After an agent-caused incident, the meeting has a predictable moment: someone asks whose it was. And the answer takes a while, because three partial answers compete — who built it, who uses it and who operates the platform.
Why the question is hard
An agent crosses organisational boundaries by nature. The data team built it, sales uses it, platform hosts it, security would audit it if they knew it existed. Each holds part of the responsibility and none holds the decision.
That diffusion is no accident: it is the result of not asking the question at the start, when it was cheap. After the incident it becomes internal politics.
Responsibility not assigned beforehand will be negotiated afterwards, at the worst possible moment.
Three distinct roles that need names
- Agent owner. Answers for behaviour: what it may do, with which permissions, for what purpose. Approves scope elevation and signs off residual risk.
- Platform operator. Answers for infrastructure: isolation, availability, logging, segmentation. Does not decide business permissions.
- Delegator. The user who triggers a specific execution. Answers for the request, not the design.
Separating these three settles most incident arguments before they happen, because every question has an intended recipient.
The mandatory-field test
The cheapest way to force that clarity is technical, not organisational: make the “owner” field mandatory in the agent registry and fail deploys without it. A required field solves in one sprint what a governance policy does not solve in a year — because the cost of leaving it blank becomes immediate and concrete.
And when the agent errs on its own
Worth saying the obvious, because it is not always said: responsibility does not migrate to the agent. It has neither intent nor assets. The person who answers is the one who decided to grant that permission to that process — and that person deserves to know it before the incident, not during.