Sun
27
09:00
10:00
11:00
12:00
13:00
14:00
15:00
Manage channels
Posts an agent schedules in Postbase sit on the same calendar as yours, where you can open, edit or cancel them.

A simple habit: check the week's calendar every Monday morning, and look at anything scheduled in the next hour before a big launch.

5. Tell it your rules, once

Most bad AI posts come from missing context, not bad intentions. Write your rules down once and reuse them: in a Claude Project's instructions, a Claude Code slash command, or a note you paste at the start of a chat. For example:

  • Our voice: plain, friendly, no hype words, no exclamation marks.
  • Never mention prices, discounts or dates unless I give them to you.
  • Never @mention people or companies unless I ask.
  • No more than one hashtag, and only on LinkedIn.
  • If you're not sure something is true, leave it out and tell me.

6. Keep it away from the risky stuff

Some posts should always be written or at least approved by a person:

  • anything about a crisis, an outage or an apology
  • replies to customers or journalists
  • legal, financial or medical claims
  • anything involving someone else's name or photo

An agent is great for the routine 80%: announcements, repurposing, reminders, the weekly roundup. Keep the rest for humans.

7. Know how to switch it off

Before you connect anything, find the off switch. You should be able to see every AI tool connected to your account and revoke each one on its own.

Connected apps

Tools you've signed in to Postbase from. Revoking cuts off their access immediately.

Claude
Halden Coffee · connected 23 Sep 2026 · last used 23 Sep 2026
Revoke
Cursor
Halden Coffee · connected 14 Sep 2026 · last used 22 Sep 2026
Revoke
Every connected AI tool is listed on Postbase's Developers page. Revoking one cuts it off immediately, and posts it already scheduled stay on your calendar.

Revoking should stop new actions straight away but leave what's already scheduled in place, so you can decide what to keep.

8. Review the connection list every month

Connections pile up: a Cursor you tried once, a Claude Desktop on an old laptop, a teammate's test. Once a month, open the list of connected apps and revoke anything you don't recognise or no longer use.

A setup we'd recommend

Putting it together, a sensible setup looks like this:

  1. Connect your accounts to a scheduler with a calendar, such as Postbase.
  2. Add its MCP server to your AI tool with a sign-in, not a key.
  3. Write your voice and rules into a reusable instruction.
  4. Drafts only for the first week.
  5. Scheduling after that, with a Monday check of the calendar.
  6. A monthly look at connected apps.

That keeps the time savings and removes most of the risk. The agent does the writing and busywork, and you keep the final say.

Ready to try it? Here's how to connect Claude to your social accounts.

Try Postbase free for 7 days

Every network, the MCP server and the API on every plan.

Start free trial

Related

Keep reading

Ready to get started?

Schedule to every network from one calendar, or let your AI agent do it.

Cancel anytime · or self-host for free

Postbase
21 – 27 Sep 2026TodayDayWeek
Wed23
09:00
10:00
11:00
12:00
13:00
14:00
15:00
16:00
09:00Fieldnote 2.4 is out
12:00New on the shelf: Kochere
14:15Cupping notes
16:30Studio tour
Manage channels