Journal · AI and Enterprise Control

Before an AI Agent Touches a Real Process

AI agents should operate within an explicit boundary of authority, accountability and control.

Devendra KumarOctober 20266 min read

An AI agent changes the nature of automation.

Traditional automation follows predefined instructions.

An AI agent interprets information, selects actions and responds to changing conditions.

Once an agent starts acting inside a real business process, the question is no longer:

Can the agent perform the task?

The question becomes:

What authority should the agent have?

That is an operating decision, not a technology decision.

Start with the boundary

An agent should not receive broad authority simply because the technology supports autonomous action.

Define the boundary first.

What may the agent observe?

What may it recommend?

What may it prepare?

What may it execute?

What requires human approval?

What actions must remain outside the agent's authority?

The answer should depend on business risk, reversibility, financial impact, regulatory exposure and consequences for customers or employees.

Autonomy is not binary

There is a useful progression:

Observe

The agent monitors information and identifies patterns.

A human remains responsible for every action.

Recommend

The agent proposes a decision or action.

A human reviews the recommendation before proceeding.

Draft

The agent prepares content, transactions or workflow actions.

A human approves before execution.

Execute with approval

The agent performs the action after a defined human approval.

Execute within predefined limits

The agent acts independently within explicit thresholds and rules.

Fully autonomous

The agent operates independently for defined low-risk and reversible activities.

The important point is not reaching the highest level of autonomy.

The important point is selecting the right level for the process.

The risk sits in the action

An agent producing a draft email is different from an agent approving a payment.

An agent classifying a service request is different from an agent closing a customer account.

An agent recommending a pricing change is different from an agent changing the price.

The model might be identical.

The consequences are not.

Autonomy should therefore follow the risk of the action, not the sophistication of the technology.

Five controls before execution

Before an agent touches a production process, establish five control areas.

1. Least privilege

Give the agent only the access required for its defined responsibilities.

Do not give broad system access because future use cases might need it.

2. Action limits

Define transaction limits, frequency limits and other boundaries.

Examples include:

Maximum transaction value

Maximum number of actions

Approved systems

Approved data

Approved operating hours

Permitted action types

3. Failure protection

Assume the agent will encounter unexpected conditions.

Design for:

Duplicate actions

Timeouts

Invalid inputs

Conflicting instructions

Unexpected system responses

Failed transactions

The process needs a safe response.

4. Reversibility

Ask whether an action can be undone.

Low-risk reversible actions are better candidates for higher autonomy.

Irreversible actions require stronger controls and human involvement.

5. Auditability

Every significant action needs a record.

The organisation should know:

What the agent received

What the agent decided

What action the agent took

Which systems were affected

Who approved the action, where required

What happened afterwards

Without an audit trail, accountability becomes difficult.

Test the agent under hostile conditions

A controlled demonstration is not enough.

Test the agent when conditions are wrong.

What happens when data is incomplete?

What happens when a system is unavailable?

What happens when instructions conflict?

What happens when the same request arrives twice?

What happens when the agent receives unexpected input?

What happens when a downstream transaction fails?

What happens when a user attempts to bypass the intended controls?

The objective is not to prove the agent never fails.

The objective is to prove the organisation knows how failure will be detected and contained.

Define the shutdown mechanism

Every production agent needs a way to stop.

The organisation should know:

Who has authority to stop the agent

What conditions trigger a shutdown

How ongoing actions are handled

How affected transactions are recovered

How the agent is restarted

Who reviews the incident

A shutdown mechanism is part of the operating design.

It is not an emergency feature added after deployment.

Treat the agent as a process change

An AI agent does not simply introduce a new technology component.

It changes how work gets performed.

Responsibilities may move.

Approval points may change.

Exception handling may change.

Control points may move from people to systems.

New monitoring responsibilities emerge.

New failure modes appear.

The process owner therefore needs to understand the change before the agent enters production.

The executive decision

Before approving an AI agent for production, ask six questions:

  1. 01What decision or action is the agent authorised to take?
  2. 02What is the highest consequence if the agent is wrong?
  3. 03What must remain human-controlled?
  4. 04What limits prevent the agent from exceeding its authority?
  5. 05How will the organisation detect and contain failure?
  6. 06Who has authority to stop the agent?

If these questions do not have clear answers, the agent is not ready for production.

What would change the decision?

Reduce the agent's autonomy when:

The action is difficult to reverse.

Financial exposure is high.

Customer impact is significant.

Regulatory consequences are material.

Data quality is uncertain.

Failure is difficult to detect.

The process has weak exception handling.

Accountability is unclear.

Increase autonomy only when evidence supports the change.

Start with a controlled boundary.

Measure performance.

Observe failure patterns.

Strengthen controls.

Then decide whether greater autonomy is justified.

The principle

AI agents should earn autonomy.

The organisation should not grant authority because the technology makes authority possible.

The right question is not:

How autonomous can this agent become?

The better question is:

How much authority is appropriate for this process, given the consequences of failure?

AI agents should operate within an explicit boundary of authority, accountability and control.

Before an agent touches a real process, define the boundary.

Related executive decision

Executive Decision · AI and Enterprise Control

What Should Remain Human?

Which decisions and actions should remain human-controlled?

October 20262 min read
TopicsAIGovernanceOperating ModelExecutive Decision-Making

Related

Read next.

Explore more perspectives →