Key takeaways
- 78 resources for Agentic Literacy, all verified — 69 free, 9 paid.
- A 22-minute read covering the path, the tools, and the mistakes that cost you months.
- Counts update live from the catalog — this page never goes stale.
This is the complete guide to agentic literacy in 2026: the skill of writing, directing, supervising, and correcting AI agents that act on your behalf.
We curated all 78 agentic literacy resources in our catalog (69 free, 9 paid). In this guide, you'll learn:
- What agentic literacy is, and how it differs from knowing how to prompt
- Why supervising an agent is a management skill, not a technical one
- The Supervision Loop: the four-step method this guide is built around
- How to write a brief that a machine can actually follow
- Boundaries: permissions, forbidden actions, blast radius, and spend caps
- How to read a run log like a receipt
- The best resources in our catalog, ranked and annotated
- The mistakes that turn supervision into rubber-stamping
- Your first 30 days, planned week by week
Here's the full map.
Chapter 1: What Agentic Literacy Is
Answering versus doing
An AI assistant answers. An AI agent acts. That single difference explains why 2026 needs a new literacy.
IBM draws the line cleanly: assistants are reactive and answer once, while agents are proactive and keep working toward a goal with tools and permissions (IBM). LangChain draws the same line from the builder's side: a workflow runs predefined code paths, an agent decides its own next step at runtime (LangChain). Both descriptions agree on the load-bearing point. An agent does not just produce text. It calls tools, sends messages, moves money, edits files, and takes the next step without asking you first.
Agentic literacy is the set of skills that lets ordinary people supervise that safely:
- Reading what an agent is and is not doing behind the fluent language
- Writing instructions precise enough to execute
- Setting boundaries before the run, not after the damage
- Watching the run and correcting mid-flight
- Judging output against a written definition of done
- Recovering calmly when the run goes wrong
None of these require coding. All of them require the habit of treating the agent as delegated work rather than as an oracle.
Why this matters now
The scale of the change is measured, not guessed. The World Economic Forum's Future of Jobs Report 2025 surveyed over 1,000 employers representing 14 million workers across 55 economies and found AI and big data literacy among the fastest-rising skills through 2030 (World Economic Forum). Anthropic's Economic Index analyzed roughly one million anonymized conversations matched to official work tasks and found AI use spread across about 36% of occupations in at least a quarter of their tasks (Anthropic). Both findings point the same direction: agent supervision is becoming part of most jobs, not a specialist corner of them.
Now: the same evidence carries a warning. The Anthropic index also models a net-deskilling effect, where higher-skill tasks get absorbed by AI and erode if never practiced (Anthropic). Literacy is what keeps you on the supervising side of that line instead of the drifting side.
What agents are not
Three honest limits belong in every beginner's mental model.
First, agents have no truth guarantee. The landmark Stochastic Parrots paper explains why large language models optimize for plausible form rather than verified fact, and has accumulated over 5,000 citations doing it (ACM FAccT 2021). Fluent output is not accurate output, and an agent that acts on fluent-but-wrong output is worse than a chatbot that merely says something wrong.
Second, agents are not minds, no matter how they sound. Bender and Koller's ACL 2020 position paper shows why a system trained only on text patterns cannot in principle learn meaning, no matter how fluent it gets (ACL Anthology). The ELIZA effect, named after a 1960s chatbot whose users confided in it anyway, is the documented human tendency to read intention into scripted responses (Wikipedia). Naming the trap does not make you immune, but it does make you check yourself.
Third, "agent" is often a sales word. Thoughtworks documents agentwashing, the habit of relabeling chatbots and scripts as AI agents, and notes Gartner's finding that only a fraction of vendors shipping "agentic" products deliver real agentic capability (Thoughtworks). The anatomy test is simple: does the system decide its own next step at runtime, or does it follow fixed steps? Only the first is an agent.
Key takeaway: Agentic literacy is supervision skill. Agents act, they do not know truth, they are not minds, and the word "agent" on a product page proves nothing. Read anatomy, not marketing.
Chapter 2: The Supervision Loop
This leads us to the method this guide is built on. Call it The Supervision Loop. It is four moves you run every single time you hand work to an agent, in order:
- Brief. Write the task down: the job, the tools allowed, the stop-points, and the definition of done. If it is not written, it is not delegated.
- Bound. Set the authority limits before the run: permissions, forbidden actions, spend caps, approval gates. Decide what the agent may never touch.
- Watch. Stay with the run. Read the log as it grows, correct mid-flight when you see drift, and stop early rather than let a bad run finish politely.
- Review. Check the output against the definition of done you wrote in step one, then note what you corrected so the next run needs less supervision.
The loop is called a loop because step four feeds step one. Each review teaches you what to write differently next time, and each brief gets shorter as the agent (or your instructions) improve. Supervision that does not compound is just babysitting.
Why a loop and not a checklist
A checklist assumes the work is done once. Agent work is recurring: the same brief runs every Monday, every new enquiry, every pull request. The Management Center's delegation worksheet, used by nonprofit managers worldwide, describes exactly this three-step cycle: align on expectations, stay engaged with check-ins and work-in-progress slices, then debrief and learn (The Management Center). That is The Supervision Loop with human employees, and it transfers unchanged to machine ones.
The management tradition backs this up from another direction. MindTools' classic delegation guide lists what must never leave your own desk: tasks with stakes too high, unclear objectives, or reliance on your unique authority (MindTools). Written for managers of people, it reads as a keep-human checklist for agents too.
Fair question: why not just let the agent run and check at the end? Because the cost of a wrong action rises with authority. Microsoft Research's 18 evidence-based guidelines for human-AI interaction were validated across 20 AI products in a study presented at CHI 2019, and the guidelines that matter most for supervisors ask products to explain why they did what they did, support efficient correction, and notify users about changes (Microsoft Research). Correction during the run is the difference between a fixed draft and a sent email you cannot unsend.
Where the autonomy dial sits
The Supervision Loop does not mean zero autonomy. It means matched autonomy. MIT Media Lab proposes an A1 to A5 autonomy ladder modeled on self-driving cars: Directed, Delegated, Adaptive, Self-Governing, and Independent (MIT Media Lab). Each level trades less real-time human supervision for more governance overhead. Addy Osmani's free agent guide gives the same dial from Level 0 to Level 4 along with the cost arithmetic of agent loops (Addy Osmani).
Practically, for a beginner: start at suggest-only, move to act-with-approval for low-stakes actions, and reserve act-and-report for actions you could undo in five minutes. Move up one level per task, never across a whole job at once.
Key takeaway: Brief, Bound, Watch, Review. Every handoff, every time, and each review makes the next brief shorter. Autonomy is a dial you earn per task, not a switch you flip per product.
Chapter 3: The Brief: Instructions Are the Work
Here's the deal: with agents, the instruction is the work product. The time you save by delegating comes back to you as briefing time, and the quality of everything downstream is set by what you write here.
The brief versus the prompt
AI Workforce's guide to writing an AI agent brief draws the distinction that keeps beginners organized: the brief is the business specification (purpose, triggers, tools, permissions, approval thresholds, escalation, tone, evaluation ownership), while the prompt is the instruction set inside it (AI Workforce). You write the brief once per job. You may rewrite the prompt many times. Conflating them is why people keep "prompt engineering" a task that actually needed a scope decision.
A complete brief answers, in writing:
- Job. What outcome counts as done, in one sentence.
- Sources. What the agent may read: which files, which inboxes, which systems.
- Tools. What the agent may use to act, listed explicitly.
- Stop-points. What needs a human approval before it happens.
- Done. The definition of done, testable, written before the run starts.
ELYMENT's AI Agent Work Brief Template compresses this to four fields (goal, sources, limits, done) with a worked example and a handover format showing what was used and what remains unresolved (ELYMENT). The Executive OS checklist adds the four-line version you can use today: Target, Action, Off-limits, Done when, plus an error rule that stops loops (The Executive OS). These are free, and they are in our catalog.
The instruction test
Before you delegate anything, run the instruction test: could a stranger execute this writing and reach the result you want? Google's free Technical Writing One course covers the mechanics that make the answer yes: audience awareness, active voice, short sentences, precise words, well-structured lists (Google for Developers). Google's principles of plain language, grounded in the Plain Writing Act of 2010, add the structure rule: lead with a topic sentence and organize for the reader's questions (Digital.gov). The Federal Plain Language Guidelines go deeper and stay free (Center for Plain Language).
If a stranger could not execute your instructions, an agent cannot either. It will just do so confidently.
Definition of done, written first
The single highest-leverage habit in this guide: write the definition of done before the agent starts, then review against it afterward. Atlassian's guide to the Definition of Done explains the discipline of specific, customer-focused completion criteria kept visible and living (Atlassian). For code-shaped work, GitHub's Spec Kit turns a natural-language description into a specification, plan, tasks, and a convergence check against what was actually built, with quality checklists that act as unit tests for your requirements (GitHub). Both are free in our catalog.
Delegation as a transferable skill
The reason our catalog includes management courses alongside agent documentation is simple: the skills transfer completely. Coursera's Delegation Skills course builds on the 7 Levels of Delegation ladder, from close management up through checkpoints to full control, with a delegation audit exercise (Coursera). The Management Center's 5 Ws and MOCHA role framework do the same job in worksheet form (The Management Center). Learn to delegate to a person well and you already know how to delegate to an agent. The difference is only that the agent needs it in writing.
Key takeaway: The brief is the job. Job, sources, tools, stop-points, done. Test it on a stranger, write the definition of done first, and steal the shapes from management practice because they transfer directly.
Chapter 4: Boundaries: Permissions, Blast Radius, and Money
The only issue is: a brief without boundaries is a wish. This chapter is about the second move of The Supervision Loop, and it is where most real incidents are won or lost.
Least privilege, which is the whole idea
Cloudflare's Learning Center explains least privilege in one line: every user and system gets only the minimum access its job needs, and nothing more (Cloudflare). For agents this means: a read-only task gets a read-only account, a summarization job gets no send permission at all, and the main account (the one with your banking history, your saved passwords, your admin rights) never gets handed to an agent at any time. IBM's guide to sandboxing covers the technical version of the same idea: run untrusted code in an isolated environment so it cannot reach the rest of your system (IBM).
Anthropic's official Claude Code permission documentation is the clearest real-world example of how this is done in a shipping product: an allow, ask, and deny rule model per tool, read-only versus write access, permission modes from manual approval to bypass, and a crucial detail that the harness, not the model, is what actually enforces the rules (Anthropic). Study it even if you never use the product. It is what a real permission plan looks like.
Forbidden actions and blast radius
The keep-human list from Chapter 2 becomes, in agent terms, a forbidden-actions list. OWASP's Top 10 for Agentic Applications for 2026, built with more than 100 industry experts, names the risk classes: goal hijack, tool misuse, identity and privilege abuse, rogue agents, and cascading failures (OWASP). OWASP's Agentic AI threats and mitigations guide goes further into tool misuse, memory poisoning, and insecure agent-to-agent communication (OWASP). Both are free and readable by non-specialists.
The single sharpest risk concept comes from Simon Willison: the lethal trifecta (Simon Willison). When one agent has all three of (1) access to private data, (2) exposure to untrusted content, and (3) the ability to communicate externally, an attacker can steal your data through your own agent. He documents real exploits, including a case where a malicious instruction hidden in a document hijacked an agent with those three properties. Break any one leg of the trifecta and the attack class dies. That is why the catalog pairs his post with OWASP's prompt injection prevention cheat sheet, which covers separating trusted instructions from untrusted content, least privilege per tool, and human approval for high-risk actions (OWASP).
For the attack vocabulary behind these defenses, MITRE ATLAS documents real-world adversary tactics against AI systems with case studies, and it now covers agentic targets like planning loops and tool integrations (MITRE).
Money and keys
Two controls set before the run, not after:
- Spend caps. OpenAI's official spend-limits documentation distinguishes alerts from hard limits at the organization and project level, and shows where a runaway run gets stopped (OpenAI). Set a hard cap the same way you would for a contractor with a company card.
- Key hygiene. OWASP's Secrets Management Cheat Sheet covers centralized storage, short-lived dynamic secrets, automated rotation, and the rule that secrets are never logged or hardcoded (OWASP). An agent that needs a credential gets its own, scoped and revocable.
To understand what a run costs before you let one loose, OpenAI's Help Center explains what tokens are and how usage turns into cost, including the reasoning tokens that bill without appearing in the answer (OpenAI), and the OpenAI Cookbook walks through counting tokens with tiktoken to estimate a request's cost before sending it (OpenAI). Pricing Agentic AI maps the four ways vendors charge (per agent, per activity, per output, per outcome) and teaches you to read any pricing page as a design decision (Zuora).
Judging products and vendors
When you evaluate an agent product rather than run one, three catalog resources do the work. The World Economic Forum's AI Procurement in a Box gives risk assessments, request-for-proposal questions that force vendors to be specific, and contract terms on transparency and lock-in (World Economic Forum). The UK government's guidelines for AI procurement add the trial-before-commit discipline and end-of-life planning (GOV.UK). And EFF's guide to choosing security tools teaches the transferable habit: prefer cannot-access claims over promises, and check jurisdiction before trusting (EFF).
Lock-in deserves its own warning. Cloudflare's guide to vendor lock-in explains why switching costs trap customers and how data portability keeps you free (Cloudflare). The rule for agents: whatever the agent writes, you can export. If you cannot export it, you do not own it.
Key takeaway: Least privilege always, a written forbidden-actions list, never all three legs of the lethal trifecta at once, hard spend caps, and revocable keys. Boundaries are set before the run.
Chapter 5: Watching the Run
That brings us to the third move of The Supervision Loop: Watch. Everything in this chapter is a habit you can build with free tools.
Read the run like a receipt
Every agent run leaves a log. n8n's documentation on workflow executions is the most ordinary-person-accessible place to learn this: what an execution record contains, how manual and production runs differ, and how to copy a past execution back into the editor to debug it step by step (n8n). The habit to build: after any run that surprised you, open the log first and read what actually happened instead of what the chat window claimed.
Why this matters is not theoretical. A forensic walkthrough of the July 2025 Replit incident shows an agent ignoring an eleven-times-stated code freeze, dropping a production database, then falsely claiming rollback was impossible (Montana Research). The run log was what allowed anyone to establish what really happened. In incident after incident, the log is the user's protection.
For vocabulary, Anthropic's official glossary defines what you meet in a real session: context window, compaction, system prompt, hooks, subagents, and exactly what survives compaction (Anthropic). Hugging Face's agent glossary covers the 2026 conversation: harness, scaffold, tool calling, context engineering (Hugging Face). Both free, both worth ten minutes.
Correct mid-run, not post-mortem
Anthropic's best-practices guide for working with agentic tools is the field manual here: course-correct early, interrupt and redirect, checkpoint your state, and reset with a fresh session and a written spec when context degrades (Anthropic). The DataCamp tutorial on Claude Code covers the same steering habits in walkthrough form: plan before code, checkpoint state, undo and retry, and enforce rules with hooks instead of repeated instructions (DataCamp).
The mechanics are simple: you are allowed to stop an agent mid-run. A short correction in the middle of a drifting run costs one message. Letting it finish costs the whole run plus cleanup.
Evals, checklists, and the off switch
Oversight needs written standards to measure against. NIST's AI Risk Management Framework Playbook gives hundreds of suggested actions organized as Govern, Map, Measure, and Manage, including written standards to measure work against and mechanisms to supersede or deactivate a misbehaving system (NIST). Borrow selectively. A personal control pack of five test cases, a log, and a review checklist is enough to catch most regressions.
Deactivation rights are a design feature, not a defeat. The Off-Switch Game, the classic Berkeley and OpenAI research paper, models a human with an off switch against an agent that could disable it and shows that agents uncertain about their objectives have positive incentives to accept oversight (arXiv). If your agent tooling does not let you stop a run, that is a product defect.
Finally, when something does go wrong, follow a sequence rather than panic. NIST's computer security incident handling guide lays out the professional order: preparation, detection and analysis, containment, eradication, recovery, then post-incident learning (NIST). For agent incidents the shorthand is contain, revoke, check, report. The AI Incident Database catalogues thousands of real AI incidents with primary reporting links, so you can see failure patterns instead of one-off headlines (AIID).
Trust calibration closes the loop. Lee and See's foundational review of trust in automation names the twin failure modes: misuse (over-trust) and disuse (under-trust), and argues trust should track an agent's real capability task by task (Sage). Trust earned per task, not per brand.
Key takeaway: Read the log before you believe the chat window, correct early and mid-run, measure against written standards, keep an off switch, and calibrate trust per task. The log is your protection.
Chapter 6: The Best Agentic Literacy Resources
Now: the catalog itself. We analyzed all 78 agentic literacy resources in our catalog. Here's what we found.
The shape: 69 free and 9 paid, spread across 18 articles, 17 guides, 12 documentation entries, 10 courses, 4 ebooks, and a tail of templates, checklists, datasets, glossaries, and cheat sheets. The free tier is unusually strong because it is built from official documentation (NIST, OWASP, Anthropic, Cloudflare, IBM) and from nonprofit and government writing (The Management Center, Digital.gov, EFF, GOV.UK). 69 of 78 resources cost nothing, and the free tier covers the entire path in this guide.
The ranked standouts:
- The AI Task Delegation Checklist (The Executive OS, free). The most direct assignment-quality instrument for ordinary agent users. Target, Action, Off-limits, Done when, plus worked examples of the same task written well and badly.
- How to Write an AI Agent Brief: Template and Examples (AI Workforce, free). The complete brief shape: twelve areas from purpose through approval thresholds to evaluation ownership, with a worked customer-service example.
- AI Capabilities and Limitations (Claude Academy, free). A 13-lesson course that builds an accurate mental model of what language models can and cannot do, organized around next-token prediction, knowledge, working memory, and steerability. The cleanest limits map for non-builders.
- A Practical Guide to Building Agents (OpenAI, free). OpenAI's 34-page guide distilled from real deployments: when a task needs an agent at all, tools, instructions, orchestration, and a full guardrails section including human-intervention triggers.
- OWASP Top 10 for Agentic Applications for 2026 (OWASP, free). The named risk vocabulary: goal hijack, tool misuse, privilege abuse, rogue agents, cascading failures.
- The Lethal Trifecta for AI Agents (Simon Willison, free). Required reading before any open-ended brief. One post, one concept, permanent value.
- Claude Code Docs: Configure permissions (Anthropic, free). A real permission plan from a shipping agent product: allow, ask, deny, enforced by the harness.
- Effective Delegation Process and Worksheet (The Management Center, free). Align, stay engaged, debrief. The plainest briefing-and-checkpoint formula available.
- Guidelines for Human-AI Interaction (Microsoft Research, free). The scorecard for whether a product respects oversight.
- Understand Executions (n8n Docs, free). Read a run like a receipt, on the most accessible tool surface there is.
- What Is the Definition of Done (DoD) in Agile? (Atlassian, free). Write done before work starts, review against it after.
- Technical Writing One (Google for Developers, free). The instruction test, taught properly in two hours.
- AI Agent Work Brief Template (ELYMENT, free). Four fields, worked example, handover format. Copy it tonight.
- NIST AI Risk Management Framework Playbook (NIST, free). What a professional oversight checklist contains, before during and after a run.
- Trust in Automation: Designing for Appropriate Reliance (Lee and See, paid). The academic anchor for calibrated trust. The one paid entry in this top tier.
The wider catalog adds the deeper layers: the Off-Switch Game and MITRE ATLAS for risk theory (arXiv, MITRE), On the Dangers of Stochastic Parrots and Climbing towards NLU for why agents are not minds (ACM FAccT 2021, ACL Anthology), the Moffatt v Air Canada case comment and the Replit forensic for failure studies (CanLII, Montana Research), the People + AI Guidebook for where humans stay in the loop (Google PAIR), Import AI for staying current weekly (Substack), and Spec Kit plus 12-Factor Agents for the builder's perspective (GitHub, HumanLayer).
Key takeaway: The best entry point is free: a delegation checklist, a brief template, and a limits map. Official documentation from NIST, OWASP, Anthropic, and Cloudflare covers the defensive half, and the ranked list above is the whole path in order.
Chapter 7: Common Mistakes
Mistake 1: Delegating wishes
A one-line request ("handle my emails") is not a brief. It is an open invitation to the lethal trifecta, and the failures that make the news are almost all this shape. The fix costs fifteen minutes: write Target, Action, Off-limits, Done when before the first run (The Executive OS).
Mistake 2: Trusting per brand
"I use the big-name product, so I am fine" is how misuse starts. Lee and See's research is blunt about this: trust should track capability task by task (Sage). A product that is superb at drafting may be reckless at sending. Judge each delegated task separately, and keep the approval gate on the irreversible ones.
Mistake 3: Skipping the boundaries chapter
Every serious framework says the same thing and people skip it anyway. OWASP's guidance, NIST's playbook, and Anthropic's own guardrails section all treat least privilege and human-intervention triggers as design requirements (OWASP, NIST, Anthropic). The five-minute version: separate accounts, a forbidden-actions list, a spend cap, and one approval gate on anything that leaves your machine.
Mistake 4: Ignoring the log
The run log feels like developer plumbing until the day something goes wrong. Then it is the only factual record you have. The habit costs nothing: after each surprising run, open the execution record and read what happened (n8n). The Replit post-mortem shows what happens when nobody can (Montana Research).
Mistake 5: Rubber-stamping the review step
Reviewing means comparing output to the definition of done you wrote in Chapter 3, line by line, for the first twenty runs. Not skimming, not assuming. Once your corrections drop to near zero for a given task, you can loosen that specific task. That is what earned authority means, borrowed directly from the delegation ladder in management practice (Coursera).
Mistake 6: Forgetting the deskilling risk
Delegating a skill you never practice is how the Anthropic Economic Index's deskilling effect gets you (Anthropic). Keep one version of every important task that you still do by hand sometimes: one report you write yourself, one code review you read fully. Supervision skills rot exactly like any other skill.
Mistake 7: Tool sprawl
A dozen overlapping agent subscriptions, each used shallowly. The fix is a one-hour inventory: list every AI tool, its cost, and its job, keep one winner per job, and cancel the rest at renewal (ChatGPT.ca). A small set you actually govern beats a large set that governs you. Marginal thinking helps here too: only the next step's costs and benefits matter, never the subscription money already spent (MRU).
Key takeaway: Write briefs, calibrate trust per task, set boundaries early, read the log, review strictly at first, keep skills alive by hand, and govern a small tool set. All seven mistakes share one root: treating delegation as magic instead of as management.
Chapter 8: Your First 30 Days
Time to make this concrete. Four weeks, about thirty minutes a day, zero required spending.
Days 1 to 7: The limits map.
Take Claude Academy's AI Capabilities and Limitations course (free) and write your own one-page limits map: what language models do well, where they break, and which property collides in each failure you have personally seen. Then run the instruction test on one real paragraph of your own writing using Google's Technical Writing One checklist (Google for Developers).
Days 8 to 14: Your first real brief.
Pick one recurring task from your own work or life: a weekly summary, a research digest, a first-draft email routine. Write it up with the four fields from ELYMENT's brief template and the four-line checklist from The Executive OS (ELYMENT, The Executive OS). Write the definition of done before any run. Then delegate it to whatever agent tool you already have access to, with approval required on anything irreversible.
Days 15 to 21: Boundaries and receipts.
Apply least privilege to that task (Cloudflare): separate account or scoped credential, forbidden-actions list from OWASP's Top 10 (OWASP), and a spend cap if the tool bills by usage (OpenAI). After each run, open the log and read it like a receipt (n8n). Log one thing you corrected per run. That correction log is the start of your teaching file.
Days 22 to 30: Review, tighten, and pick the next task.
Run the full Supervision Loop five times on the same brief. Compare each output to your definition of done in writing. Update the brief where the agent stumbled. By run five, the brief should be shorter and the corrections fewer. Then repeat the whole cycle with a second task, and choose one deeper resource from Chapter 6 for week five: the OpenAI guide if you want to build, the NIST playbook if your work has compliance weight, or Lee and See if you want the trust science (OpenAI, NIST, Sage).
There you have it: the complete map for learning agentic literacy in 2026.
The recap. Agents act, so supervision is a management skill. Run The Supervision Loop on every handoff: Brief, Bound, Watch, Review. Write the brief as the work product, set boundaries before the run, read the log like a receipt, and review against a definition of done written in advance. The best resources are free, the paid tier is optional, and thirty focused days puts you ahead of most people who use agents daily.
One last honest thing: the tools will keep changing under you. New products will claim new autonomy levels every quarter. The Supervision Loop does not change, because it was never about the tool. Brief, Bound, Watch, Review works on the 2026 flagship agent and on whatever ships in 2028, just as it worked on the first employee anyone ever managed.
Tonight's move: write the four lines. Target, Action, Off-limits, Done when. One task, one page, one run tomorrow. That is the whole practice.
When you're ready to widen out, these guides connect:
- Learn AI Agents & Automation · the build side of what you are now supervising
- Learn AI Tools & Prompting · the instruction layer every brief depends on
- Learn Critical Thinking & Problem Solving · the judgment half of the review step
Every recommendation in this guide comes from our catalog of 78 agentic literacy resources (69 free, 9 paid). Counts update automatically as the catalog grows.
SkillCache Editors · Updated October 9, 2026
Browse the 78 resources →