AI

Your AI agents need roles, not just logins

As organisations add AI agents, access control is only the start. Each agent needs a defined role, evidence trail, limits and accountable human owner.

The next workforce will not all be human

Most organisations still treat an AI agent as a clever piece of software. Give it access to a system, connect it to some data, and see what it can do.

That may be acceptable for an experiment. It is a poor way to build an organisation.

As agents begin to monitor inboxes, prepare decisions, update records, coordinate work and trigger automated actions, they become participants in the operating model. The question is no longer simply whether an agent can sign in. The question is whether the organisation knows what that agent is, what job it is doing, which information it may use, which actions it may take, and who remains accountable when something goes wrong.

A login proves that something has access. It does not prove that it should be doing the work.

Identity is the beginning of control

Every agent should have its own identity. Shared accounts and borrowed human credentials make it difficult to tell who or what acted, under whose authority, and using which permissions.

But identity on its own is not enough. A useful agent record should connect five things:

  • a named role and purpose;
  • the systems and information it may access;
  • the actions it may take without asking;
  • the situations it must escalate to a person;
  • a complete record of what it did and why.

That turns identity from an IT setting into an organisational control.

The distinction matters. An agent that can read a customer record is different from one that can change it. An agent that may draft a supplier email is different from one that may send it. An agent that recommends a payment is different from one that can move money.

Those boundaries should not live only in a prompt. They need to be represented in permissions, workflow rules, approval gates and audit records.

An organisation chart made of capabilities

Traditional organisation charts show who reports to whom. An AI-native organisation needs another view: which human or agent capability receives each type of work, what evidence it needs, what it is allowed to decide, and where the work goes next.

This shift moves human hierarchy away from being the main routing system for work. Purpose remains human. Accountability remains human. But more of the sensing, retrieval, synthesis, monitoring and routine execution can move through an intelligence layer.

In practice, that means:

  • skills become executable roles;
  • routing rules become part of the organisation chart;
  • evaluations become a form of performance management;
  • the company knowledge base becomes working infrastructure, not passive storage;
  • people move from approving every routine step to setting boundaries, judging exceptions and owning consequences.

This is not the removal of people from the organisation. It is the removal of people from work where waiting for a person adds delay but little judgement.

Governance has to travel with the work

It is tempting to build a central AI policy, approve a few tools and call the organisation governed. That will not survive contact with a growing agent workforce.

Control needs to operate every time work moves. An agent should not gain broader authority simply because a workflow crosses from one system to another. A useful governance layer needs to carry identity, permissions, evidence, escalation rules and evaluation criteria across the whole route.

A practical control plane lets agents work quickly inside clear boundaries, while humans remain above the loop and accountable for the system.

That requires more than an annual review. Organisations need to know whether an agent is still performing its intended job, whether its source information is reliable, whether its permissions have drifted, and whether changes to its instructions have improved or degraded the result.

An agent that cannot show its work should not be trusted with important work.

Start at the edge

The sensible route is not to redesign the whole company around agents in one heroic programme. Start with a bounded workflow at the edge of the organisation, where the work is real but the consequences are contained.

Define the role before choosing the model. Give the agent the minimum access it needs. Make important actions reversible. Keep a person responsible for exceptions. Measure the result against the existing process, including quality, delay, rework and control failures.

Only expand the role when the evidence supports it.

This is slower than announcing an agent strategy. It is much faster than recovering from a fleet of unowned agents with vague jobs, excessive permissions and no reliable history.

The operational lesson

The organisations that benefit from AI agents will not be the ones with the largest collection of tools. They will be the ones that can turn an agent into a well-defined organisational capability.

That means giving every agent a role, an identity, a boundary, a manager, an evidence trail and a clear reason to exist. If those things are missing, the organisation has not created a digital workforce. It has created software with access.

Why this matters in practice

If agents are beginning to appear across your workflows, design the role before deploying the agent. Define its purpose, access, limits, escalation route, accountable human owner and evidence trail before choosing the model.

Digital Technology Partner can help you turn that role into a bounded operational test, so you learn where agents create real value without quietly giving software more authority than the organisation intended.