Skip to content
Analysis·6 min read

Your Company's AI Agents Have Logins and No Manager

AI agents at work get API keys, Slack seats and spend limits, but rarely an owner or a written scope. Somebody on your team is doing that supervision for free.

The Taipei Times ran a piece this week asking where the employee handbook is for Taiwan's new AI coworkers. Within hours, Koreabizwire reported that companies are running into a fresh class of security problem as agents move out of demos and into production workflows.

Read the two side by side and you get the same story from opposite ends. Companies provision agents like software. The agents then behave like staff. Almost nobody has written down the rules.

We think this is the part of AI at work that's changing people's days right now, more than any model release. It lands on individual contributors as work nobody budgeted for: deciding what an agent is allowed to touch, checking what it did, and cleaning up when it does something confidently wrong. And it eats into productivity gains that plenty of leadership decks have already counted.

An agent gets a token, not a scope

Think about what happens when a contractor joins your team. They get a scope of work and a named manager, a start date and an end date, and somebody runs an offboarding checklist when they go.

An agent joining the same team typically gets an API key, an OAuth token scoped to whatever the employee who authorized it could already reach, a Slack seat, and sometimes a spend limit on a cloud account. What it rarely gets is a written scope, an owner of record or a decommission date.

That gap matters because agents act. A retrieval chatbot hands you text you can ignore. An agent files the ticket, merges the branch, updates the CRM record, emails the vendor or moves the money. The permission model most companies run was built for tools that wait to be told what to do, and it now sits behind software that decides a sequence of actions by itself.

Which is why we find the Taipei handbook question more useful than yet another AI maturity model. The questions are ordinary HR questions pointed at software. Who owns it? What is it allowed to do? How do we know what it did? How does it leave?

Borrowed credentials turn every agent into an insider

There's nothing exotic about the problem Koreabizwire flagged. An agent inherits the entitlements of whoever set it up, and in most companies that means a senior engineer or an operations lead with broad standing access. Give that agent a long-lived token and a permissive scope and you've created an insider account that never sleeps, never sits through a performance review and can't be socially trained out of a bad instruction.

Prompt injection makes that a live attack surface. A support agent reading customer tickets is reading untrusted input. So is a coding agent that pulls in a dependency's README. How much damage either one can do is set entirely by what its credential allows, and in most deployments nobody has audited that since the pilot.

The teams that have written something like a handbook tend to arrive at the same short list. Every agent gets a named human owner, listed in the same directory as employees. It gets a written scope of authority that spells out the actions it has to escalate instead of taking. Its credentials follow least privilege and carry an expiry date, rather than being a standing token copied from somebody's personal account. It keeps an action log a non-engineer can read during an incident review.

And there's a decommission trigger, so a retired agent loses its access instead of running unattended.

Review time is where the productivity claims leak

Agents shift work from producing to reviewing, and review time gets underestimated almost everywhere. Reading a 300-line agent-generated pull request closely enough that you'd sign your name to it often costs more than writing 80 lines yourself. Same for a reconciliation the agent completed, a customer email it drafted, or a data pull it stitched together from three systems.

Most measurement schemes can't see that cost. Tool adoption is easy to count. Verification effort is not.

It also helps explain the credibility problem around AI-attributed job cuts. Monday.com joined roughly 20 other companies in citing AI when trimming headcount, and the note that accompanied Robinhood's 10 percent reduction showed that investors and staff have stopped taking that attribution at face value.

There's a counterweight, though. Lloyds reported this week that AI is creating more UK jobs than it eliminates, and a meaningful share of what's being created sits in review, integration and control functions rather than in model building.

Look at what agents are actually absorbing in the deployments described publicly and the pattern is consistent: first drafts, ticket triage and routing, log and meeting summaries, test scaffolding, routine data pulls, and repetitive reconciliation between systems. Those tasks share a shape. The inputs are clear, the output can be checked, and the cost of an error is tolerable when a human reviews before anything gets committed.

What isn't moving is work that means holding ambiguity, negotiating across teams with competing incentives, or personally carrying the consequences of a decision. That's part of why engineering roles have held up better than the 2024 predictions suggested. The shortage now is in people who can specify and verify. Typing fast was never going to be the scarce skill.

Demand is showing up outside engineering too. Reporting this week noted a surge in AI skill requirements in nontech roles, and Inc. made the case that the strongest candidate for a technical job often isn't a computer science major. Finance, marketing, legal operations and HR are where a single well-scoped agent can absorb the biggest share of a workflow. They're also where nobody has been trained to supervise one.

Be the person who owns the agent

The mood is getting worse faster than the labor data. HR Dive reported workers describing FOBO, a fear of becoming obsolete. Pew found young adults in the US increasingly wary that AI will take their jobs. Research summarized by zoomer.com found that AI training can backfire for older workers through technostress, pushing them toward avoidance rather than adoption.

Trying to out-draft an agent is a race you'll lose. The better seat is the one where you define what the agent may do, check that it did it, and answer for the result. Those positions last because they carry accountability, and accountability is the one thing no vendor is currently offering to take off your hands.

It's also a better thing to spend training hours on. Another prompt technique goes stale quickly. Knowing how to scope, permission, log and audit an autonomous process is closer to an operations discipline, and it still applies if your company switches model vendors next quarter.

In most organizations nobody has been assigned any of this, which means the first person to do it credibly gets to set the standard and gets named in the process. That's rare visibility in a year when TikTok is closing offices, Patreon has cut 20 percent and Pentera has run two rounds in four months.

So start narrow, and write everything down. Over the next 90 days, inventory the agents already running in your team's workflows, including the ones somebody spun up for a pilot and never turned off. Find out whose credential each one is borrowing and whether that token expires. Write a one-page scope for the agent you rely on most, with the actions it must escalate. Track your own verification time for two weeks so the next argument about productivity uses numbers. When an agent gets something wrong, log what it cost and what control you added.

Then put those documents on your resume instead of tool names. One agent with an owner, a scope and a review log will carry more weight in an interview than any claim of AI fluency.

Topics in this article

Know someone who'd find this useful?

Wondering about your own job?

The calculator takes about two minutes and shows which parts of your situation matter most. Or see which skills are paying more this year.