The Horse That
Opens Gatesand stops at every one
The same animal from the first session starts doing the actual work. The thing that makes that safe is that it will not touch a latch until you say so.
By the end of today you will know what an agent actually is, what it can and cannot reach, and exactly what happens at the moment before it changes anything.
Presented by Emile du Toit
brainitconsulting.com
Three sessions in, and the room is ready.
- The horse predicts the next word. The saddle is your standing instructions. The saddlebags are tools.
- One folder, one job — the line round the work.
- The tack room is the editor: your files on the left, the open page in the middle, and the assistant beside them.
Everything so far, the assistant only talked about. Today it starts doing.
Contents
- The horse that opens gatesSame animal. Put to work.
- It stops at every gateThe most important thing in this session.
- What's in the bags nowFour things it can actually do.
- Taking the reins backStopping it is normal, not failure.
Then the questions this always raises, the glossary so far, and the picture to photograph.
The horse that opens gates
Nothing has been replaced. Something has been added.
A riding horse takes you somewhere and brings you back. A working horse does a job on the property — pulls the load, moves the stock, and yes, gets a gate open when a gate is in the way. Same animal, same training, different work, and rather different tack.
That is what has changed. In the first session you had a horse and a set of reins: you asked, it answered, and everything it produced arrived as words you then had to carry somewhere yourself. Last session we walked into the room where your files are. Today the horse comes into that room and starts picking things up.
- Sessions one and two. It could talk, and it could use tools. You did all the fetching and carrying.
- Sessions three and four. We found the room where your work lives, and fitted it out.
- Today. It can open your files, change them, and run things — inside that one folder, and only when you say yes.
The word for this is an agent, which sounds like something from a film and means something very dull: a model that has been given a goal, some tools, and permission to keep going until the job is done. You met the idea in session one as the loop. Today you meet it as a thing on a screen.
Nobody fetched a cleverer horse. They just put this one to work.
It stops at every gate
If you remember one thing from today, this is the one.
A working horse that opens gates sounds alarming until you see how it actually goes. It walks up to the gate. It stops. It waits. It does not touch the latch until the person with it says go. Every gate, every time, no exceptions, no matter how many times it has been through that gate before.
On screen this is the permission prompt, and it is what makes this session safe. Before the assistant changes a file, creates a file, or runs anything on your computer, it stops and tells you exactly what it is about to do. Nothing happens until you answer.
What the prompt is telling you
It will name the file, and show you what it wants to write. Read the file name at minimum. Most mistakes announce themselves right there — a file you didn't expect, in a place you didn't expect.
- Yes — go ahead, this once.
- No — don't. It stops and asks what you'd rather it did. Saying no is not an argument; it is steering.
- Yes, and stop asking for this kind of thing — convenient, and the one to leave alone for now.
Ask me every time. The gate stays shut until you open it. Start here. Stay here for a good while.
Go ahead on your own. It stops asking about edits and just works. Useful once you know a job well — and only in a folder where a mistake costs you nothing.
Just tell me the plan. It works out what it would do and shows you, without touching anything. Excellent for "what would this take?" and completely safe.
The middle one is where people get themselves into trouble, and always in the same way: they turn it on for a job they understand, then leave it on for a job they don't.
What's in the bags now
Session one's saddlebags, made real.
In the first session the saddlebags were an idea — the things a model could be given so it could act rather than only talk. Sitting in your folder, they stop being an idea. Here is every one of them, and the list is shorter than you would think.
"Run a command" is the one that makes people sit up, so let us be plain about it. It means the assistant can do the sort of thing you did in the black panel last session — check a version, count some files, start something. It cannot reach outside the folder you opened it in, and it asks before every single one.
What is not in the bags matters just as much. It has no access to your email unless you connect it. It cannot see your other folders. It has not been given your bank, your accounts package, or your phone. Those connections exist and are useful, and they are a later session, deliberately.
Taking the reins back
Stopping it is ordinary. Riders do it constantly.
Sooner or later it will set off in a direction you did not intend — usually because you asked for something more loosely than you thought. Nobody watching this for the first time expects to be allowed to interrupt, so it is worth saying plainly: you can stop it at any moment, and doing so costs nothing.
The three ways you steer mid-job
- Stop it. The escape key. It halts where it is. Nothing is half-broken, because anything it had already done, it had already asked you about.
- Say no at the gate. When the prompt appears and it is about to do the wrong thing, decline. It stops and asks what you would prefer.
- Just tell it. "No, not that file — the one in past-estimates." It is a conversation, and correcting it mid-job is the normal way to work, not a sign anything failed.
Sometimes it will come back with a question rather than an answer — which tank size, which of these two files did you mean, do you want this sent or drafted. That is the behaviour you want. Dale's own rules say don't guess a price, and a horse that asks rather than guesses is one you can leave a job with.
There is one more thing worth knowing before next session. Everything above is steering while you are watching. What none of it gives you is a way back after the fact — if you approve a change to your rate card on Tuesday and realise on Thursday it was wrong, none of these buttons help. That is exactly what session seven is for.
Questions people actually ask
The ones that come up the moment it can change something.
Can it delete my files?
Only through a gate you opened.
Inside the folder you opened it in, yes — and it will stop and tell you before it does. It cannot touch anything outside that folder. The honest risk is not that it goes rogue; it is that you get comfortable and start clicking yes without reading, which is why we work on copies until session seven.
Could I break my computer with this?
The horse is in one stall, and the door is latched.
Practically, no. It works in the folder you opened, it asks before it runs anything, and nothing on this list touches Windows or macOS itself. The realistic bad day is a folder of files in a mess — annoying, recoverable, and the exact thing session seven makes trivial.
Is it uploading my files to train itself?
The horse reads in your room. It doesn't take the papers home.
What it reads goes to the company's computers so it can answer — the same as when you pasted into a browser in session one. Whether those conversations may be used to improve future models is a setting in your account, and it is worth looking at once and deciding. The model itself is not learning your business as it goes; it starts each conversation knowing nothing but what is in the room.
Plain words
Everything the series has named so far. Today's are marked.
This list grows every session and always shows the lot, so you never need last week's handout to read this week's.
- Large language model (LLM) 001
- The engine that predicts the next word. The horse.
- GPT 001
- Generative — it makes new text rather than looking up a stored answer. Pre-trained — all its learning happened in advance. Transformer — the design of the machinery underneath. A breed name, not a job title.
- Knowledge cutoff 001
- The date its training stopped. It knows nothing after it, and doesn't know that it doesn't. The last day the horse was out in the world.
- Prompt 001
- What you type. A pull on the reins.
- Chatbot 001
- A model you can talk to, turn by turn. Horse plus bridle.
- System prompt / instructions 001
- Standing orders sent with every message, whether you type them or not. The saddle.
- Context window 001
- How much of the conversation it can hold at once. How far it can see on this ride.
- Token 001
- A chunk of a word — how length is counted, and how you're billed. Sugar cubes.
- Hallucination 001
- Making something up and sounding certain. Shying at a shed snakeskin.
- Tool 002
- A specific action it's allowed to take in the real world. A saddlebag.
- MCP 002
- An agreed standard for plugging tools into a model. Standard-size buckles.
- Agent 002
- A model given a goal, tools, and permission to keep going. A working horse, not a show pony.
- Agentic loop 002
- Look, decide, act, check, repeat. The ride itself.
- Human in the loop 002
- A person approves before something real happens. A hand on the reins.
- Automation 002
- The same work happening without you starting it each time. The horse knows the route.
- File 003
- A thing with a name and contents. A single piece of gear.
- Folder (directory) 003
- A box holding files, and sometimes other folders. A shelf.
- Project 003
- One folder holding one job's worth of everything. The room, with the door shut.
- Path 003
- The written address of a file — which boxes it sits inside. Directions to the shelf.
- Editor (VS Code) 004
- A window showing you one folder and everything in it. The tack room.
- Terminal 004
- A panel where you type an instruction to the computer directly. Talking to the stable itself.
- Install 004
- Putting a program on your own machine, once. Building the room.
- Permission prompt 005
- The stop before it changes anything, showing what it plans to do. The gate, and your hand on the latch.
- Approval mode 005
- Whether it asks every time, works on its own, or only shows a plan. How loose you're holding the reins.
- Interrupting 005
- Stopping it mid-job with the escape key. A pull on the reins. Ordinary.
Everything on one page
Photograph this before you go.
1 · It can act
Read, write, run, look things up — inside one folder.
2 · It stops at the gate
Every change, every command. You open the latch.
3 · You can stop it
Escape halts it. Saying no is steering, not failure.
4 · Driving it
Describing a job, and writing the house rules down.
And there is still no undo. Until we fit one, work on copies of anything you would be sorry to lose. Ten seconds of copying buys you every mistake for free.
#006 — Driving the Working Horse
Today was what it is and what it will not do without asking. Next time is how to drive it: describing a job so you get the thing you wanted, writing your house rules into the folder so you stop repeating them, and choosing between the two of these worth using.
Before you come: nothing. Just turn up.
I do this for a living, and love to help people.
Thirty-plus years in enterprise software and a computer science degree — which mostly means I have watched a great many horses bolt, and I can usually tell you which ones are worth saddling before you spend money on the saddle.
In person
Your team, your room, your actual work on the whiteboard instead of somebody else's examples.
Over video
The same session, at your desks, with fewer chairs to stack afterwards.
Built for real
When the idea survives the workshop and somebody has to go and build the thing — that part I do too.
Fun fact — I rode to school on horseback as a kid in South Africa. So the metaphor isn't borrowed. I've done the falling off in person.
Emile du Toit brainitconsulting.com
Workshop #005 · The Horse That Opens Gates
© 2026 Emile du Toit, BrainIT Consulting
Print it, download it, share it with your team. Just leave my name on it.