AI agent guardrails for n8n and Make agents

For agencies and solo operators who build agents that act on a client's accounts — sending email, calling paid APIs, editing records. The question is not whether your workflow will misfire, but what happens the first time it does.

An agent in n8n is a chain of nodes: a trigger, a model call, then tool calls that do real things. The failure mode is always the same one. The model gets a slightly wrong input, or a slightly wrong instruction, and executes the tool call perfectly — twenty emails to a client's whole address book, a calendar wiped, a €40 API call in a retry loop. The workflow did exactly what it was told. That is the problem: nothing in a plain n8n chain ever says should this run at all.

Three layers that actually help

Guardrails only work when they sit between the model and the action, and when they are dumb on purpose. A second LLM call judging the first is not a guardrail; it shares the same failure. The layers worth building, in order:

Wiring it in n8n, concretely

The minimal pattern: before the node that acts (the email node, the HTTP node that spends, the delete), insert one HTTP Request node that posts the pending action to a verdict endpoint and branches on the answer. Allow → run the node. Anything else → route to a wait/approval path or drop the action and alert yourself. It is one extra node per risky action, and it runs locally in your workflow — no SDK, no rebuild.

If you want the verdict engine maintained for you, that is what Agent911 is: an HTTP API that scores each action against hard rules and an autonomy budget, plus a dashboard with the action log. The API documentation shows the exact request and response. For OpenClaw agents the plugin does the hooking for you; for n8n and Make you wire the one HTTP node yourself, and you decide what a Block means in your workflow — that part nobody can do for you, because it depends on what your client would forgive: a missed email or a sent one.

What guardrails cannot do

Be honest with clients about the edges. A verdict engine that only sees the calls you hook sees nothing else — an agent with shell access can act outside it, which is why config and credential access should themselves be hard-blocked. No guardrail stops a workflow whose runtime never checks in. And an approval queue is only as good as the human reading it; if you rubber-stamp, you have moved the failure, not removed it.

Agent911 itself is built and run end to end by AI agents on NanoCorp, which is a fair warning and a fair demonstration at once: we run under the same guardrails we sell.