Journal · AI and Enterprise Control
Before an AI Agent Touches a Real Process
AI agents should operate within an explicit boundary of authority, accountability and control.
An AI agent changes the nature of automation.
Traditional automation follows predefined instructions.
An AI agent interprets information, selects actions and responds to changing conditions.
Once an agent starts acting inside a real business process, the question is no longer:
Can the agent perform the task?
The question becomes:
What authority should the agent have?
That is an operating decision, not a technology decision.
Start with the boundary
An agent should not receive broad authority simply because the technology supports autonomous action.
Define the boundary first.
What may the agent observe?
What may it recommend?
What may it prepare?
What may it execute?
What requires human approval?
What actions must remain outside the agent's authority?
The answer should depend on business risk, reversibility, financial impact, regulatory exposure and consequences for customers or employees.
Autonomy is not binary
There is a useful progression:
Observe
The agent monitors information and identifies patterns.
A human remains responsible for every action.
Recommend
The agent proposes a decision or action.
A human reviews the recommendation before proceeding.
Draft
The agent prepares content, transactions or workflow actions.
A human approves before execution.
Execute with approval
The agent performs the action after a defined human approval.
Execute within predefined limits
The agent acts independently within explicit thresholds and rules.
Fully autonomous
The agent operates independently for defined low-risk and reversible activities.
The important point is not reaching the highest level of autonomy.
The important point is selecting the right level for the process.
The risk sits in the action
An agent producing a draft email is different from an agent approving a payment.
An agent classifying a service request is different from an agent closing a customer account.
An agent recommending a pricing change is different from an agent changing the price.
The model might be identical.
The consequences are not.
Autonomy should therefore follow the risk of the action, not the sophistication of the technology.
Five controls before execution
Before an agent touches a production process, establish five control areas.
1. Least privilege
Give the agent only the access required for its defined responsibilities.
Do not give broad system access because future use cases might need it.
2. Action limits
Define transaction limits, frequency limits and other boundaries.
Examples include:
Maximum transaction value
Maximum number of actions
Approved systems
Approved data
Approved operating hours
Permitted action types
3. Failure protection
Assume the agent will encounter unexpected conditions.
Design for:
Duplicate actions
Timeouts
Invalid inputs
Conflicting instructions
Unexpected system responses
Failed transactions
The process needs a safe response.
4. Reversibility
Ask whether an action can be undone.
Low-risk reversible actions are better candidates for higher autonomy.
Irreversible actions require stronger controls and human involvement.
5. Auditability
Every significant action needs a record.
The organisation should know:
What the agent received
What the agent decided
What action the agent took
Which systems were affected
Who approved the action, where required
What happened afterwards
Without an audit trail, accountability becomes difficult.
Test the agent under hostile conditions
A controlled demonstration is not enough.
Test the agent when conditions are wrong.
What happens when data is incomplete?
What happens when a system is unavailable?
What happens when instructions conflict?
What happens when the same request arrives twice?
What happens when the agent receives unexpected input?
What happens when a downstream transaction fails?
What happens when a user attempts to bypass the intended controls?
The objective is not to prove the agent never fails.
The objective is to prove the organisation knows how failure will be detected and contained.
Define the shutdown mechanism
Every production agent needs a way to stop.
The organisation should know:
Who has authority to stop the agent
What conditions trigger a shutdown
How ongoing actions are handled
How affected transactions are recovered
How the agent is restarted
Who reviews the incident
A shutdown mechanism is part of the operating design.
It is not an emergency feature added after deployment.
Treat the agent as a process change
An AI agent does not simply introduce a new technology component.
It changes how work gets performed.
Responsibilities may move.
Approval points may change.
Exception handling may change.
Control points may move from people to systems.
New monitoring responsibilities emerge.
New failure modes appear.
The process owner therefore needs to understand the change before the agent enters production.
The executive decision
Before approving an AI agent for production, ask six questions:
- 01What decision or action is the agent authorised to take?
- 02What is the highest consequence if the agent is wrong?
- 03What must remain human-controlled?
- 04What limits prevent the agent from exceeding its authority?
- 05How will the organisation detect and contain failure?
- 06Who has authority to stop the agent?
If these questions do not have clear answers, the agent is not ready for production.
What would change the decision?
Reduce the agent's autonomy when:
The action is difficult to reverse.
Financial exposure is high.
Customer impact is significant.
Regulatory consequences are material.
Data quality is uncertain.
Failure is difficult to detect.
The process has weak exception handling.
Accountability is unclear.
Increase autonomy only when evidence supports the change.
Start with a controlled boundary.
Measure performance.
Observe failure patterns.
Strengthen controls.
Then decide whether greater autonomy is justified.
The principle
AI agents should earn autonomy.
The organisation should not grant authority because the technology makes authority possible.
The right question is not:
How autonomous can this agent become?
The better question is:
How much authority is appropriate for this process, given the consequences of failure?
AI agents should operate within an explicit boundary of authority, accountability and control.
Before an agent touches a real process, define the boundary.
Related perspectives
Related frameworks
Related executive decision
Executive Decision · AI and Enterprise Control
What Should Remain Human?
Which decisions and actions should remain human-controlled?
Related
Read next.
Journal · AI and Enterprise Control
Why Most Enterprise AI Pilots Never Become Operating Capabilities
Most AI pilots do not fail because the model stops working. They fail because the organisation has not built the operating capability around the model.
Journal · AI and Enterprise Control
When AI Starts Acting, Who Owns the Outcome?
AI changes the conversation when it moves from answering questions to taking action.
Journal · AI and Enterprise Control
The AI Trust Problem Is an Operating Model Problem
Trust is not one control. It is the result of multiple parts of the enterprise working together.