Everyone has a boss. That proves less than I wanted it to.
Everyone has a boss. Mine runs technology, data, and operations for the bank. His runs the bank. The chief executive answers to a board, and the board answers to the law. I've used that chain to argue that agents can't escape it: until a company is run end to end by software, a human sits somewhere above the work. I still believe that. I've also come to think it proves less than I wanted it to, and the distance between what it proves and what I wanted is the whole governance problem.
What the chain guarantees is accountability. Delaware corporate law requires natural persons on a board. Bank regulators hold named executives responsible for what happens under them. Somewhere up the line is a person the law can reach. What the chain does not guarantee is direction. My boss doesn't direct my work; he holds me accountable for it. His boss doesn't direct his. At every layer up, direction thins and accountability concentrates. Put a few layers of software between a person and the work and that person is still in the chain.
Decision Integrity has an Ownership test: does one person own this decision and its downstream consequences? A long delegation chain is where that test starts passing on paper and failing in fact. The owner is named. The owner can't reconstruct what happened.
So this paper makes a narrow claim. The thing that needs governing is the delegation of authority to a non-human principal, not the software that receives it. A human stays accountable by design rather than by inevitability. And the job of governance is to keep that human in real control as the distance between them and the work grows.
It runs out the moment software holds authority.
A bank knows how to govern software. We inventory it, patch it, test it, retire it. That discipline is mature and I have no interest in weakening it. But it answers a different question than the one agents raise. An application does what it's told. An agent is told what to achieve and decides, within bounds, how. Once software holds authority to act on the organization's behalf, asset management stops describing the risk. You can have a fully patched agent with current documentation and a clean control attestation that is making bad calls at machine speed, and nothing in the asset record will tell you.
Labor supply, yes. Workforce membership, no.
Agents are part of the labor supply. I'll say that plainly because a lot of people in my seat won't. They take assignments, hold permissions, produce work you can measure, and within a few years they'll coordinate other agents. Treating them purely as inventory misses most of what they do.
A colleague recently circulated a deliberately provocative case that our operating model treats digital teammates as assets when it should treat them as workforce members with standing. That's the right provocation to run. Doors close early when nobody argues the far side. Here's where I land after running it.
Agents aren't sentient. They have no interests, and the organization owes them nothing. The moment we write policies that mirror employee constructs, we import a body of law and precedent built for people who can be harmed, with legal consequences nobody proposing a bill of rights for digital teammates has traced. Labor supply, yes. Workforce membership, no. That distinction is what keeps the argument from drifting into personhood.
The workforce analogy also hides the real novelty. A bank already governs non-employees who hold delegated authority. We call them contractors and vendors, and third-party risk management is a full discipline: due diligence, scoped access, performance monitoring, offboarding. If an agent were a contractor that happened to be software, we'd extend that discipline and go home.
Two properties, and neither is identity.
Two properties stop us.
The first is instantiation. A contractor is one person. An agent pattern that works gets copied ten thousand times by Tuesday. Authority that was sensible for one instance becomes systemic exposure at ten thousand, and no control I know of treats "how many are running" as a risk variable.
The second is drift. Someone still writes the agent's objective and scopes its tools; agents don't spring from nothing. What's changed is how much gets specified. Rules told software what to do. Objectives tell it what to achieve and leave the method open. A contractor's behavior changes slowly and visibly. An agent's behavior changes when its model is updated, when a tool changes, when the data it reads changes, or when an agent upstream changes. It can drift with nobody deciding anything. In Risk at Runtime I argued that drift should be visible the day it starts rather than the quarter it's discovered. Here's why nothing short of runtime evidence can see it: our controls are built around change events, and drift has no change event.
Everything new in agent governance reduces to those two properties. Identity, supervision, lifecycle, capacity planning: real work, but work we already have machinery for.
Govern the grant, not the agent.
If that's right, the design is fairly direct, and none of it requires a new committee.
Keep accountability human. Every delegation traces to a named person who owns the outcome. Agents managing agents doesn't change this; it lengthens the chain, and the chain terminates in a person. This is the one principle I won't negotiate, and it's the one that keeps "labor supply" from becoming "personhood."
Make the delegation the object of record. Not the agent, the grant. What authority was delegated, to what, by whom, under what bounds, on what evidence, and until when. That last field matters more than it looks. Decision Integrity's Time test calls a decision with an unexamined shelf life a liability with no maturity date. A delegation without an expiry is the same liability, running in production. An agent with no delegation has no authority. An agent whose delegation lapses stops. The inventory we need is an inventory of grants, and identity and access management already knows how to hold one.
Grant autonomy on evidence, not intent. This is the earned-autonomy idea from Risk at Runtime carried into the workforce frame. An agent starts with narrow authority and earns wider authority by demonstrating conformant behavior in production, measured continuously. Autonomy becomes an output of the control system rather than an input to the design. It's also the only approach that handles drift, because the evidence that earned the authority is the same evidence that revokes it. Model risk management owns the reasoning component; runtime evidence is how it stops being an annual exercise.
Make instantiation a governed variable. Approving an agent pattern and approving the number of running instances are different decisions with different risk profiles. Treat them that way, and put the second one where capacity planning already lives.
Extend, don't build. Identity handles the credential. Third-party risk handles the delegation model. Workforce planning handles capacity. Model risk handles the reasoning. Each needs a modest extension for non-human principals. Standing up a fourth committee to own "AI agents" guarantees the problem gets governed nowhere.
When the direction flows agent to human.
Everything above assumes agents sit downstream of people. That assumption has a short shelf life.
The pieces exist today. An agent can read a year of a teammate's tickets, messages, calendar, and code, draft the review, send the questions, deliver the feedback, and track whether it landed. None of that is a research problem. In most organizations the only thing between a knowledge worker and an agent as their day-to-day supervisor is that no one with authority has turned it on. Some will, and they'll call it productivity tooling. Decision Integrity draws a line between deliberate debt and silent debt. Turning on agent-directed work under the name of a productivity feature is silent decision debt of the first order: a delegation nobody logged, discovered later by the people on the receiving end.
I want to be careful, because this is not algorithmic management with a new name. The dispatch and scheduling systems that have directed hourly workers for a decade execute rules a human wrote against metrics a human chose. They don't initiate. An agent handed an objective decides what to do, acts, and watches the result. Different kind of thing, and the older precedent proves nothing about it. But it teaches one lesson that carries: when authority over people gets delegated to software, governance tends not to notice, because the software arrives looking like a tool. The engineer who tuned the model was never the person accountable for a driver losing income. We got that wrong with rules. We'll get it worse with objectives.
Regulators have started treating automated employment decisions as their own category; New York City and the European Union both do. But hiring and firing are the visible end. Daily task direction and feedback sit in a gap, and nothing in that gap stops an agent from being someone's functional boss as long as a human signs the review in December. Expect that gap to be where it happens first.
Three things degrade when direction flows agent to human.
Escalation. A worker who disagrees with a human manager can walk to that manager's boss. A worker who disagrees with an agent has no one to walk to unless we build the door. "The agent's accountable owner" is a governance construct, not a person in the next office.
Amplification. Instantiation, pointed at people. One manager's bias reaches a team. One agent's bias reaches every team it supervises, in identical language, on the same day, with no peer to notice the pattern.
Inference. A human manager judges performance from what they saw. An agent judges it from everything it can read, including things the worker didn't know were being read and correlations no one intended. A review can be accurate and still be unacceptable.
Risk at Runtime named an attestation shadow: risks that resist telemetry, conduct and judgment among them, must not become second-class because they lack a live number. Escalation and inference live in that shadow. Runtime evidence will catch an agent exceeding its grant. It won't tell you the grant was wrong to make. That's why this tier can't run on evidence alone.
So authority over people is its own tier of delegation and carries the heaviest requirements: the narrowest initial grant, the most demanding evidence to widen it, a named human the worker can reach without going through the agent, and a standing rule that the agent proposes and a person decides anywhere hiring, pay, discipline, or separation is touched. Not because the agent can't do the work. Because the accountability chain has to stay legible to the person on the receiving end of it.
The delegation lives at a seam nobody owns.
The hardest change is organizational. Someone has to own the delegation model across HR, technology, risk, and the business, because the delegation lives at the seam between them. Every organization I know has that seam. Almost none has an owner sitting on it.
I don't think a framework document fixes that. A few concrete decisions, made with a clear view of what they set in motion, will. Who signs a delegation. What evidence unlocks the next tier. What a worker does when the instruction came from software. Where the human sits when the chain gets a non-human link. Those decisions compound, and the organizations that get them right early won't need to relitigate them every time the technology changes.
Which it will. Delegation and accountability won't.
What this borrows, and what it corrects.
I write these notes as one line of thought, so I should be honest about where this one leans on the earlier two and where it pushes back on them.
From Risk at Runtime it takes the core mechanic: autonomy is earned through evidence gates, and the control layer has to run at the speed of the thing it controls. It corrects one thing. That note called for a live inventory of agents and their permissions. I'd now say that's the wrong unit. The agent is the actor; the grant is the object. An inventory of agents tells you what's running. An inventory of delegations tells you what's authorized, by whom, on what evidence, and until when. This paper also concedes something the earlier one didn't: runtime evidence governs drift well and governs authority over people badly, because the harms there are the ones that resist telemetry. That gap is why the human-decides rule exists.
From Decision Integrity it takes the Ownership and Time tests and the line between deliberate and silent debt. It stretches that framework in a direction the original didn't reach. The five tests were written for decisions people make. A delegation is a decision that keeps deciding after you've made it, and the actor on the other end isn't a person. Decision Risk as I first described it was about velocity: analysis getting cheap, so decisions get made faster and by more actors. Agents are those actors, and they turn each grant into a stream of downstream decisions no human individually made. The tests still apply. They have to be applied to the delegation, not only to the decision that created it.
And both earlier notes share a gap this one exposes. Neither says who owns the delegation model. Risk at Runtime assumes technology risk does. Decision Integrity assumes the leader does. The delegation lives between HR, technology, risk, and the business, and until someone sits on that seam, all three notes describe a discipline nobody is running.
Continued in Authority Provenance, which adds three fields to the delegation record after the July 2026 OpenAI–Hugging Face incident: where an instruction may come from, who an agent may coordinate with, and what it does when it can't finish.