Unattended AI agents
Unattended means the agent runs whether or not anyone is looking. It is the point of an always-on agent and the moment it becomes a system with real consequences, because everything it does at 3am it does without a person to catch it. Here is what has to be true before that is a good idea.
Direct answer
What does an unattended AI agent need to run safely?
Four things: a host that stays online without a person, credentials scoped to only what the agent needs, a hard spend ceiling that stops rather than warns, and actions that are either reversible or gated behind an approval. Missing any one of them turns an ordinary failure into an incident nobody sees until later.
What is safe to leave unattended
| Action | Unattended? | Why |
|---|---|---|
| Read and summarise sources | Yes | Reversible, no external effect |
| Draft a reply for review | Yes | Nothing leaves until you send it |
| Flag and prioritise an inbox | Yes | Changes labels, not outcomes |
| Write a report to a workspace | Yes | Contained and reversible |
| Send external email | Gate it | Cannot be unsent |
| Make a purchase | Gate it | Real money, hard to reverse |
| Delete anything | Gate it | Often unrecoverable |
| Post publicly | Gate it | Reputational, and permanent |
Requirement 1: a host that does not depend on a person
An unattended agent on a laptop is a scheduled agent with a single point of failure wearing shoes. The lid closes, the machine sleeps, the schedule passes and does not catch up. A VPS or a managed environment removes that particular dependency; only one of the two also removes the server.
Requirement 2: credentials scoped to the job
The temptation with an unattended agent is one broad key, because it makes everything work first time. It also means any mistake the agent makes is as wide as that key. Scope is the cheapest safety measure available and it costs one afternoon.
- Read-only wherever the job is genuinely read-only, and many are.
- One credential per integration, so revoking one does not stop everything.
- Stored encrypted and injected at runtime, never pasted into a prompt or committed to a file.
Requirement 3: a ceiling that stops, not one that warns
An attended agent that starts looping gets closed by whoever is watching. An unattended one does not, and the failure compounds for as long as it goes unnoticed. A warning at 80 percent is useful; a hard stop is what actually bounds the damage.
- The cap must halt execution, not send a notification and continue.
- Prepaid is safer than postpaid for exactly this reason: the worst case is a stopped agent, not an invoice.
- A stopped agent is a small problem. An agent that ran all weekend on a retry loop is a different kind of problem.
Requirement 4: reversible actions, or an approval gate
This is the judgment call, and it is worth making deliberately rather than discovering. Sort what the agent can do into things you can undo and things you cannot, and treat the two differently.
- Safely unattended: reading, summarising, drafting, flagging, filing, writing to a workspace you control.
- Gate behind approval: sending email to people outside your team, spending money, deleting, posting publicly, anything with legal or contractual weight.
- The test: if this fires wrongly at 3am and nobody sees it until Monday, what is the worst outcome? If the answer is bad, it needs a gate.
Unattended does not mean unsupervised
The distinction matters and gets lost in the marketing. Unattended is about execution: the agent runs without a person present. Supervised is about accountability: a person still reads what it produced and remains responsible for it. You want the first without giving up the second.
How Qoren supports unattended execution
Agents run in managed, isolated environments that stay online without a person, credentials live in an encrypted vault and are injected at runtime, the credit balance carries a hard stop rather than a warning, and the Hermes runtime supports an approval mode where an action waits for human sign-off before it happens.
Related guides
The honest answer
Do AI agents need supervision?
Yes, but less than you think and differently than you expect. Which parts of running an agent can be automated away, and which stay a human responsibility.
Read guideMoney
AI agent spend control
How AI agents run up unexpected bills: retry loops, growing context, oversized tool payloads. Why alerts arrive too late, and what a real hard stop looks like.
Read guideThe homework, itemised
Stop babysitting your AI agents
Running an AI agent is easy. Keeping it running is the homework: restarts, key rotation, silent failures, runaway spend. The whole list, and who does it.
Read guideFrequently asked questions
What is the difference between an unattended agent and an autonomous one?
Unattended describes when it runs: on a schedule or trigger, without a person present. Autonomous describes how much it decides for itself. An agent can be unattended and tightly scripted, or attended and highly autonomous. Conflating the two is how people end up granting broad permissions they did not intend.
Is it safe to let an AI agent run while I sleep?
It depends entirely on what it can do, not on how good the model is. An agent that reads sources and drafts a brief is safe to run overnight. An agent that can send email, spend money, or delete things should have those specific actions gated behind approval, even if everything else runs freely.
Do I need approvals for every action?
No, and requiring them everywhere defeats the purpose. Gate on reversibility rather than on importance: an agent doing important reading unattended is fine, an agent doing trivial deleting unattended is not.
What is the most common mistake with unattended agents?
One broad credential and no spend ceiling, because that combination is the fastest path to a working demo. It is also the combination where an ordinary bug becomes an incident, since nothing bounds either the blast radius or the bill.
Can an unattended agent still ask me something?
Yes, and the good ones do. Approval mode on the Hermes runtime pauses an action until a human signs off, so the agent runs unattended by default and stops at exactly the steps you said it should stop at.
Run OpenClaw, Hermes or Codex agents 24/7, without the homework.
Qoren runs the machine, the secrets, the updates and the logs, with a hard cap on credit spend. Start from a template and have an agent working today.